When AI gets a body, it inherits an attack surface
Embodied AI puts a model inside a machine that operates in the physical world: a robot, an arm, a humanoid. Once a model gains motors, sensors and a body, it…
Embodied AI puts a model inside a machine that operates in the physical world: a robot, an arm, a humanoid. Once a model gains motors, sensors and a body, it…
Amelia Coen | Friday, 12 September 2025 at 12:21 UTC Arman S. (Tess), a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite…
Every so often, a vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. Recently, the Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in…
In this article AI agents aren’t only smarter API callers. They plan, chain actions across systems, and invoke tools in sequences while no single human explicitly approves each step. The…
The Cybersecurity and Infrastructure Security Agency (CISA) and four international cybersecurity agencies have published guidance urging software manufacturers and online service providers to establish coordinated vulnerability disclosure (CVD) programs, saying…
Andrzej Matykiewicz | Thursday, 18 September 2025 at 15:51 UTC Note: This is a guest post by pentester and researcher, Tom Stacey (@t0xodile). You’d think that after almost 21 years…
Children are diving into the digital world earlier than ever, making it essential to instill good cyber habits from the start. This year, a staggering 80% of internet users under…
In this article On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI…
Miggo researchers discovered two vulnerabilities that could allow attackers to seize control of vulnerable message brokers or expose data across shared environments. While there is no evidence either vulnerability has…
Initially the attackers released new package versions with two malicious scripts that get executed at install time using a preinstall hook in the configuration script. The scripts also execute platform-specific…