SOCRadar uncovered a phishing-as-a-service platform that rents out AI voice agents posing as Apple Support to trick stolen-iPhone victims into handing over their Activation Lock passcode.
SOCRadar uncovered a phishing-as-a-service platform that rents out AI voice agents posing as Apple Support to trick stolen-iPhone victims into handing over their Activation Lock passcode.
Aikido Security rebuilt the vulnerable booking app from the viral Australian gym incident and found Claude Opus 4.6 on OpenClaw exploited it in 9 of 10 runs, unprompted.
Google's Mandiant disclosed technical details of its Agentic Vulnerability Discovery Harness (AVDH), a multi-agent AI pipeline that found over 100 true-positive critical vulnerabilities in a stolen-repository incident response in two days, with 12 CVEs assigned so far.
Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
OpenAI disrupted a Russia-linked influence campaign that used ChatGPT to build a fake Israeli think tank, complete with a custom index designed to rank Russia above the United States.