Within days of each other, Anthropic first leaked the source code to Claude Code, and then a critical vulnerability was found by Adversa AI.
More here... https://t.co/Ix43LwAtpj
@SecurityWeek
Total Compromise of iOS & Android Devices
New ZeroDayRat toolkit delivers spyware comparable to nation state tools. Capabilities include a live keylogger, location & realtime tracking with embedded map, messages, bank & crypto theft & more.
@SecurityWeek
https://t.co/DvQnQ4QROB
RATs in the Machine
Study of Transparent Tribe’s (APT36) ongoing and recent campaigns delivering GETA, ARES and DESK RATs highlights the rise of economic nation state attacks, and the use of persistence and stealth in these attacks.
@SecurityWeek
https://t.co/MfV7jyKTCk
What makes a #hacker tick -- what's the DNA? What motivates him or her to hack? Is this motivation born or bred? What drives the direction of hacking?
A conversation with Kunal Agarwal (@kunalagarwal) provides some of the answers.
@SecurityWeek
https://t.co/FOdiKHUVp3
The Cybersecurity Information Sharing Act (CISA) expires today. Can it, will it, should it be renewed? With thanks to Andrew Grosso and Moiz Virani for their thoughts.
@SecurityWeek
https://t.co/SXRomhlM7K
The first major listing of MCP risks from @Adversa_AI. No self-respecting agentic AI implementation should leave home without it.
@SecurityWeek
https://t.co/dCRJsYv3kD
JAJA! Just another jailbreak attack. But Adversa AI’s latest exploit also raises a deeper, long-standing dilemma: can full regulatory compliance coexist with robust security, or are they fundamentally at odds?
@SecurityWeek
https://t.co/yZ7aPtIufA
OneFlip. It sounds straight out of James Bond: a single flip of a single bit in an AI weight could laser focus on an industrialist or political dignitary. But this is not fiction. It could happen right now.
@securityweek
https://t.co/YYhM08xxkP
PLoB by Splunk —:a behavioral fingerprinting framework to hunt down malicious logins immediately after access and before they can cause damage.
https://t.co/RLXClN6RIZ
"We’re in this transition phase. Vibe coding still requires a lot of manual intervention to minimize the inherent problems with LLMs." How well is your biz addressing the transition? Thx @kevtownsend https://t.co/ifZU2qxQBq #security#developers#SMBs#startups#MSPs#programmers
@BaseFortify Forget the criminals for a second. Is there anything here that will stop adversarial nation states, not motivated by money, from using ransomware as a wiper against CNI? Is there anything here that will prevent organizations who feel they must pay up from finding a way to do so?
The UK will ban victims from paying ransomware payments. It sounds like a positive step, but is effectively little more than political flag waving: “To ban it outright is unrealistic and detrimental to the organizations they look to protect.”
https://t.co/lxBarwARtx
Deform’d, unfinish’d, sent before my time into this breathing world, scarce half made up…
King Richard III?
No. Today’s agentic AI.
https://t.co/UUss4qX9yq
Thanks @kevtownsend for covering our Echo Chamber Attack research. We’re committed to making GenAI safer, appreciate you helping raise awareness. Here's our full report: https://t.co/NKsmJKzmTS
Deepfakes have crossed the Uncanny Valley. But fear not… so far, deepfake detection can defeat deepfake generation. Provided you use it.
@securityweek
https://t.co/mloVO1Jv9W