Reset
Cybersecurity
Kimi K3 under the microscope: AISI/CAISI institutes evaluate its cyber capabilities, a Redis RCE PoC emerges
Kimi K3 under the microscope: AISI/CAISI institutes evaluate its cyber capabilities, a Redis RCE PoC emerges

New stone in the "Offensive LLMs" file after the Hugging Face breach and the OpenAI sandbox exploit: UK AISI and CAISI publish a preliminary assessment of the cyber offensive capabilities of Kimi K3, the Chinese open-weight model with 2.8 T parameters. In parallel, a researcher releases a functional exploit against the latest Redis server obtained via this same model.

Jul 25, 2026 7 2

Cybersecurity
BlueNoroff: a Zoom kit tailored for crypto, with live AI deepfake video
BlueNoroff: a Zoom kit tailored for crypto, with live AI deepfake video

The North Korean group BlueNoroff (Lazarus) has been operating a Zoom/Teams phishing kit since May 2026 that compromises legitimate Telegram accounts, invites targets to a fake meeting, captures their webcam, overlays an AI deepfake (ChatGPT), profiles installed crypto wallets, and then pushes malware via ClickFix. Five versions of the kit documented by JUMPSEC.

Jul 24, 2026 8 2

Cybersecurity
GitHub Actions hijacked to scan cPanel/WHM: 10 PHP packages compromised and CVE-2026-41940 exploited at scale
GitHub Actions hijacked to scan cPanel/WHM: 10 PHP packages compromised and CVE-2026-41940 exploited at scale

Socket.dev documented a campaign where 583 GitHub Actions workflows slipped into 10 PHP packages scan the Internet for cPanel/WHM instances vulnerable to the CVE-2026-41940 authentication bypass - to steal almost all available credentials. Approximately 6,100 workflows bear the campaign's signature on GitHub.

Jul 23, 2026 18 3

Cybersecurity
Hugging Face breach: when an autonomous AI agent serves as a swarm-scale intrusion tool
Hugging Face breach: when an autonomous AI agent serves as a swarm-scale intrusion tool

On July 20, 2026, Hugging Face revealed a breach in its production infrastructure. The entry was made through a malicious dataset, but the most disturbing aspect is elsewhere: the post-intrusion operations were carried out by an "autonomous agent framework" executing thousands of actions across a swarm of ephemeral sandboxes.

Jul 20, 2026 23 3

LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information