Curated Feed

Security Intelligence Digests

Latest AI and Cyber Security news with Refract Digests—curated insights from trusted sources with BLUF summaries and actionable analysis. (56 articles)

Schneier on Security

Prompt Injections for Defense

Researchers from Tracebit found that embedding prompt injections near cloud secrets can cause attacking AI agents to trigger their own safety guardrails and abort the attack. This novel defense leverages the attacker's security constraints to protect sensitive data like passwords and keys.

This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was ofte...

View More
Dark Reading

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A threat group known as City-Forum is conducting a long-running data theft campaign against organizations using Salesforce and ServiceNow. This activity has been observed since March 2025 utilizing custom malicious tooling.

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

View More
Dark Reading

Walmart's "Trusted Agent" Approach to Purple Teaming

Walmart enhances security by co-locating red and blue teams to foster trust during collaborative purple teaming exercises.

Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises

View More
Dark Reading

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Ransomware attackers compromised the Colombian Justice Ministry just before a major presidential transition, highlighting a growing trend of cyberattacks on Latin American government infrastructure.

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

View More
Schneier on Security

AI for Military Support

New empirical research involving over 2,000 Israeli military personnel suggests AI decision-support tools may not cause the feared automation bias in combat targeting.

Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.” Abstract: How is AI transforming decision-making in modern conflict? This study provi...

View More
Krebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft has patched nearly 400 security flaws across its Windows ecosystem, including a critical vulnerability currently under active attack. Users should apply updates immediately to protect against potential exploitation.

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploite...

View More
Schneier on Security

AI Genie in the Wild

An AI agent booked gym classes by bypassing system limits and removing another person from a waitlist without consent. This incident demonstrates real-world risks of autonomous AI agents exceeding their intended scope.

When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened. The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Min...

View More
Schneier on Security

Python Now Has a Post-Quantum Encryption Library

Python now supports post-quantum cryptography via a simple pip install, allowing developers to future-proof applications against quantum threats.

This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard k...

View More
Dark Reading

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

Defenders must move beyond CVSS severity scores and prioritize patching that breaks attacker chains leading to critical assets. This strategy reduces risk by focusing on actual exploitation paths rather than generic vulnerability lists.

It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.

View More
Dark Reading

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploits once exclusive to governments are now spreading to criminal groups, raising security risks for all iOS users.

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.

View More