lithos Twitter
Lithos Header
Last Updated
Age in hrs 
1
2
3
5
8
13
21
34
55

 Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers  - Modern frontier AI models deploy safety classifiers. These are second AI models that sit between the user and the frontier model, evaluating every request in real time. If a request is flagged as harm[…]

 Analyzing 2026's most prevalent browser attack techniques  - 4 in 5 ClickFix attacks are reached via search engine results. 30+ criminal device code phishing kits in the wild, up from zero last year. 90% of phishing kits generated with the help of AI. Phishing domains active for an average of 2 days before being rotated for a fresh one.

 Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products  - A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian...

 IQVIA fined $7.8 million for failing to properly anonymize health data  - Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization.

 The Credential Layer Is Expanding Faster Than Security Teams Can See It  - Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because...

 150" Long Term Support (LTS) channel for ChromeOS - Major update from 144- 150  - The Long Term Support Candidate LTC-150 has been promoted to ChromeOS LTS-150 and is rolling out to most ChromeOS devices. The current version is 150.0.7871.256 (Platform Version: 16700.66.0 ).

 LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings  - A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled....

 Criminals Invade Solihull Home In Violent Crypto Attack  - Three robbers and fourth remote mastermind attack Solihull businessman with hammers, threaten pregnant wife in targeted crypto robbery

 Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365  - For many organizations, Microsoft 365 environments are essential to data security strategy. Their strategic plans live in SharePoint; their employee records and customer data are stored in OneDrive. T[…]

 Beta Channel Update for ChromeOS / ChromeOS Flex  - The Beta channel is being updated to OS version 16820.18.0 (Browser version 155.0.8059.31) for most ChromeOS devices.

 Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes  - Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system. "Weak authorization in...

 N0n ransomware: what you need to know  - N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra...

 ShinyHunters hacker detained in Jordan – now he’s helping FBI hunt down his own crew  - "No safe haven", FBI Director Kash Patel warns cybercrime threat actors.

 News alert: Aembit gives enterprises new controls over personal AI agents accessing sensitive systems  - SILVER SPRING, Md., Oct. 6, 2026, CyberNewswire — Aembit , the identity control plane for AI agents, today announced support for securing personal agents’ access to enterprise environments, available immediately to existing customers at no additional cost.

 Stable Channel Update for Desktop  - The Stable channel has been updated to 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

 Police Urge Passkey Use After Surge in Cybercrime Profits  - Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually

 OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU  - OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union.

 Citrix NetScaler Targeted Via New Zero Day  - The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government

 Citrix patches NetScaler SAML zero-day exploited in attacks  - Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.