Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 10 janvier 2026Flux principal
À partir d’avant-hierFlux principal

Are Copilot prompt injection flaws vulnerabilities or AI limits?

Par : Ax Sharma
6 janvier 2026 à 12:16
Microsoft has pushed back against claims that multiple prompt injection and sandbox-related issues raised by a security engineer in its Copilot AI assistant constitute security vulnerabilities. The development highlights a growing divide between how vendors and researchers define risk in generative AI systems. [...]

Trust Wallet confirms extension hack led to $7 million crypto theft

Par : Ax Sharma
26 décembre 2025 à 10:47
Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers. [...]

Trust Wallet Chrome extension hack tied to millions in losses

Par : Ax Sharma
26 décembre 2025 à 10:47
Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers. [...]

CISA flags ASUS Live Update CVE, but the attack is years old

Par : Ax Sharma
22 décembre 2025 à 12:09
An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the CVE documents a historic supply-chain attack in an End-of-Life (EoL) software product, not a new attack. [...]

Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374

Par : Ax Sharma
22 décembre 2025 à 12:09
An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the CVE documents a historic supply-chain attack in an End-of-Life (EoL) software product, not a new attack. [...]
❌
❌