Explore real-world engineering experiences from top tech companies.
Receive daily AI-curated summaries of engineering articles from top tech companies worldwide.
This article explains how to secure AI inference workloads on GKE using Model Armor as a network-level guardrail against AI-specific attack vectors.
Microsoft Defender researchers disclosed a now-patched intent redirection vulnerability in EngageLab SDK that exposed over 50 million Android users, including 30 million cryptocurrency wallet users.
A security bulletin on threats spanning hybrid botnets, decade-old exploits, fraud losses, and AI-enabled attacks.
A zero-day vulnerability in Adobe Reader has been actively exploited via malicious PDF files since at least December 2025.
A hack-for-hire campaign linked to the threat actor Bitter targeted journalists, activists, and government officials across the MENA region using spear-phishing and Android spyware.
A new variant of the Chaos botnet malware has been identified targeting misconfigured cloud deployments, with notable capability additions including a SOCKS proxy feature.
This article covers Masjesu (XorBot), a DDoS-for-hire botnet targeting IoT devices globally since 2023.
APT28 (Forest Blizzard/Pawn Storm) has deployed a previously undocumented malware suite called PRISMEX in a spear-phishing campaign targeting Ukraine and NATO allies, active since at least September 2025.
This post introduces a tool that uses symbolic execution and the Z3 theorem prover to automatically generate magic packets capable of triggering BPF-based Linux backdoors.
Anthropic launched Project Glasswing, using Claude Mythos to find zero-day vulnerabilities across critical systems.
North Korean threat actors behind the 'Contagious Interview' campaign have distributed over 1,700 malicious packages across npm, PyPI, Go, Rust, and PHP ecosystems since January 2025.
Cloudflare accelerates its post-quantum roadmap to achieve full PQ security including authentication by 2029.