Friday, April 24, 2026

AI

LegalPwn Attack Exploits AI Tools Like Gemini and ChatGPT Using Disclaimers to Run Malicious Code

The attack, dubbed "LegalPwn," was revealed in groundbreaking research by AI security firm Pangea and represents a significant evolution in prompt injection techniques that exploit the fundamental compliance programming of large language models. A sophisticated new cyberattack has been discovered that tricks leading artificial intelligence...

AI-Powered FunkSec Ransomware Decryptor Now Available for Free

Avast cybersecurity researchers, in cooperation with global law enforcement agencies, have announced the public release of a free FunkSec ransomware decryptor, marking a significant win in the ongoing battle against cybercrime. The tool comes after months of investigations and technical analysis, following FunkSec’s rapid...

Critical AI Vibe Coding Platform Vulnerability Exposes Unauthorized Access to User Private Apps

A critical security vulnerability in Base44, a popular AI-powered "vibe coding" platform recently acquired by Wix, that allowed unauthorized access to private applications built by users. The vulnerability, which has since been patched, could have exposed sensitive enterprise data including internal chatbots, HR operations,...

WhoFi, an AI-powered Wi-Fi biometrics system, can track humans behind walls with an impressive 95.5% accuracy

Researchers have developed a groundbreaking artificial intelligence system called WhoFi that can identify and track individuals through walls using only Wi-Fi signals, achieving an impressive 95.5% accuracy rate. This innovative approach represents a significant leap forward in biometric identification technology, offering a privacy-preserving alternative...

Cybersecurity Alert – AI-Driven Web3 Scam Targets Users with Fake Platforms to Harvest Credentials

A sophisticated cybercriminal group known as LARVA-208 has launched a new campaign targeting Web3 developers through an elaborate phishing scheme involving fake AI workspace platforms. The operation represents a significant evolution in the group's tactics, shifting from targeting traditional IT staff to exploiting the...

NVIDIA AI Container Toolkit Faces Critical Vulnerability as PoC Exploit Emerges

Wiz Research has disclosed a critical container escape vulnerability in the NVIDIA Container Toolkit, dubbed NVIDIAScape, that poses a significant threat to the security of AI cloud services worldwide. The flaw, tracked as CVE-2025-23266 with a CVSS score of 9.0, enables malicious containers to bypass...