UTC, a GitHub advisory was published detailing a critical vulnerability in the PraisonAI multi-agent orchestration framework. Exactly 3 hours, 44 minutes, and 39 seconds later, the first targeted ...
MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
In July, Sysdig threat hunters uncovered JadePuffer, the first-ever documented agentic ransomware infection in which an LLM drove the entire extortion operation, from gaining initial access to ...
Microsoft disclosed a cluster of 12 vulnerabilities affecting Azure and M365 environments. Among them was CVE-2026-85889, an authentication bypass in Azure AI Foundry-the enterprise platform designed ...
Storm-3168, an AI-orchestrated threat actor also known as JADEPUFFER, used two compromised service principals to delete 100+ ...
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage and ...
A 16-year-old security researcher known as Faav has disclosed a critical authentication flaw in Microsoft’s internal Titan ...