CyberNotableConfirmedDeveloping
10.0
New malware variant targets AI development infrastructure for data exfiltration and sabotage
WIRED SecurityHI·about 6 hours ago
Researchers identified a vulnerability in AWS Kiro allowing attackers to execute arbitrary code by embedding hidden instructions in web pages. The flaw bypasses security approval prompts, enabling the AI to modify its own configuration when tasked with summarizing malicious sites. This highlights a critical security boundary failure in LLM-integrated development tools.
Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.