Fresh kernel flaw comes with public exploit code and continues ugly run of highly reliable privilege escalation bugs tied to memory and page-cache handling
Integer Overflow vulnerability (CVE-2026-8295) has been found in simdjson library.
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution. [...]
Russian state-sponsored threat group Sandworm is continuing to target industrial and critical infrastructure environments using aggressive lateral movement,... The post Sandworm uses...
New research from Bitdefender detailed targeting an Azerbaijani oil and gas company in a multi-wave cyberespionage campaign that... The post Bitdefender uncovers FamousSparrow attacks on...
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The vulnerability,...
Patero, a provider of post-quantum encryption and secure communications technologies, and Orilla, an edge-native software company focused on... The post Patero, Orilla launch secure...
Tidal Cyber announced a major advancement to its platform with the separation of MITRE ATT&CK intelligence from Tidal... The post Tidal Cyber updates platform for MITRE ATT&CK v19 with focus on...
Cargo theft now starts with phishing emails and stolen credentials, not hijackings, to reroute and steal freight from supply chains. NMFTA outlines how cyber-enabled cargo crime is changing...
Semperis, an identity-driven cyber resilience and crisis response company, published results of a multi-industry global study of 1,100... The post Semperis study warns AI agents are rapidly...
Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release...
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.
A bustling underground ecosystem is providing criminals with the tools to unlock iPhones—and wage phishing attacks against their contacts to access bank accounts and more.
Human IT managers thought they were being nice to the boss, but were assisting a threat actor
Human IT managers thought they were being nice to the boss, but were assisting a threat actor
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
A newly revealed Exim BDAT vulnerability is affecting some email server setups that use Exim as their Mail Transfer Agent (MTA), prompting security attention due to its severity. Tracked as...
UK researchers find LLMs are learning to finish jobs faster and improving all the time
Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks. [...]
Cybersecurity in Construction: Your Site Is Secure – But Is Your Data? There’s something ironic about the construction industry. You’re in the business of building things that last, structures...
Dell confirmed that its SupportAssist software is causing blue-screen crashes on some Windows systems following a wave of user reports about random reboots affecting Dell devices since Friday. [...]
Reducing memory requirements to control costs in a new wave of kit
The alleged main administrator of Dream Market Incognito Market, one of the largest dark web marketplaces before its shutdown, has been indicted in the United States on money laundering charges. [...]
In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group. Shortly after, data allegedly taken from the company's Salesforce...
Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious...
Palo Alto Networks found and fixed 75 flaws this month, up from its usual five
If a setting fails in the forest and nobody hears it ...
If a setting fails in the forest and nobody hears it ...
The real question in modern cyber defense isn't who has more technology. It's who uses their resources more efficiently. Here's how AI fused with threat intelligence tips that balance.
NVD enrichment now covers only 15–20% of CVEs. Learn how Recorded Future Vulnerability Intelligence prioritizes risk using real attacker behavior signals.