Dear readers, Mythos didn’t just shake up how AI can attack and defend: Business as usual, and the public-private partnership model on which we have long relied, is being fundamentally reshaped....
A new CSIS report, Building a Robust U.S.-ROK Cyber Alliance: A Joint Cyber Resilience Strategy, examines how the United States and South Korea can strengthen bilateral cyber cooperation in...
Until recently, artificial intelligence was a welcome tailwind for U.S. growth. We’re beyond that now. AI is more like a hurricane-strength weather system making itself felt across the entire...
On the eve of the U.S.-Israeli strikes on Iran, 56 tankers sailed through the Strait of Hormuz. Two days later, Lloyd’s List, the maritime industry’s journal of record, counted just seven tankers...
Karakurt and DPRK facilitators sentenced, PCPJack worm steals cloud credentials while evicting rivals, and attackers exploit an unpatched PAN-OS zero-day.
Iran is ramping up trade with China via rail in a bid to blunt the impact of a US blockade of its ports and adapt to pressure designed to strangle its economy. The number of cargo trains going...
ShinyHunters takes the credit and gives developer an F for security
ShinyHunters takes the credit and gives developer an F for security
Weeks after the Copy Fail vulnerability was revealed, a new Linux kernel escalation vulnerability has been uncovered. Dubbed “Dirty Frag,” this flaw could allow a local user to gain root access on...
A key company behind Thailand’s national AI effort is suspected of helping to smuggle billions of dollars worth of Super Micro Computer Inc. servers containing advanced Nvidia Corp. chips to...
Developers using the latest versions of AI coding tools like Claude Code, Cursor CLI, Gemini CLI, and CoPilot CLI could inadvertently execute malicious code on their systems with a single...
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States...
A federal jury on Thursday convicted an Alexandria man of conspiring with his twin brother to delete approximately 96 federal government databases after the pair were fired from a contractor that...
Social media biz says watchdog's fine formula is 'disproportionate' and should stop counting global revenue
Health authorities across several countries are racing to trace and contain an outbreak of the hantavirus after the World Health Organization (WHO) said Thursday that five confirmed infections had...
The National Reconnaissance Office (NRO) is expanding its research and experimentation projects designed to allow analysts to track back how artificial intelligence (AI) algorithms come to...
NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach. [...]
In this weekly roundup from The Cyber Express, the global cybersecurity landscape continues to show rapid and uneven change, shaped by both regulatory shifts and escalating cyber threats....
Poland’s domestic intelligence service said attackers breached water treatment facilities in five towns in 2025, in some cases gaining access to industrial control systems that could have...
One of the Pentagon’s top technology leaders ruled out any reconciliation with Anthropic, despite the White House softening its own tone on the AI company. “Never again will we be single-threaded...
On a recent call with the heads of the biggest artificial-intelligence companies, Vice President JD Vance was alarmed. New AI models such as Anthropic’s Mythos, which are capable of finding...
Akamai edge configurations are now visible on the Wiz Security Graph, giving teams a single understanding of risk from edge to runtime
Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail...
Attackers move faster than overwhelmed SOC teams can realistically investigate alerts. Prophet Security breaks down how AI can help analysts investigate alerts faster and focus on real threats. [...]
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. [...]
AI-driven discovery, NIST’s retreat from universal enrichment, and the end of “good enough” vulnerability managementKey takeawaysAI-driven discovery tools are accelerating CVE volume, resulting in...
Unpatched kernel flaw chain (CVE-2026-43284, CVE-2026-43500) enables root escalation on major Linux distributions.
With the launch of the first 16 satellites, Russia begins construction of a network for satellite internet that aims to cover the entire country by 2030. But getting there won’t be easy.
A newly disclosed local privilege escalation (LPE) vulnerability known as Dirty Frag is raising serious concerns across the Linux ecosystem after researchers revealed that the flaw can grant root...
CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]