ReversingLabs

Why the smartest LLMs are not-so-smart pen testers

Key takeawaysThe harness matters more than the model:Ridge Security’s benchmark of eight leading LLMs found that how well an AI does at autonomous pen testing depends more on the system around the model than on how smart the model is.Higher coverage costs a lot more:Grok 4.5 had the highest coverage at 77%, and Claude Opus 4.6 reached 63% at $217 per run. Smaller and open-source models like Gemini 3 Flash and GPT-OSS-120B cost a fraction of that, and a well-built harness can close much of the ga

Read More
Krebs

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members ofTeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.Ina statementreleased today, theAustralian Federal Police(AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”The

Read More
Krebs

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of theFederal Bureau of Investigation(FBI) today l

Read More
Krebs

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp.today issued updates to plug at least 974 security holes in itsWindowsoperating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.Image: Shutterstock.com, Kirill Makarov.This month’s patch bundle obl

Read More
Krebs

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data brokerRadaris.comhas long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in

Read More
Krebs

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 millionAT&Tcustomers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.One of several selfies from the Facebook page of Cameron Wagenius.Cameron John Wagenius, 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona “Kiberphant0m.” Worki

Read More
ReversingLabs

31 Red Hat npm packages backdoored by Miasma in 72 seconds

RL researchers have uncovered a large-scale, coordinated supply chain attack targeting the@redhat-cloud-servicesnpm scope. On June 1, an attacker published malicious versions of 31 packages (update) in a 72-second window, injecting obfuscated preinstall malware into every one.The affected packages collectively represent approximately 9.8 million total downloads and cover the full breadth of Red Hat’s Hybrid Cloud Console JavaScript ecosystem — UI components, API clients, build tooling, configura

Read More
ReversingLabs

Agentic AI risk isn’t a model problem. It’s an architecture problem.

With artificial intelligence, trust isn’t what it used to be. AI is prodding security teams to move from static, binary, identity-based trust toward dynamic, probabilistic, behavior-based trust. They’re also adjusting to a shift in security from the component layer of applications to the data layer.AI pushes a meaningful portion of security risk up from static components — libraries, services, containers — and into the data and context the system consumes at runtime, said Christopher Jess, senio

Read More