Tag
Koreshield is a security product that screens customer messages, retrieved documents, and tool calls for AI support agents to prevent data leaks, hidden instructions, and unsafe actions, with easy integration.
Researchers have revived TEMPEST attacks using injected RF signals, demonstrating recovery of internal signals from modern electronics, including voice cloning and injection.
The article highlights a potential flaw in AMD's random number generator that prevents it from generating the value 0, raising concerns about randomness and security implications.
The Muse Mac app had a local privilege escalation vulnerability that was responsibly disclosed and fixed with a hotfix. The company has issued a fix and provided details on the issue, emphasizing transparency and security.
This paper introduces a multi-agent system called CB-MAS for document sensitivity classification, which addresses the limitation of fixed input length in transformer models like BERT by using iterative consultation and channel boosting.
Meta's AI assistant Muse has a critical zero-day vulnerability that allows local apps to hijack the account, raising security concerns despite Meta's claims of building it for privacy.
A team implemented 1024-bit RSA signature forgery in nearly SNFS time, showing that temporary HSM access allows attackers to forge arbitrary signatures without factoring the key.
This article reveals that the npm package mathmain contains a hidden remote access implant with an encrypted loader, which decrypts and executes malicious code when a specific equation is solved using the library.
The article shares initial user impressions of Grok 4.7, an AI model, discussing frontend and backend work, comparisons to other models like 5.6 sol and fable 5.1, and raising questions about safeguards and censorship.
The author discovered that an internal AI agent had overly broad IAM permissions, highlighting the need for better security practices in managing AI agent identities and seeking community advice on handling such issues.
Amazon blocked Meta's Muse AI agent from accessing its shopping platform due to concerns over unauthorized access and privacy violations, citing lack of transparency and potential security risks. This action is part of Amazon's broader effort to fend off competition from rival agentic AI services in e-commerce.
This research paper proposes a taxonomy for Kubernetes misconfigurations and explores using large language models to improve detection methods in cloud-native environments.
ZCode has been open-sourced on GitHub following the remediation of security issues, with the source code now available for community scrutiny and security assessments by CAICT and NSFOCUS confirming data remediation.
Attackers can hijack AI agents by injecting malicious content into retrieved sources, exploiting the inability to distinguish instructions from content, as identified in OWASP's top 10 for agentic applications.
A user expresses frustration with Openclaw's new safety limits that prevent agents from saving and using credentials, arguing for user control over such decisions.
The article explains how Cloudflare's cloudflared tunnel can be used to expose local services to the internet without inbound ports, but warns that Cloudflare terminates TLS, exposing traffic in plaintext.
The article reviews updates to the w64devkit development tool over the past year, including the addition of a co-maintainer, enhanced security through code-signing, and improvements like multilib support for cross-compiling.
This article explains the basics of software sandboxing, detailing syscall policies for enhancing security using techniques like seccomp and BPF, with influences from Docker, systemd, and OpenBSD.
Cloudflare Quick Tunnels allow developers to expose localhost to the internet with a single command, providing secure, encrypted URLs without needing an account or DNS configuration.
SecAIQ Watch is a free, open-source dashboard that monitors AI tools on your computer, displaying their connections, access, and token usage locally without cloud or account requirements.