π§©GitLab Patches Critical Account Takeover Vulnerability
GitLab released emergency patches for a critical authentication bypass vulnerability that could allow attackers to take over accounts without valid credentials under specific conditions. Security teams are being urged to update immediately due to the risk of unauthorized access across development environments.
π€Researchers Demonstrate Autonomous AI Worm Capable of Spreading Across Agents
Security researchers demonstrated a proof-of-concept AI worm capable of autonomously spreading between AI-enabled systems using prompt injection techniques. The research highlights growing concerns around interconnected AI workflows and the operational security risks of rapidly deployed AI tooling.
βοΈSnowflake Customers Continue Facing Data Theft Extortion Attempts
Multiple organizations tied to the ongoing Snowflake credential theft campaign continue reporting extortion attempts after attackers leveraged stolen credentials and weak authentication practices to access cloud-hosted data environments.
π‘VMware Warns of Active Exploitation Against ESXi Vulnerabilities
Broadcom issued warnings regarding active exploitation of multiple VMware ESXi vulnerabilities that allow privilege escalation and virtual machine escape scenarios. Administrators are being urged to prioritize patching internet-facing virtualization infrastructure immediately.
π οΈMalicious npm Packages Found Targeting Developer Environments
Researchers identified several malicious npm packages designed to steal environment variables, developer tokens, and CI/CD secrets from software development environments. The packages were downloaded thousands of times before removal, reinforcing continued software supply chain concerns.



