A Los Angeles jury delivered a rare verdict against Silicon Valley giants Wednesday — the second finding in two days — boosting hopes of safety advocates that courts will deliver a long-sought...
There’s a theoretical red line with cyber warfare. Cross it, and the U.S. will respond with a physical attack like missile strikes. And that line “is whatever the President says it is,” according...
Heliox EV Chargers listed below contain improper access control vulnerability that could allow an attacker to reach unauthorized services via the charging cable. Siemens has released new versions...
SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS...
Short-range kamikaze drones operated by an Iran-backed militia appear to have successfully targeted a U.S. military Black Hawk helicopter and a critical air defense radar at an American base in...
The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of...
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and...
SIMATIC S7-1500 devices contain a vulnerability that could allow an attacker to inject code by tricking a legitimate user into importing a specially crafted trace file in the web interface....
Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: SICAM A8000 Device firmware CPCI85 for CP-8031/CP-8050 SICORE for CP-8010/CP-8012...
New data from Marlink reports a 50% surge in satellite jamming and spoofing incidents affecting global shipping in... The post Marlink warns surge in satellite spoofing is blinding maritime...
Following its recent cybersecurity incident, medical technology giant Stryker said it found no indication of ransomware or malware.... The post Stryker rules out ransomware, confirms threat actor...
The U.S. FCC (Federal Communications Commission) updated its Covered List to include additional categories of communications equipment deemed... The post FCC expands Covered List to block...
GitLab security advisory (AV26-276)
Nodejs security advisory (AV26-277)
n8n security advisory (AV26-278)
Hitachi security advisory (AV26-279)
Exposure management company Tenable announced Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management... The post Tenable Hexa AI brings agentic automation to exposure...
ISC BIND security advisory (AV26-280)
Cisco security advisory (AV26-281)
The new director of Cyber Command and the National Security Agency told both organizations’ workforces in a Tuesday all-hands meeting that he wants to double down on intelligence-sharing with U.S....
US lawmakers are pressing Tulsi Gabbard to reveal whether using a VPN that connects to overseas servers can strip Americans of their constitutional protections against warrantless surveillance.
Poland experienced 2½ times more cyberattacks in 2025 compared to the previous year, and the numbers are constantly rising, a government official said Tuesday. The attacks included a destructive...
A New Mexico state court jury on Tuesday held Meta liable for nearly $400 million in civil damages after a trial where the state attorney general accused the Facebook and Instagram operator of...
The head of the UK’s national cybersecurity agency is calling for security professionals to “seize the disruptive vibe coding opportunity” to make software more secure. However, this must be...
The first black-and-white surveillance image shows a simple factory complex on a tree-lined road west of the Iranian city of Isfahan. In a second image, the factory, which United States Central...
Runtime governance for securing the agentic enterprise
Accelerate your path to Zero Criticals with AI that investigates, assigns, and guides cloud remediation for you
This episode of Talos Takes breaks down the 2025 Year in Review as well as Splunk's Top 50 Cybersecurity Threats report.
Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. "Instead...