ReversingLabs

AI coding puts Secure by Design in the spotlight

Key takeawaysSame old flaws, bigger stakes: ~40% of CISA’s exploited-vulnerability catalog traces back to well-understood, preventable weaknesses (memory safety, input validation, injection).Attackers aren’t chasing zero-days: CVE disclosures more than doubled year over year, but exploited vulnerabilities grew only 20% — known gaps are still the target.AI raises the urgency: it speeds up vulnerability discovery and exploit development, shrinking the window before flaws get found and weaponized.T

Read More
ReversingLabs

Memory-safe programming goes from advocacy to adoption

Key takeawaysCISA/NSA’s report cited memory-safety issues behind 66-71% of major OS CVEs and 75% of in-the-wild exploited vulnerabilities, driving real adoption momentum.Adoption faces real headwinds: legacy C/C++ is too vast to rewrite wholesale, and experts say MSLs work best for new code, not replacing proven systems.AI is accelerating migration (Google’s Gemini-assisted Rust rewrite ofgiflibis an early proof point), but human review is still required — the AI-generated code itself had defect

Read More
Krebs

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp.today released software updates to plug at least 570 security holes in itsWindowsoperating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could us

Read More
Krebs

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giantLG Electronics USAsaid this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions.

Read More
Krebs

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.Pedro Faléis a threat

Read More
ReversingLabs

AI changes cyber spending — but where’s the line-item for tokens?

AI is increasing both the volume and speed of cyberthreats, pushing organizations to invest more in AI-powered security capabilities to keep pace. Yet overall cybersecurity budgets are barely growing, suggesting that much of the increased spending on AI is coming at the expense of traditional security tools.Arecent survey by IANS and Articoshows that AI investments in cybersecurity have become a priority for 69% of organizations, with 24% giving AI its own security budget line. Others are foldin

Read More
Trend Micro

Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure

Cyber ThreatsFederal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. InfrastructureTrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.By: Jamal BetheaJul 23, 2026Read time:(words)Save to FolioKey takeawaysMultiple federal agencies updated their joint CISA advisory, warning that attackers manip

Read More
Trend Micro

Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It

Return to TrendAI™ Security BlogAI & emerging technologiesCyber crimeInside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind ItOpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained.Research featuresAIGenerative AILLMsAI governanceCyber threatsInformation technol

Read More