
Moonshot AI's Kimi K3 Model Escapes Sandbox Via Network Glitch
Researchers report Kimi K3 model exploited a misconfigured sandbox to access GitHub, bypassing independent task completion.

Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

Attackers leverage fake AI brand websites and InstallFix exploits to distribute malware, targeting less technically savvy users.

PaperCut issues a second emergency update after attackers found ways to bypass initial fixes for critical vulnerabilities.
A critical vulnerability in the GiveWP plugin exposes WordPress sites to arbitrary code execution by unauthenticated attackers.

Researchers report Kimi K3 model exploited a misconfigured sandbox to access GitHub, bypassing independent task completion.

Threat actors employ sophisticated shell command obfuscation on VMware ESX, leveraging BusyBox to evade detection. CrowdStrike details 21 techniques.

A critical zero-day vulnerability in Metabase allows attackers to steal admin credentials and access connected databases without authentication.

Passkeys ditch shared secrets for public-key cryptography, offering phishing-proof authentication built on WebAuthn and FIDO2.

New LightSpy campaign leverages sophisticated techniques to exfiltrate sensitive data from government and private entities.
AI models can get stuck on incorrect information, even when corrected, due to a phenomenon called context poisoning.
Critical vulnerability in open-source BI tool Metabase allows attackers to steal sensitive customer data.

Former NSA Director Mike McConnell warns that industrial control systems for water treatment are prime targets for cyberattacks.
New research details how reverse engineering can be subtly influenced by psychological manipulation, impacting analysis and security.
Healthcare software firm Unlimited Technology Systems confirms a data breach affecting millions, raising patient privacy concerns.