AI Recommendation Poisoning: How ‘Ask AI’ Buttons Silently Alter LLM Memory
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
Security researchers have uncovered a class of vulnerabilities in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel that allow attackers…
Google's Agent Development Kit for Python had two vulnerabilities fixed in version 2.5.0: continuation forgery and resumable-mode bypass.
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after researchers at Pillar Security demonstrated that…
Unit 42 researchers have disclosed three attack paths against Google Password Manager in Chrome on Windows, which could allow malware already running…
Cybersecurity firm Bitsight has uncovered a large-scale operation dubbed 'Fuyao' involving cheap Android TV boxes that secretly impersonate smartphones to commit ad…
Google has patched a record 1,442 security vulnerabilities across Chrome versions 149, 150, and 151, surpassing the total number of flaws fixed…
CVE-2026-3545 is a critical sandbox escape vulnerability in Chrome's Navigation component with a CVSS score of 9.6. It could be exploited to…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…