Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and...
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed....
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to...
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation,...
How MCP turns PAM into an AI-ready source for faster reporting and compliance visibility
Cisco security advisory (AV26-794)
Crims talked their way onto three employee PCs before trousering corporate data
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
Roundcube security advisory (AV26-793)
Pub chain says turn off the cameras, reminds punters not to blare sound from phone vids either
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information,...
Stored Cross-Site Scripting vulnerability (CVE-2026-18478) has been found in Magnolia CMS software.
No, no nasties to see here, guv...
HashiCorp security advisory (AV26-791)
WordPress security advisory (AV26-792)
WebPros security advisory (AV26-790)
IBM security advisory (AV26-789)
This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn't expect.
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority...
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
Repairable hardware is little comfort when personal details escape
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and...
Heap-based buffer overflow vulnerability (CVE-2026-18370) has been found in eradman entr software.
Dell security advisory (AV26-788)
Walk away and hope the classifier catches anything irreversible or destructive
Reverse engineering GHSA-vwf4-m7j8-wcjf with AI to accelerate defense.
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-66484 to CVE-2026-66486) found in GNU cpio software.
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant...
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the...
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-71391 to CVE-2026-71394) found in GNU Emacs software.