ACME validation had a challenge-request hole Cloudflare has fixed a flaw in its web application firewall (WAF) that allowed attackers to bypass security rules and directly access origin servers,...
Chasing Shadows, the best-selling book by Citizen Lab director Ron Deibert, is now out in paperback form on the one-year anniversary of its launch. This edition includes a new afterword describing...
Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities in GitHub Actions and JavaScript projects. The post AI-supported vulnerability...
A set of three security vulnerabilities has been disclosed in mcp-server-git, the official Git Model Context Protocol (MCP) server maintained by Anthropic, that could be exploited to read or...
Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads, likely with the intent to deploy a remote access...
Internal ICE planning documents propose spending up to $50 million on a privately run network capable of shipping immigrants in custody hundreds of miles across the Upper Midwest.
AI + skilled malware developers = security threat VoidLink, the newly spotted Linux malware that targets victims' clouds with 37 evil plugins, was generated "almost entirely by artificial...
The Problem: The Identities Left Behind As organizations grow and evolve, employees, contractors, services, and systems come and go - but their accounts often remain. These abandoned or “orphan”...
We've identified an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks. The post DNS OverDoS: Are Private Endpoints Too Private?...
Introducing new-era DLP with an eye for secure visibility
Cybersecurity researchers have disclosed details of a malware campaign that's targeting software developers with a new information stealer called Evelyn Stealer by weaponizing the Microsoft Visual...
Oracle addresses 158 CVEs in its first quarterly update of 2026 with 337 patches, including 27 critical updates.Key takeaways:The first Critical Patch Update (CPU) for 2026, contains fixes for 158...
Cloudflare has addressed a security vulnerability impacting its Automatic Certificate Management Environment (ACME) validation logic that made it possible to bypass security controls and access...
Leaked API keys are no longer unusual, nor are the breaches that follow. So why are sensitive tokens still being so easily exposed? To find out, Intruder’s research team looked at what traditional...
Senior researcher Noura Aljizawi speaks with Nalah Ayed from CBC Ideas about her personal experience of returning to Syria to grieve for the first time in 13 years following the fall of the...
Tenable Research has discovered a server-side request forgery (SSRF) vulnerability in Java’s handling of client certificates during a TLS handshake. In certain configurations, this can be abused...
Picture this: You’re a utility executive. It’s August 2029. A heat wave grips 10% of the country, and your regional transmission organization is red-lining. Community concerns around rolling...
The United States’ attack on Venezuela has raised questions about domestic checks on power and signaled a challenge to international law and longstanding norms of sovereignty and the use of force....
Transport Canberra has launched a new investigation into its fleet of Chinese-made electric buses amid growing cybersecurity concerns. British media have reported that the UK’s National Cyber...
Uptake by European Union member countries of a measure intended to beef up continental cybersecurity has hardly been enthusiastic. 15 months after EU nation-states were supposed to have...
The Department of Homeland Security would need to follow stricter guidelines when using mobile biometric applications under legislation introduced Thursday by the ranking member of the...
The Wiz JetBrains IDE plugin is now generally available, enabling developers to fix risks before code leaves their local environment.
Update Chainlit to the latest version ASAP Two "easy-to-exploit" vulnerabilities in the popular open-source AI framework Chainlit put major enterprises' cloud environments at risk of leaking data...
LLM cybersecurity benchmarks fail to measure what defenders need: faster detection, reduced containment time, and better decisions under pressure.
FortiGuard Labs analysis of a multi-stage Windows malware campaign that abuses trusted platforms to disable defenses, deploy RATs, and deliver ransomware.
A strange charge appears on a bank account. An email claims a package is on the way. A social media account stops accepting a password that worked yesterday. When these moments hit, many people do...
AI poses substantial threats and opportunities for democracy in an important year ahead for global democracy. Despite the threats, AI technologies can also improve representative politics, citizen...
Global LLM use is growing rapidly; site visits to major LLM platforms increased threefold from April 2024 to August 2025, rising from an estimated 2.4 billion to nearly 8.2 billion monthly visits....
The UK’s National Cyber Security Centre (NCSC) is once again warning that pro-Russia hacktivists are a threat to critical services operators. The cyber arm of the UK’s sigint specialists at GCHQ...
Cyberattacks cost the global economy over £7 trillion a year — more than double the UK’s gross domestic product. The annual hit to the country alone is £27 billion. But one prediction that can be...