The Trump administration on Monday will launch a global partnership with more than 20 allies to accelerate the development of secure 6G wireless networks, officials first shared with POLITICO, as...
The White House recently published a National Security Presidential Memorandum directing the executive branch to “responsibly accelerate the use of AI across intelligence and warfighting domains...
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the...
Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC)...
The People’s Republic of China (PRC) has identified control over time, and the precision behind the “granting of time” as a critical capability. It seeks to weaponize “chronopolitics” to gain...
See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit.
Nvidia and a host of tech giants on Monday launched a new artificial intelligence safety initiative focused on open models, as the fallout from a cyberattack committed by rogue OpenAI models...
After OpenAI enhanced the brain power of its chatbot last summer, hundreds of users worldwide began asking it how to make and deploy biological weapons and poisons. The models, operating largely...
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration...
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-57916 and CVE-2026-57917) found in proCertum SmartSign software.
Over several weeks in June and July 2026, Europol supported an action targeting nihilistic violent extremist content online. Investigators from nine countries participated in these ‘Referral...
The Office of the Director of National Intelligence has shrunk more than is publicly known in recent weeks, losing about 200 personnel to firings and reassignments since June 1, according to data...
Previous U.S. foreign, security, and defense policies toward the People’s Republic of China (PRC) and the Chinese Communist Party (CCP) have failed. Contrary to the decades-long hopes and...
Secretary of State Marco Rubio announced on Thursday a new visa restriction policy targeting foreign nationals responsible for or complicit in cybercrime and cyber-enabled crime. “This policy...
Integer overflow vulnerability (CVE-2026-16554) has been found in DaveGamble cJSON library.
Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops...
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on...
So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete...
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can...
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and...
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments...
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage...
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary...
Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.
(Security) hole-ier than thou
Stop the spread (of online recruiting and propaganda)
Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the...
Progress security advisory (AV26-746)