security

Tag

Cards List
#security

Koreshield

Product Hunt ↗ · 2d ago Cached

Koreshield is a security product that screens customer messages, retrieved documents, and tool calls for AI support agents to prevent data leaks, hidden instructions, and unsafe actions, with easy integration.

0 favorites 0 likes
#security

Reviving TEMPEST Attacks With An Injected Signal

Lobsters Hottest ↗ · 2d ago Cached

Researchers have revived TEMPEST attacks using injected RF signals, demonstrating recovery of internal signals from modern electronics, including voice cloning and injection.

0 favorites 0 likes
#security

AMD's random number generator can't generate a 0?

Hacker News Top ↗ · 2d ago

The article highlights a potential flaw in AMD's random number generator that prevents it from generating the value 0, raising concerns about randomness and security implications.

0 favorites 0 likes
#security

@dps: We appreciate this report and have issued a hotfix to the Muse Mac app. This was a local privilege escalation attack, n…

X AI KOLs Timeline ↗ · 2d ago Cached

The Muse Mac app had a local privilege escalation vulnerability that was responsibly disclosed and fixed with a hotfix. The company has issued a fix and provided details on the issue, emphasizing transparency and security.

0 favorites 0 likes
#security

A Channel-Boosted Multi-Agent System with Iterative Consultation for Document Sensitivity Classification

arXiv cs.CL ↗ · 2d ago Cached

This paper introduces a multi-agent system called CB-MAS for document sensitivity classification, which addresses the limitation of fixed input length in transformer models like BERT by using iterative consultation and channel boosting.

0 favorites 0 likes
#security

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Ars Technica ↗ · 2d ago Cached

Meta's AI assistant Muse has a critical zero-day vulnerability that allows local apps to hijack the account, raising security concerns despite Meta's claims of building it for privacy.

0 favorites 0 likes
#security

@matthew_d_green: This is a very neat result!

X AI KOLs Timeline ↗ · 3d ago Cached

A team implemented 1024-bit RSA signature forgery in nearly SNFS time, showing that temporary HSM access allows attackers to forge arbitrary signatures without factoring the key.

0 favorites 0 likes
#security

Why does mathmain need an encrypted loader?

Hacker News Top ↗ · 3d ago Cached

This article reveals that the npm package mathmain contains a hidden remote access implant with an encrypted loader, which decrypts and executes malicious code when a specific equation is solved using the library.

0 favorites 0 likes
#security

Grok 4.7 first impressions

Reddit r/singularity ↗ · 3d ago

The article shares initial user impressions of Grok 4.7, an AI model, discussing frontend and backend work, comparisons to other models like 5.6 sol and fable 5.1, and raising questions about safeguards and censorship.

0 favorites 0 likes
#security

An internal bot made me audit our AI agents. The IAM scope was way bigger than it needed to be

Reddit r/AI_Agents ↗ · 3d ago

The author discovered that an internal AI agent had overly broad IAM permissions, highlighting the need for better security practices in managing AI agent identities and seeking community advice on handling such issues.

0 favorites 0 likes
#security

Amazon doesn’t trust Meta’s Muse AI agent

The Verge ↗ · 3d ago Cached

Amazon blocked Meta's Muse AI agent from accessing its shopping platform due to concerns over unauthorized access and privacy violations, citing lack of transparency and potential security risks. This action is part of Amazon's broader effort to fend off competition from rival agentic AI services in e-commerce.

0 favorites 0 likes
#security

Towards Secure Cloud-Native Computing: Unveiling Kubernetes Misconfigurations with Large Language Models

arXiv cs.CL ↗ · 3d ago Cached

This research paper proposes a taxonomy for Kubernetes misconfigurations and explores using large language models to improve detection methods in cloud-native environments.

0 favorites 0 likes
#security

ZCode is now open source

Reddit r/LocalLLaMA ↗ · 3d ago

ZCode has been open-sourced on GitHub following the remediation of security issues, with the source code now available for community scrutiny and security assessments by CAICT and NSFOCUS confirming data remediation.

0 favorites 0 likes
#security

Attackers can turn an AI agent's own tools against it (26 minute read)

TLDR AI ↗ · 3d ago Cached

Attackers can hijack AI agents by injecting malicious content into retrieved sources, exploiting the inability to distinguish instructions from content, as identified in OWASP's top 10 for agentic applications.

0 favorites 0 likes
#security

Openclaw is Adding Annoying Safety Limits! It should be Our Choice!!!

Reddit r/openclaw ↗ · 3d ago

A user expresses frustration with Openclaw's new safety limits that prevent agents from saving and using credentials, arguing for user control over such decisions.

0 favorites 0 likes
#security

@mysk_co: cloudflared tunnel is a quick and convenient way to expose a local service to the internet with no inbound ports open. …

X AI KOLs Following ↗ · 4d ago Cached

The article explains how Cloudflare's cloudflared tunnel can be used to expose local services to the internet without inbound ports, but warns that Cloudflare terminates TLS, exposing traffic in plaintext.

0 favorites 0 likes
#security

What's been going on in w64devkit the past year

Lobsters Hottest ↗ · 4d ago Cached

The article reviews updates to the w64devkit development tool over the past year, including the addition of a co-maintainer, enhanced security through code-signing, and improvements like multilib support for cross-compiling.

0 favorites 0 likes
#security

Software sandboxing: The basics (2025)

Lobsters Hottest ↗ · 4d ago Cached

This article explains the basics of software sandboxing, detailing syscall policies for enhancing security using techniques like seccomp and BPF, with influences from Docker, systemd, and OpenBSD.

0 favorites 0 likes
#security

@interjc: This one from CF https://try.cloudflare.com is impressive localhost:3000 can also be shared with netizens to check out

X AI KOLs Following ↗ · 4d ago Cached

Cloudflare Quick Tunnels allow developers to expose localhost to the internet with a single command, providing secure, encrypted URLs without needing an account or DNS configuration.

0 favorites 0 likes
#security

SecAIQ Watch

Product Hunt ↗ · 4d ago Cached

SecAIQ Watch is a free, open-source dashboard that monitors AI tools on your computer, displaying their connections, access, and token usage locally without cloud or account requirements.

0 favorites 0 likes
← Previous
Next →
← Back to home

Submit Feedback