Hackers used a malicious worker to inject scripts into more than 100,000 websites via the Brevo supply chain attack.
Browser AI agent security research: security researcher Gal Weizman of Forever Security demonstrated that one ordinary browser extension can hijack AI agents in Chrome, Edge, Perplexity Comet, Opera ...
A new type of attack hijacks AI assistants built directly into a browser to access sensitive information, execute malicious ...
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension.
Microsoft 365 phishing MFA bypass platform BigBear 2.0 compromised 258 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing ...
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG  5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
The campaign reportedly targeted visitors through Brevo’s embedded tracker, chat widget, hosted forms, and unsubscribe pages.
A government organization providing cloud infrastructure to Indian companies is inadvertently distributing malware.
Magento zero-day vulnerability CVE-2026-75650 exploited a fully patched store for three days before Adobe released APSB26-146 on September 7. A self-updating Rust backdoor survived the patch, evaded ...
PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
MCP is now stateless at the protocol level. The Mcp-Session-Id header and the initialize/initialized handshakes that linked clients to specific server instances have been removed. The protocol version ...