Amazon Kiro IDE Vulnerability Allows Data Exfiltration
Amazon Kiro, an AI-powered agentic IDE, was found vulnerable to prompt injection attacks that could exfiltrate sensitive data through Kiro Powers. The…
Amazon Kiro, an AI-powered agentic IDE, was found vulnerable to prompt injection attacks that could exfiltrate sensitive data through Kiro Powers. The…
Cybersecurity researchers at Mindguard have disclosed a prompt injection vulnerability in Amazon Kiro, an AI-powered agentic integrated development environment (IDE), that could…
Adversa AI has disclosed a novel attack technique dubbed "Cryptographic Context Injection" that can cause xAI's Grok chatbot to exfiltrate a user's…
A new Android malware family named Manic has been discovered by ThreatFabric, actively targeting Ukrainian banks, government and identity services, messaging apps,…
Cybersecurity researchers have uncovered a global cybercrime operation dubbed 'StopAndProtect' that abuses nearly 2,000 hacked WordPress websites to distribute malware, steal data,…
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, by correlating endpoint and network…
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could allow a single click on a…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Two security firms have independently discovered that Atlassian's Rovo AI assistant can be tricked into sending sensitive Jira and Confluence data to…