AI & software security
-
AI helps port exploit between WAGO PLCs
Forescout researchers used AI to adapt an exploit between WAGO industrial controllers, but the experiment still demanded specialist intervention, substantial compute cost, and damaged hardware.
-
Infostealers hijack Claude sessions for paid usage
Anthropic is warning affected customers that commodity infostealers stole active Claude sessions, allowing attackers to access accounts without repeating the normal authentication process.
-
New Nodemailer CVEs formalise patched flaws
Six Nodemailer vulnerabilities have received CVE assignments, consolidating previously disclosed flaws involving server-side file access, SSRF, TLS validation, and message handling.
-
UK opens £100m sovereign AI buying scheme
The UK has opened its first competitions under a £100 million Sovereign AI procurement programme, including dedicated work on AI-agent security and secure defence integration.
-
Tenable patches critical Security Center flaws
Tenable has issued stand-alone patches for Security Center and Enclave Security vulnerabilities, including a critical authenticated remote-code execution flaw rated 9.9 under CVSS v3.1.
-
ChatGPT enters EU’s toughest DSA tier
The European Commission has designated ChatGPT as a Very Large Online Search Engine, bringing the service into the Digital Services Act’s enhanced systemic-risk and oversight regime.
-
Missed TeamCity patch exposed JetBrains Cadence
JetBrains says attackers exploited an unpatched TeamCity vulnerability in its Cadence service, exposing customer data, cloud identities, and credentials contained in an older server backup.
-
ServiceNow fixes three maximum-severity flaws
ServiceNow has patched three AI Platform vulnerabilities rated CVSS 10.0 that can expose instance data, enable privilege escalation, or permit arbitrary database operations without authentication.
-
Cursor enters European cyber intrusions
Recovered chat logs show a ransomware operator using Cursor during attacks affecting European organisations, with researchers documenting repeated attempts to bypass the coding agent’s safety controls.
-
Unit 42 finds AI malware mostly experimental
Unit 42 says only a small fraction of more than 400 AI-associated malware samples in its study appeared on production endpoints, underscoring a gap between research artefacts and operational attacks.










