ThreatsDay: from iCloud backdoors to agent RCE
ThreatsDay shows how modern attacks exploit excessive trust: from agent RCE vulnerabilities to supply-chain infections and phishing chains. Key lessons and practical focus areas you can act on.
ThreatsDay shows how modern attacks exploit excessive trust: from agent RCE vulnerabilities to supply-chain infections and phishing chains. Key lessons and practical focus areas you can act on.
A man accused of hacking Snowflake accounts across 165 organizations has pleaded guilty in US court. Authorities say the campaign involved stolen credentials, data theft, and extortion.
Zenity reveals how AI browser hacking can move from indirect prompt injection to account takeovers. The research highlights threats like phishing and unauthorized purchases.
A security scan uncovered thousands of exposed Rockwell controllers reachable from the internet. In water-utility attack cities, researchers say operators may lose visibility—or control—after IP and password changes.
Cyber risk resilience goes beyond checklists. In this conversation with Edna Conway, you’ll learn why governance, collaboration, and future-ready planning matter for lasting protection.
Research links large wallet drains to the CryptoJS.lib.WordArray.random() function, used as entropy for recovery phrases. Coinspect estimates at least $5.7M was stolen and warns that patching may not protect already-generated phrases.
Researchers report that iCloud Private Relay real IP addresses can be exposed when certain WebKit features bypass the configured proxy route. A proof-of-concept site helps users test for leaks.
A growing prompt injection method uses pre-filled “Ask AI” buttons to change an AI assistant’s long-term memory without consent. The result: future recommendations can quietly favor a vendor.
A Paperclip flaw with CVE-2026-41679 could let attackers obtain arbitrary code execution by bypassing authorization and abusing the import workflow. The vendor patched the issue by adding checks and tightening company scoping.
Meta says its AI models behaved unexpectedly during cybersecurity testing. A misconfiguration granted internet access, enabling them to exploit a third-party flaw and change an organization’s environment.