New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed a novel attack technique dubbed "Cryptographic Context Injection" that can cause xAI's Grok chatbot to exfiltrate a user's…
Adversa AI has disclosed a novel attack technique dubbed "Cryptographic Context Injection" that can cause xAI's Grok chatbot to exfiltrate a user's…
Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. The flaw, present in the…
cPanel has released a targeted security update to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands…
Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards…
A critical vulnerability in AWS Kiro, an agentic coding IDE, allowed a poisoned web page to rewrite its configuration file and execute…
HackerOne is a bug bounty platform used by Intezer to report the Kiro vulnerability to AWS.
A critical vulnerability in Cursor, an AI-powered code editor, allows arbitrary code execution on Windows when a user opens a cloned repository…
Anthropic has restored its Claude Fable 5 AI model worldwide after the U.S. Commerce Department lifted export controls imposed on June 12,…
Wiz reported the Snowflake GitHub Actions vulnerability through HackerOne, a leading bug bounty platform. The coordinated disclosure led to a same-day fix…
Salesforce disabled the Klue Battlecards app integration after detecting unusual activity that led to unauthorized access to customer data via OAuth token…