Securing AI agent harness files from config attacks
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades…
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades…
The need and ability to face the challenge with a clear plan In today’s technological landscape, organizations managing critical infrastructure face a complex paradox: how to leverage the agility of…
The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a…
Evelyn Stealer Abuses Visual Studio Code Extensions in Multistage Attacks A sophisticated multistage malware campaign, dubbed “Evelyn Stealer,” is exploiting the Visual Studio Code (VSC) extension ecosystem to compromise software…
Executive Summary The SolarWinds supply chain attack in 2020 reminded the world how a single weakness in trusted software can have global consequences. That incident reshaped how organizations view software…
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes…
Firewall migration is one of those projects that looks straightforward on a whiteboard and becomes complicated fast during execution. Configuration dependencies you did not know existed. Interruptions that force you…
If Q1 set the pace for Rapid7’s tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release…
Malware: BEACON, Cobalt Strike, EKZ Infostealer, EKZ Stealer, GOLD IONIC, Inc, INC, Incransom, INC Ransom, INC Ransomware, Lynx, Lynx Ransomware, RainINC, Ransom.Inc, Tarnished Scorpion, Warble, Water Anito CVEs: CVE-2019-6693, CVE-2020-9289,…
Executive Summary A Russian-speaking threat actor known as “Trim” has spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as…