❌

Normal view

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

20 August 2026 at 14:36
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

20 August 2026 at 12:01
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack, which the researchers named "Zombie Card," requires physical

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

20 August 2026 at 11:39
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu,

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

20 August 2026 at 11:05
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

19 August 2026 at 19:02
Cybersecurity researchers have disclosed details of aΒ remote Spectre attackΒ against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,

❌