A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If exploited, the vulnerability could allow attackers to hijack the host’s control flow, which could enable remote code execution. Isolated-vm is downloaded more than 1 million times per week and is also used as a direct or optional component in other…
Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass. Citrix said in an advisory that supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and…
Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month. ThreatDown researchers say “Kriminal” is largely a storefront wrapped around legitimate AI services, using jailbreak prompts to bypass their guardrails and resell the resulting capabilities to would-be…
Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED classification level. The assessment was conducted by an Australian Signals Directorate (ASD)-endorsed IRAP assessor against the Australian Government Information Security…
OpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.” In its first announcement , issued Tuesday, OpenAI said it “temporarily” slowed the pace of its scaling, in addition to…
An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part of a pull request (PR) that GitHub Copilot was involved in, though Wiz has clarified that it is unclear whether the coding…
The National Security Agency (NSA) and Central Security Service recently published an advisory statement on behalf of the Five Eyes Cyber Security Agencies, warning that AI technologies are making it easier than ever for would-be malicious actors to infiltrate and compromise sensitive networks. “AI is not a future consideration — it is already here,” the statement says. “It lowers barriers for…
A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe-coded an app and put it to work with customer data. Now, the client wanted to know what risks the tool posed. And what it should do about them. They needed answers quickly, so Shostack gave himself 15 minutes to analyze the system. Soon, he had “a list of…
Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this…
GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw. The critical vulnerability, tracked as CVE-2026-19478 , is described as a code injection issue through…