Tenable security advisory (AV26-724)
Zyxel security advisory (AV26-725)
In a military conflict with Taiwan, China’s cheapest path to victory is a short, decisive one: a decapitating opening strike—that is, a strike targeting leadership—that collapses organized...
Algorithmic insights—the techniques, methods, and design know-how that materially improve artificial intelligence (AI) systems—can confer substantial commercial and strategic advantages. Unlike...
AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have...
The Houthis, the Iranian-backed armed faction in Yemen, on Monday said they would impose a blockade on Saudi ships, threatening to open a new front in the Middle East conflict and raising the...
President Donald Trump on Monday signed an executive order making it harder for U.S. defense contractors to obtain waivers allowing them to buy critical minerals and other materials from China and...
The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.
Silicon Valley and Washington are debating a multibillion-dollar question: Should American companies be able to use Chinese artificial-intelligence models? OpenAI and Anthropic executives are...
How Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.
Coordinated vulnerability disclosures operate on a straightforward premise: the affected vendor is notified first, given a defined window to remediate, and public disclosure follows.
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been...
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
In April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.
As AI accelerates how organizations build and how attackers operate, a deeply connected security ecosystem is how defenders keep up.
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said...
It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along...
Future major events can’t rely on yesterday's playbook. Lessons from the World Cup show why true cyber resilience starts months before kickoff and extends far beyond stadium perimeters. The post...
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades...
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
Plus dozens of PoCs in the public domain
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers...
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers,...
IC3 says any account claiming to represent it is fake
Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Chinese open-weight model GLM 5.2 happily obliged
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on...