company · 7 records
Palo Alto Networks

JADEPUFFER group targets AI infrastructure using new ENCFORGE ransomware strain
A threat actor known as JADEPUFFER deployed a new Go-based ransomware strain called ENCFORGE targeting AI model files and infrastructure after exploiting a remote code execution vulnerability in Langflow.

Russian hackers exploit Zimbra vulnerability to steal email data
A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal email data and authentication codes from Western government and commercial organizations between July 2025 and early 2026.

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google, Anthropic, and OpenAI have released new AI cybersecurity models and safety initiatives to aid defense while addressing risks of model misuse and unauthorized actions.

Researchers identify three passkey hijacking vulnerabilities in Google Chrome Password Manager
Unit 42 researchers disclosed three passkey hijacking vulnerabilities in Google Chrome Password Manager requiring local malware compromise on Windows systems.

NVIDIA launches security alliance and open source framework for AI systems
NVIDIA formed the 37-member Open Secure AI Alliance and released the open-source NOOA framework to enhance AI security following reported agent-related security incidents.

Qilin ransomware gang exploits critical Palo Alto Networks VPN vulnerability
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN to breach corporate networks.

Researchers identify new IoT botnet developed with potential AI assistance
Palo Alto Networks Unit 42 researchers disclosed TuxBot v3 Evolution, a modular IoT botnet framework developed with apparent LLM assistance, exhibiting multi-architecture compilation, encrypted C2 channels, DDoS capabilities, and lineage tied to the Keksec threat ecosystem.