Content Paint

Security

(Human) JFrog Artifactory attackers are minting admin keys

From nobody to admin with One Neat Trick.

How a vibe-coded app let hackers use $600k worth of AI tokens at METR

"Because we were not paying for these tokens, there was no natural token spend ceiling..."

The Pentester’s 0days: What (exploited) VMware bugs say about the changing face of infosec

Thirty minutes to arbitrary file write; 30 more to root -- and to two critical VMware CVEs.

Australian police, FBI arrest two over TeamPCP attacks

Cat videos, a HackerOne account, and a TikTok profile helped reveal the identities of alleged attackers.

CISA spots Oracle bug exploitation seven months after patch

Government security teams given just three days to patch the CVSS 10 vulnerability.

Vercel puts $1m on the table for hackers to escape its sandbox

Hackers have just two weeks to find a vulnerability.

France tax agency hack affects at least 678,000

Attackers claim millions more may have been affected.

NIST asks industry what to do about AI and vulnerabilities

National Vulnerability Database is due for further modernisation after cuts to CVE enrichment programme.

Patching in the AI era: Move fast, even if it breaks things

Security teams are feeling the pressure of AI-powered bug disclosure. Is it time to change how we patch?

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.