A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children. Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled “faces” and “profiles.” Fowler said the images he reviewed included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification. “I recently discovered a publicly exposed database that was neither password-protected nor encrypted,” Fowler said. “The database…
Kirsten Doyle
A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on August 9. The message came from an account that claimed to be the vice president and marketing head of CoinDesk and wanted to know about the researcher’s plans to attend future conferences. The researcher spotted the scam but kept the conversation going to find out what the…
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and organisations during a controlled cybersecurity evaluation. This included attempts to socially engineer software maintainers and insert malicious code into an open-source project. The incident happened during routine cyber capability testing between 25 and 28 July, when researchers gave AI agents access to the public internet and deliberately disabled some cyber safety mechanisms to better understand how the models behave under less restrictive conditions. According to AISI, researchers ran a cybersecurity challenge 122 times across seven frontier models. …
AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, and helping organisations fix problems faster. It also raises serious questions about the quality of code, its security, accountability, and trust. When an AI writes or patches the code, who will ensure that it is indeed secure? And, are the current application security practices adequate…
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links. According to the researchers, clicking one of these links caused the application to automatically open, import a prompt from the URL, and immediately submit it without displaying the full prompt or requiring user approval. Anthropic addressed the issue in Claude Desktop version 1.1.2321. Hidden instructions Oasis Security demonstrated the attack using…
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors. According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk. The campaign is being tracked across the cybersecurity industry under several names,…
Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number. One in three have missed a call from a doctor, hospital, or healthcare provider, while others report missing calls from employers, pharmacies, financial institutions, government agencies, and even family emergencies. The findings come at a time when cybercrime losses have hit a new all-time high. According to the FBI’s Internet…
Security researchers at Sysdig have documented what they believe is the first documented case of an AI agent running a ransomware operation from end to end. Dubbed JADEPUFFER, the operation used a large language model (LLM) to automate an attack that began with the exploitation of an internet-facing Langflow instance and ended in destructive database extortion. Sysdig’s research describes an AI-driven campaign that adapted to failures, harvested credentials, searched for sensitive data, moved toward its intended target, and attacked a production database server. The attackers initially exploited CVE-2025-3248, a missing-authentication vulnerability in Langflow’s code validation endpoint that allows unauthenticated remote…
AI can generate code faster than most software organizations can absorb it. This should be a productivity breakthrough, but it also exposes a larger problem: many of the processes surrounding software delivery still happen at human speed. A new white paper from code4thought looks at what happens when AI changes how quickly teams write software, and what software engineering produces, how organizations govern it, and where engineers add the most value. AI-Assisted Software Engineering: The New Delivery Paradox pulls from six in-depth conversations covering security, product engineering, academic research, regulated industry, retail banking, and AI assurance. The expert contributors do…
A supply chain attack targeting Klue, a competitive intelligence platform, has lead to the theft of Salesforce data from multiple entities, including several cybersecurity vendors. Klue disclosed that threat actors had gained unauthorized access to part of its integration infrastructure in June after compromising a legacy credential linked to a backend system. “Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce,” Klue said. According to incident investigations published by Huntress and other…
