AI just had a big week on both sides of the security line, catching a 13-year-old Chrome bug on one hand, breaching real companies during a botched test on the other. Add a hard-coded credential zero-day, a patchable NGINX flaw, and an autonomous DeepSeek-powered intrusion
This week's security news covers a lot of ground, but a pattern runs through nearly all of it: systems built to enforce a trust boundary quietly failing to do so. This roundup covers five separate disclosures: a Check Point authentication bypass already under active exploitation, an OpenAI agent
msaRAT: The Malware That Never Talks to the Internet Directly Cisco Talos has uncovered a new Rust-based remote access trojan tied to the Chaos ransomware group, and it takes an unusual approach to command-and-control that keeps the malware itself completely off the network. What You Need to
FakeGit Used 7,600 GitHub Repositories and AI Registries to Deliver SmartLoader Malware A supply chain attack doesn't need to wait for a developer to stumble onto a poisoned package anymore. Here's how a campaign called FakeGit turned thousands of fake GitHub repos into a distribution