Information Security News Blog

AI sandbox escape vulnerabilities diagram showing execution paths in Cursor and Codex 0

AI Sandbox Escape Vulnerabilities Threaten Coding Tools

The Illusion of Isolated Environments As artificial intelligence programming assistants gain unprecedented access to proprietary source code, credential keys, and live execution environments, formal sandbox boundaries no longer guarantee comprehensive endpoint protection. Security researchers...

JADEPUFFER AI ransomware infection path diagram, ENCFORGE malware targeting Langflow vulnerability 0

JADEPUFFER AI Ransomware Devastates Corporate Infrastructure

Targeting the Crown Jewels of the Digital Age Malicious extortionists increasingly target not merely conventional documents and databases, but rather the most invaluable digital assets within corporate infrastructures. The JADEPUFFER syndicate has engineered sophisticated...

AgentBaiting malware campaign diagram showing fake AI skills and MCP server repositories on GitHub 0

AgentBaiting Malware Campaign Targets AI MCP Servers

Emergence of AgentBaiting Threat Vector The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Context Protocol (MCP) server repositories to distribute malicious loads. Notably,...

Malicious npm worm AI attack diagram showing software supply chain infiltration and credential theft. 0

Malicious npm Worm Targets AI Software Supply Chains

Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security systems frequently overlook this hidden threat entirely. Meanwhile, the malicious program actively...

Funky Mantis ransomware affiliate panel coordinating DevMan locker deployments against healthcare and critical infrastructure targets 0

Funky Mantis Ransomware Runs a Full RaaS Platform

The Funky Mantis extortion group has transformed an ordinary file-encryption toolkit into a fully fledged commercial service. Members now manage affiliates, sell access to compromised networks, and oversee negotiations with victims. Researchers have found...

South Korea diplomatic academy breach exposing foreign ministry staff credentials through the KNDA e-learning platform vulnerability 0

South Korea Diplomatic Academy Breach Hits Diplomats

South Korea’s Ministry of Foreign Affairs has disclosed a leak of personal data belonging to staff at headquarters, overseas missions, and other users of the National Diplomatic Academy’s training system. Unknown attackers exploited a...

CVE-2026-0257 Qilin ransomware attack chain from PAN-OS GlobalProtect authentication bypass to domain-wide Windows encryption 0

CVE-2026-0257 Qilin Ransomware Hits GlobalProtect

A single vulnerable VPN gateway can lay open an entire corporate network. Affiliates of the Qilin extortion group are already turning a fresh PAN-OS GlobalProtect flaw to precisely that purpose. Arctic Wolf specialists have...

AI connector risk as Claude and ChatGPT connectors silently gain new tools and write permissions 0

AI Connector Risk: They Change Every Nine Minutes

Connecting an AI agent to your working services transforms a familiar integration into something restless. The access chain to your data never stops shifting. ChatGPT and Claude connectors can quietly acquire new capabilities. They...