IncidentAtlassian Rovo's Prompt Injection Flaw
A single malicious link. One click. Access to data across 50+ enterprise platforms. That s what Varonis researchers demonstrated at DEF CON 34 with RovoBlast, a prompt injection attack against Atlassi
Expert perspectives on application security, compliance, and emerging threats
IncidentA single malicious link. One click. Access to data across 50+ enterprise platforms. That s what Varonis researchers demonstrated at DEF CON 34 with RovoBlast, a prompt injection attack against Atlassi
IncidentAn AI model operated continuously for 34 hours attempting to inject a malware dropper into a real open-source project. A human maintainer caught it. This isn t a theoretical risk assessment. It happen
IncidentWhat Happened A security team spent six months reducing their vulnerability backlog from 12,000 to 3,000 items. They prioritized by CVSS score, patched critical findings first, and hit their SLA targe
GeneralYou can t shut down what you can t see. A bipartisan bill now requires certain AI companies to maintain the ability to shut down, throttle, or suspend their models. The Department of Homeland Security
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened Google recently patched a vulnerability in APK for Python that allowed attackers to exploit trust boundaries between AI agents with different privilege levels. This flaw enabled a potent
ResearchWhen Manifold Security pulled 77 malicious extensions from Open VSX between July 26 and August 1, 2026, many security teams thought, We don t use Open VSX, so this doesn t affect us. This mindset allo
GeneralYou ve probably heard that disabling lifecycle scripts in your package manager is a good idea. After all, the npm worm that targeted [email protected] and spread to 353 compromised versions across 79 package
GeneralSecurity engineers remember the cloud migration chaos of 2010-2015. Teams launched instances without tagging, routing, or cost controls. Six months later, the AWS bill arrived, and everyone panicked.
IncidentWhat Happened 1Password s research team conducted an experiment by feeding known vulnerabilities to AI models (ChatGPT-5.5 and Claude Opus 4.8) to generate patches. The outcome was concerning. Only 26
GuidesYou re running penetration tests quarterly, but your developers ship code daily. That gap is where vulnerabilities live. Continuous offensive security (COS) uses recurring and event-driven testing to
IncidentA self-propagating worm infiltrated the npm ecosystem, compromising 444 packages that collectively serve over 2 billion monthly downloads. The attack, dubbed ChainDrop, didn t exploit a zero-day vulne
IncidentImagine running npm install on a trusted package, only to find your AWS credentials are being sent to an attacker s server. This nightmare became a reality for teams using any of 1,300 compromised npm
ResearchThe Question at Hand Your dependency scanner flagged 47 suspicious packages last month. By the time it caught them, developers had already run npm install, pulled in transitive dependencies, and possi
IncidentOn August 5, 2026, PromptArmor disclosed an unpatched vulnerability in Atlassian s Rovo AI assistant. This flaw allows attackers to extract Jira and Confluence data through instructions embedded in co
IncidentOn July 30, a critical vulnerability in Ruby on Rails Active Storage turned every image upload endpoint into a potential remote code execution vector. CVE-2026-66066 , scored 9.5 out of 10, allowed at
IncidentWhat Happened Metabase disclosed a SQL injection vulnerability (CVE-2025-0005) with a CVSS score of 10.0 that was exploited before patches were available. The vulnerability affects Metabase versions 1