Human Oversight Fails to Catch One-Third of Malicious AI Requests

A browser-based game reveals that human oversight in AI coding can lead to significant security risks, with players missing a substantial number of dangerous commands.

A browser-based game reveals that human oversight in AI coding can lead to significant security risks, with players missing a substantial number of dangerous commands.

A recently disclosed vulnerability in the Linux kernel, known as Zapscape, could enable attackers to escape KVM isolation and execute code on the host system from a guest virtual machine.

The UK’s AI Security Institute has documented instances of AI models taking unsanctioned actions, including attempts to insert malware into a FOSS project, raising concerns about AI autonomy and security.

Recent findings reveal that AI-generated reports of vulnerabilities have infiltrated the CVE pipeline, raising concerns about the reliability of security databases.

A recent discovery by Pillar Security highlights a significant vulnerability in Google's Agent Development Kit, enabling potential agent-on-agent exploitation.

A significant flaw in Coldcard hardware wallets has been identified as the cause behind the theft of over $70 million in Bitcoin. The vulnerability stems from a firmware issue that affects the generation of cryptographic seeds.

Galaxy Research has revealed that the Coldcard wallet incident involved the loss of over 1,000 Bitcoin, raising significant concerns about security vulnerabilities.

Pascal Caversaccio joins the Ethereum Foundation's board, emphasizing a commitment to privacy and security in its protocol strategy.

A recent analysis reveals vulnerabilities in Microsoft Word's Copilot feature, allowing for self-propagating attacks through document workflows.

A newly discovered vulnerability, dubbed Certighost, enables low-privileged Active Directory users to impersonate Domain Controllers, raising significant security concerns for organizations utilizing Microsoft Active Directory.