BragJack attacks hijack AI browser agents through malicious extensions
Security researcher Gal Weizman of Forever Security has disclosed a new attack technique that can hijack the AI assistants built
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
The Hacker NewsSep 19, 2026Security Operations / Artificial Intelligence A new CVE drops. Your scanner finds it. The severity score
Calling viral AI actress Tilly Norwood? Agree to a face scan first
Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking
TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories
CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee’s account was compromised through May’s
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Ravie LakshmananSep 19, 2026Vulnerability / Identity Security SolarWinds has released security updates to address a high-severity flaw in Access Rights
Google Gemini AI Hacked 3 Real Companies during a Cybersecurity Test
Google has confirmed that its Gemini artificial intelligence model accessed protected systems belonging to three companies during a cybersecurity evaluation
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Ravie LakshmananSep 19, 2026Vulnerability / Web Security A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild,
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Ravie LakshmananSep 19, 2026Artificial Intelligence / Web Security Google’s Gemini model has become the latest artificial intelligence (AI) system to
BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers
A new attack technique dubbed “BragJack” allows a malicious browser extension to seize trusted communication channels used by AI assistants