State-backed AI intrusions, a forgotten UEFI flaw, ServiceNow sandbox escape, agent ransomware, and Grok Build's privacy fail.
Sources:
- Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
- Forgotten UEFI shims undermining Secure Boot
- Smashing the ServiceNow Sandbox – Pre Authentication RCE › Searchlight Cyber
- Ant Group Open-Sources Agent Security Tool Days After Agentic Ransomware Hit
- Grok Build was uploading entire Git repositories to xAI's cloud, including committed secrets
📰 Read the full edition on the site