Security & Vulnerabilities (SEC) Intelligence Hub
Real-time accumulated intelligence, primary research, and executive digests for Security & Vulnerabilities (SEC).
OTora exposes reasoning level DoS for LLM agents
Researchers introduced OTora, a two-stage red-teaming framework that launches reasoning-level denial-of-service attacks against LLM-based agents, dramatically increasing their reasoning tokens and latency while largely preserving task correctness and accuracy across several agent benchmarks. The work targets a previously underexplored vulnerability where adversaries bloat an agent’s reasoning depth or tool-use budget instead of corrupting outputs. OTora crafts adversarial triggers and reasoning payloads that systematically induce excessive, yet still goal-consistent, deliberation. Experiments on WebShop, email, and operating-system agents built on models such as LLaMA-70B and GPT-OSS-120B show order-of-magnitude slowdowns. The authors also outline mitigation strategies for detecting abnormal reasoning spikes and constraining latency in deployed systems.
Read Original Source ↗JFrog finds Shai Hulud npm malware campaign
Researchers reported a renewed Shai Hulud malware campaign on npm, compromising more than 428 packages and 1,700 versions, starting with popular caching libraries keyv and cacheable, and targeting multiple operating systems and development environments. The JavaScript-based worm steals secrets from local machines, CI systems, clouds, Kubernetes, Vault, and developer tools, then uses stolen npm and GitHub credentials to republish infected packages and inject malicious files and workflows into reachable repositories. Victims are urged to treat any installation of affected versions as compromised, review tokens and secrets, monitor GitHub branches and workflows, and follow ongoing research updates as investigators expand the known package and victim scope.
Read Original Source ↗Microsoft warns CaptiveCrunch hotel WiFi attacks
Microsoft researchers report a threat group is infecting hotel Wi-Fi networks with custom malware, CaptiveCrunch, to steal guests’ Microsoft 365 credentials and session cookies when they connect through captive portals. The attackers reportedly compromise routers and access points, inject malicious JavaScript into captive portal pages, and capture authentication tokens. Stolen cookies allow unauthorized access to corporate email, documents, and other cloud resources without needing passwords. Microsoft has updated detections and is notifying affected customers, while urging organizations to enforce multifactor authentication and conditional access policies. Security experts recommend using VPNs, avoiding sensitive logins on public Wi-Fi, and monitoring accounts for suspicious activity.
Read Original Source ↗VulnCheck reports 1.3 percent AI discovered exploits
Security firm VulnCheck reports that only 1.3 percent of AI-discovered software vulnerabilities were confirmed exploited in the first half of 2026, nearly matching exploitation rates for vulnerabilities found by traditional methods. Researcher Patrick Garrity tracked 1,061 AI-assisted vulnerabilities, of which fourteen were exploited. Anthropic’s Project Glasswing yielded over 23,000 findings, but just 126 became published entries and only one has been used in an attack. Although exploitation rates remain low, attacks occur sooner after disclosure: the median time dropped from 120 to 80 days, with about 23 percent exploited on or before disclosure, increasing urgency for faster defensive responses.
Read Original Source ↗CrowdStrike reports AI systems under direct attack
CrowdStrike’s 2026 Threat Hunting Report finds artificial intelligence systems are now being directly targeted, with attacks on AI infrastructure, model access and large language model services joining a broader surge in automated intrusions. The report says attackers adopt exploits within hours of disclosure, with most proof-of-concept code weaponized in under two days. China-linked and other groups rapidly abused React2Shell, npm packages, GitHub actions and cloud resources using stolen identities. CrowdStrike concludes adversaries are both using and attacking AI, favoring fewer, more complex campaigns. Technology, financial services and academia face rising pressure, with recommended responses including securing AI infrastructure and applying AI-driven detection at comparable speed.
Read Original Source ↗