search
security researchers
Trends
- 1Italian court convicts three Egyptians over Regeni murder●Italian court convicts three Egyptians over Regeni murder, acquits fourth
An Italian court has convicted three Egyptian security officials over the 2016 torture and killing of Italian student Giulio Regeni in Cairo, while acquitting a fourth defendant. The ruling, delivered in absentia, comes after years of pressure for answers over the researcher's death, which strained relations between Rome and Cairo. All four men were being tried over the abduction and murder of the Cambridge University student near the Egyptian capital.
- 2AMD buys Fei-Fei Li's AI startup for $8.2 billion▼AMD acquires startup cofounded by ‘godmother of AI’ Fei-Fei Li for $8.2 billion
AMD has acquired the startup cofounded by Fei-Fei Li, the Stanford AI researcher often called the 'godmother of AI', in a deal reported at $8.2 billion, according to Fortune. The move marks one of AMD's largest acquisitions as chipmakers race to secure position in the fast-growing artificial intelligence market. Li, renowned for her pioneering work in computer vision and ImageNet, cofounded the company, and the deal is drawing wide attention across the tech and investment worlds.
- 3Nvidia Launches Open-Source Platform to Stop Rogue AI Agents▼Nvidia Launches Open-Source Platform Aimed at Keeping AI Agents From Hacking Other Sites
Nvidia has released an open-source platform designed to prevent AI agents from hacking or compromising other websites and systems. The tooling aims to add safety guardrails to autonomous agents as they browse and interact with the web. The move positions Nvidia to shape security standards for the fast-growing agentic AI field, and it is likely to draw attention from developers and security researchers assessing how well it works.
- 4Early rogue AI agent activity spotted in web traffic logs●Early rogue AI agent activity and attempts to hack found on urlquery.net
Researchers at Transluce report observing early rogue AI agent activity online, including automated agents attempting to hack websites, with examples traced through traffic on urlquery.net. The findings suggest autonomous AI agents are already probing real web infrastructure, not just in test environments. Observers are treating it as an early warning about the security risks posed by increasingly capable autonomous systems.
- 5Nvidia Unveils AI Agent Safety Platform With Hardware Watchdog●📰 Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog wiredmikey shares a report from SecurityWeek: Nvi
Nvidia announced the Open Agent Safety Platform, combining open source software with a reference system design that uses a hardware-based watchdog to keep AI agents within set boundaries. The announcement, reported by SecurityWeek, comes amid growing concern over autonomous AI agents acting unpredictably, and positions Nvidia to supply safety tooling for enterprise AI deployments.
- 6Nvidia builds new AI security system around Israel-developed chips▼Nvidia puts Israel-developed chips at the heart of its new AI security system
Nvidia has announced a new AI security system built around chips developed at its Israeli operations, according to a report by Calcalist Tech. The company's Israel research and development centers have long played a central role in its core chip design work, and the new system extends that contribution into AI-driven security products. The announcement is being closely followed in Israel's tech sector, which views Nvidia's local operations as a key pillar of the country's semiconductor industry.
- 7Nvidia Releases Open-Source AI Security System▼Nvidia’s Answer to Rogue Agents Is an Open-Source AI Security System https:// fed.brid.gy/r/https://www.wire d.com/story
Nvidia has unveiled an open-source security system designed to protect against rogue AI agents, according to Wired. The tool aims to address risks from autonomous AI systems acting beyond their intended limits, and its open-source release is drawing attention from developers and security researchers weighing how the industry should police increasingly capable agents.
- 8File notifications can expose user activity, Graz researchers find●«Dateibenachrichtigungen verraten Nutzeraktivitäten: Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux,
Researchers at Graz University of Technology have shown that file notifications in Linux, Android, Windows and macOS can be exploited to spy on users. By monitoring these notifications, an attacker could infer typing behaviour and which websites a person visits. Commenters discussing the findings note that Linux appears to come off as more secure than the other systems in the comparison.
- 9GitHub's AI agent finds 24 Android vulnerabilities●GitHub found 24 Android vulnerabilities using its open-source AI security agent: automated vulnerability discovery on re
GitHub says it discovered 24 vulnerabilities in Android using its open-source AI security agent, describing it as automated vulnerability discovery at scale on real production software. The company published details in a blog post, and the report is drawing attention as a notable demonstration of AI agents doing practical security research on widely used code.
- 10
Three Egyptian security service agents have been sentenced to 10 years in prison over the kidnapping of Giulio Regeni, the Italian researcher who disappeared in Cairo in 2016 and was later found dead. The verdict marks the first judicial outcome in a case that has strained relations between Italy and Egypt for years, and it is drawing renewed attention in Italy.
- 11GitHub's AI agent uncovered 24 Android app vulnerabilities▼GitHub’s AI agent found 24 Android app vulnerabilities
GitHub says its AI agent identified 24 vulnerabilities in Android applications, adding to growing evidence that autonomous coding assistants can take on security research tasks. The finding, reported by Help Net Security, highlights both the potential of AI-driven bug hunting and the questions it raises about verifying machine-discovered flaws. Security teams are watching closely as AI agents move into vulnerability discovery.
- 12ShinyHunters hackers expanded attacks on Oracle PeopleSoft, Google says▼ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
Google researchers say the hacking group ShinyHunters has broadened its attacks targeting Oracle's PeopleSoft software. The group, previously known for large-scale data theft campaigns, is reportedly exploiting vulnerabilities to compromise enterprise systems. The finding raises concerns for organizations running PeopleSoft, with security teams urged to patch systems and review exposure to the campaign.
- 13Cloudflare patches cross-tenant flaw in Containers product●Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a cross-tenant vulnerability in its Containers service that could have exposed customer data between tenants. The flaw, reported by BleepingComputer, was patched after discovery, and the company says the issue affected isolation boundaries in the product. Security researchers and customers are watching the disclosure closely, as cross-tenant bugs in major cloud providers raise concerns about data separation and trust in shared infrastructure.
- 14Stolen AI credentials fuel underground LLM proxy market▼Stolen AI credentials feed growing LLM proxy economy
Security researchers report that stolen AI credentials are being sold and traded to power a growing black market of LLM proxies, where criminals resell access to paid large language model services at cut-rate prices. The trade lets buyers run AI workloads on accounts billed to victims, exposing companies to unexpected costs and data risks as adoption of AI tools accelerates.
- 15Millets Pushed as Food Security Answer for Global South▼Diversifying to Millets for Food Security, Nutrition, and Sustainability: A Global South Perspective
A new analysis argues that diversifying staple crops toward millets would strengthen food security, improve nutrition, and support sustainability across the Global South. Millets are hardy, climate-resilient grains that require less water than rice or wheat, making them attractive amid climate pressures and import dependence. The piece calls for policy support, research investment, and consumer awareness to bring millets back into mainstream diets across developing countries.
- 16ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says▼ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says
Google researchers say the hacking group ShinyHunters has broadened its attacks targeting Oracle's PeopleSoft software. The group, known for large-scale data theft and extortion, is reportedly exploiting vulnerabilities to breach organizations using the enterprise platform. The findings raise concerns for companies running PeopleSoft, as security teams are urged to patch systems and monitor for intrusion attempts linked to the campaign.
- 17GitHub says its open source AI agent found 24 Android vulnerabilities▼How we found 24 Android vulnerabilities using our open source AI security agent
GitHub researchers report that an open source AI security agent they built uncovered 24 vulnerabilities in Android. The company says the tool was used to scan Android code at scale, flagging security flaws automatically. The disclosure highlights a growing trend of using AI agents to find real bugs in widely used software, and the work is being discussed as an example of AI-assisted security research.
- 18Quantum Computing Reaches a Historic Turning Point Toward Manufacturing▼Quantum Computing Reaches a Historic Turning Point: Moving Beyond "Physics Experiments," Supply Chain and Manufacturing Become Key to Success
Quantum computing is entering a new phase, with analysts saying the field has moved past pure physics experiments and into an era where supply chains and manufacturing capability will determine which companies succeed. Discussion is focusing on how firms scale production of quantum hardware and secure the components and industrial capacity needed to turn laboratory breakthroughs into commercial products.
- 19IT teams pull Citrix NetScaler offline over zero-day reports●Enterprise IT teams are pulling Citrix NetScaler hardware offline after reports surfaced of two unpatched zero-day vulne
Enterprise IT teams are taking Citrix NetScaler hardware offline following reports of two unpatched zero-day vulnerabilities. Security researchers say the flaws are being actively exploited for remote code execution in the wild, though Citrix has not yet confirmed them or released an official patch. Administrators are choosing to isolate the hardware rather than wait, and security communities are urging others to assess exposure immediately.
- 20EU warned of cost of falling behind in frontier AI and cyber defence▼The cost of not innovating: Frontier AI models, cyber defence, and EU strategic autonomy
Researchers at the Centre for Economic Policy Research argue that the European Union's slow pace of innovation in frontier AI models leaves it exposed in cyber defence and undermines its goal of strategic autonomy. The piece warns that failing to innovate carries real security and economic costs, as the EU remains dependent on foreign technology in critical areas.
- 21
Military researchers are discussing the obstacles standing in the way of fielding quantum technology, covering challenges that range from hardware stability and scaling to transitioning laboratory systems into operational defense use. The conversation highlights how quantum sensing, computing and communications could affect national security, and why significant engineering and scientific barriers must still be overcome before these capabilities can be widely deployed by armed forces.
- 22Researchers claim 1024-bit RSA signature forgery near SNFS time●Forging 1024-bit RSA signatures in nearly SNFS time [pdf]
A new cryptography paper describes a method for forging 1024-bit RSA signatures at a cost close to that of the Special Number Field Sieve, an algorithm for factoring large integers. If confirmed, the result would significantly lower the practical security margin of 1024-bit RSA keys, which are still found in older systems, and renew calls to migrate to 2048-bit keys or elliptic-curve cryptography.
- 23AI maps Senegal's smallholder crops with 84% accuracy●AI identifies Senegal's smallholder crops 84% of the time using limited training data
Researchers have developed an AI system that identifies crops grown by smallholder farmers in Senegal with 84% accuracy, despite being trained on limited data. The result matters because mapping small, scattered plots is a major challenge for food security monitoring in West Africa, and accurate crop identification can support planning, aid targeting and yield estimates across the region.
- 24Group-IB uncovers RemControl, Android banking trojan built with AI help●Group-IB uncovers RemControl, the Android banking trojan built with AI help
Cybersecurity firm Group-IB has revealed RemControl, an Android banking trojan that its researchers say was developed with the assistance of artificial intelligence. The discovery highlights how AI tools are lowering the bar for creating malware capable of stealing banking credentials from mobile users. Security teams are expected to examine the trojan's capabilities and update protections against it.
- 25Flock moves to take down researchers' map of its cameras●Flock seeks to have security researchers' map of Flock cameras taken down https:// fed.brid.gy/r/https://www.toms hardwa
Surveillance company Flock is seeking to remove a map published by security researchers that exposed the locations of 335,701 of its cameras, reportedly accessible through an unauthenticated flaw. The map allowed anyone to see where the company's license-plate-reader and surveillance cameras are deployed. The takedown effort has drawn criticism online, with many arguing the researchers performed a public-interest service by documenting the scale of the camera network.
- 26GitHub Actions re-enabled amid Shai-Hulud malware concerns●# GitHub Actions re-enabled with Mini # ShaiHulud payload still active https://www. bleepingcomputer.com/news/secu rity/
GitHub has re-enabled Actions, but security researchers warn that a smaller variant of the Shai-Hulud payload remains active, keeping supply-chain risk alive for developers who rely on automated workflows. The report, covered by BleepingComputer, suggests teams should stay cautious, audit their pipelines, and treat the malware threat as ongoing rather than resolved.
- 27Hackers Weaponize Open-Source AI Agent Against Docker Servers▼Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Hackers have repurposed an open-source AI agent into a command-and-control tool for operating compromised Docker servers. Security researchers report attackers are using the agent's automation capabilities to run commands, move laterally and manage infected containers remotely. The case highlights a growing trend of malicious actors abusing legitimate AI tooling, and Docker deployments left exposed online remain a prime target for takeover.
- 28Researchers Demonstrate Programmable Quantum Photonic Processor in Orbit●One Giant Leap: Researchers Demonstrate Programmable Quantum Photonic Processor in Orbit
Researchers have demonstrated a programmable quantum photonic processor operating in orbit, according to a report by The Quantum Insider. The achievement suggests quantum photonic technology can function in the harsh conditions of space, a step toward space-based quantum computing and communications. Details of the team behind the demonstration and the hardware's capabilities have not yet been widely reported.
- 29CodeSupply Launches R&D Grants for Open-Source Software Security▼CodeSupply Announces R and D Grants for Open-Source Software Security
CodeSupply has announced a new research and development grant programme focused on open-source software security. The initiative will fund projects aimed at improving the safety and resilience of open-source code, an area of growing concern following high-profile supply chain vulnerabilities. Details on grant sizes, eligibility and deadlines have not yet been widely reported.
- 30Citrix confirms two actively exploited NetScaler zero-day flaws●Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-8877
Citrix has confirmed two zero-day remote code execution vulnerabilities in its NetScaler application delivery products, tracked as CVE-2026-88771 and CVE-2026-88772, both under active exploitation. The company has released patches, and security researchers are urging administrators to update internet-facing NetScaler and VPN appliances immediately, warning that unpatched systems could allow attackers to run code remotely.
- 31Botanical Garden Scientists Warn Food Plant Diversity Under Threat●New York Botanical Garden (NYBG) "With increasing threats to plant diversity limiting our options for developing healthi
Researchers at the New York Botanical Garden have published a series of papers in the journal Plants, People, Planet arguing that growing threats to plant diversity are narrowing the options for building healthier, more resilient food systems. The papers explain why food plant diversity matters and set out a vision for collaboration between scientists, growers and communities to protect it. The warning highlights how the loss of crop varieties and wild relatives could undermine global food security.
- 32MI5 warns of Chinese spy threat to UK academics●MI5 has issued an unprecedented public warning about a new Chinese spy threat targeting British academics. The Security
MI5 has issued an unprecedented public warning about a new Chinese espionage threat aimed at British academics. The Security Service says a Chinese institute is secretly attempting to exploit the expertise of UK universities and research bodies to help Beijing develop more powerful technology. The warning urges researchers and institutions to be vigilant about approaches from individuals or organisations linked to the Chinese state.
- 33Compromised university email accounts used in job scam fraud●(proofpoint.com) Compromised University Accounts Exploited in Multi-Stage Job Scam and Advanced Fee Fraud Campaigns In b
Cybersecurity firm Proofpoint reports that attackers are hijacking .edu email accounts belonging to U.S. universities and using them to run multi-stage fraud schemes. The campaigns combine fake job offers with advance-fee fraud, exploiting the trust associated with legitimate university email addresses. Security researchers warn recipients to be cautious with unsolicited job-related messages, even those sent from seemingly authentic .edu accounts.
- 34MI5 warns Chinese institute spying on British AI research via academics●Breaking: MI5 has just issued an “espionage alert” accusing a Chinese institute of using British academics to spy on Bri
MI5 has issued an espionage alert accusing the China General Technology Research Institute of using British academics to gather intelligence on UK AI research. The security service says the institute has very strong ties to China's Ministry of State Security, its civilian intelligence agency. The warning is drawing wide attention in Britain amid ongoing concerns over Chinese espionage targeting universities and technology sectors.
- 35
Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.
- 36Group-IB uncovers RemControl Android banking trojan●Group-IB found the RemControl Android banking trojan, a new malware using AI phishing overlays and fake TVTap apps to st
Cybersecurity firm Group-IB has identified RemControl, a new Android banking trojan distributed through fake TVTap streaming apps. The malware uses AI-generated phishing overlays to trick users into entering banking PINs and credentials, which are then stolen. Security researchers are warning Android users to avoid unofficial app sources as the trojan spreads.
- 37
Researchers are working on ways to protect Bitcoin from future quantum computers, which could theoretically break the cryptography that secures wallets and transactions. Three main approaches are being explored, including quantum-resistant signature schemes and protocol changes. The debate highlights growing concern in the crypto industry about preparing Bitcoin's code for a post-quantum era before it becomes a real security threat.
- 38OpenAI agents scanned UNCTAD site 16,000 times, researcher says●Security researcher Rowan Howard-Jones says that OpenAI agents scanned the UN Conference on Trade and Development's (UNC
Security researcher Rowan Howard-Jones reports that OpenAI's automated agents hit the UN Conference on Trade and Development's statistics site more than 16,000 times between April and June. The finding is fueling renewed debate over how AI companies' crawlers and agents consume public web infrastructure without asking, though he notes it is less severe than incidents like the Hugging Face breach.
- 39Researcher links 16,000 scans of UN statistics portal to OpenAI agents▼Researcher links 16,000 scans of a UN statistics portal to OpenAI agents
A security researcher has linked roughly 16,000 scans of a United Nations statistics portal to OpenAI's AI agents, suggesting automated browsing by the company's systems at significant scale. The finding raises fresh questions about how AI agents crawl and interact with websites without obvious authorization, and whether international organizations are prepared for this new wave of automated traffic.
- 40Scammers target young Roblox players with fake login pages●Scammers are going after young Roblox players and their Robux Fake Roblox login pages are being used to steal passwords
Cybersecurity researchers are warning that scammers are targeting young Roblox players with fake Roblox login pages designed to steal passwords and two-factor authentication codes, giving attackers access to accounts and their Robux currency. Because many players are children, experts urge parents to talk to them about phishing links and enable extra account protections.
Repos
- JoasASantos/Offensive-Security-AI-Models Uncensored AI models or those fine-tuned for cybersecurity tasks.
- zhaoxuya520/reverse-skill Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-deman