Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
4+ hour, 27+ min ago (569+ words) The campaign scans IPv4 address ranges for Redis services exposed to the internet, typically on TCP port 6379, then attempts to interact with instances that allow connections without authentication. Once access is obtained, the attackers use Redis’s administrative CONFIG SET command to…...
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
1+ day, 4+ hour ago (616+ words) A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident....
Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks
1+ day, 22+ hour ago (502+ words) A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems....
Telerik UI Flaws Let Attackers Chain AES-CBC Padding Oracle to Unauthenticated RCE
2+ day, 1+ hour ago (562+ words) Security researchers have identified a critical vulnerability chain in Progress Telerik UI for ASP.NET AJAX, which allows unauthenticated attackers to escalate from a cryptographic padding oracle to remote code execution on exposed web applications. Documented by Tanto Security researcher…...
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security
4+ day, 8+ min ago (488+ words) Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software supply-chain security platform. The company now maintains more than 3,000 unique container images and 675,000 image versions. The milestone reflects more than…...
Google Unveils Gemini 3.8 Flash Cyber for Autonomous Vulnerability Discovery and Automated Patching
6+ day, 4+ hour ago (540+ words) Google has introduced Gemini 3.8 Flash Cyber, a specialized AI model focused on cybersecurity. This model is designed to autonomously identify software vulnerabilities, generate code fixes, and validate patches before deployment. Access to this model is restricted to vetted defenders through…...
GitSpawn Flaw Enables Arbitrary Code Execution in Claude Code, Codex, Cursor and Grok
6+ day, 4+ hour ago (506+ words) A newly disclosed vulnerability class, named GitSpawn, reveals a serious weakness in AI coding agents that automatically execute Git commands to understand a developer’s project better. Researchers at Manifold Security discovered that several tools, including Claude Code, OpenAI Codex, Cursor,…...
Hugging Face Transformers Flaw Writes Malicious Python Code to Disk Before User Consent
1+ week, 1+ hour ago (254+ words) A newly disclosed vulnerability in the Hugging Face Transformers library could allow attacker-controlled Python files to be written to a victim’s system before the user approves the execution of remote code. This vulnerability is tracked as CVE-2026-80047 and affects Transformers…...
Anthropic Unveils Claude Fable 5.1 and Mythos 5.1 With Powerful Cybersecurity Capabilities
1+ week, 4+ hour ago (586+ words) Anthropic has launched Claude Fable 5.1 and Claude Mythos 5.1, two versions of the same advanced AI model designed to enhance capabilities in coding, knowledge work, scientific research, and cybersecurity operations. While Fable 5.1 is available to the general public, Mythos 5.1 is restricted…...
Critical JFrog Artifactory Authentication Bypass Exploited in the Wild
1+ week, 21+ hour ago (249+ words) According to a post from the security research firm watchTowr dated September 1, its threat intelligence team has already observed exploitation activities targeting this flaw. JFrog Artifactory is widely utilized by software development teams as a repository manager for binaries, build…...