Secret to their success: Using the right model for the right security job
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence...
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI)...
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software...
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as...
Progress Software security advisory (AV26-755)
More organizers prohibit camera-equipped specs, even with prescription lenses
The OCCRP found that the co-founder of NSO Group, which develops Pegasus spyware, travelled to Panama in 2013 on an Israeli diplomatic passport. The post Co-Founder of Controversial Spyware Firm...
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks...
How unauthenticated Model Context Protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution.
Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones. The post AI-assisted security tools are finding more...
Washington rallies allies to shape next-generation networks after spending 18 months rattling them
Apache security advisory (AV26-749)
Arista Networks security advisory (AV26-751)
JetBrains security advisory (AV26-752)
Apple security advisory (AV26-753)
Vercel security advisory (AV26-754)
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution....
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a...
Silicon Valley leaders from Anthropic PBC’s Dario Amodei to Nvidia Corp.’s Jensen Huang warned against a U.S. crackdown on open-weight artificial intelligence systems, deepening a debate about how...
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Bridge is a powerful asset management tool that allows...
Plaintext Storage of a Password vulnerability (CVE-2026-41874) has been found in OpenSolution Quick.Cart software.
An Italian investigation into an alleged Russian intelligence network has turned the spotlight on one of the country’s most sensitive military cyber facilities: the Interforce Cyber Training...
Xi Jinping has made a consequential strategic choice. Faced with Kim Jong Un’s growing partnership with Vladimir Putin, Xi is rebuilding Chinese political and economic support for North Korea and...
North America accounts for the most internet-exposed industrial control systems (ICS) as of early 2026, with roughly 38% of all such devices located on the continent, according to the internet...
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-63301 to CVE-2026-63303) found in OpenSolution Quick.CMS software.
A fast-moving wildfire, one of many raging across Spain, bore down on the Madrid Deep Space Communications Complex on Friday, forcing an evacuation and temporarily suspending operations at one of...
A popular Vatican website and mobile app has been leaking hundreds of thousands of users’ names and email addresses. “Click to Pray” is the Vatican’s official prayer app. Users can sign up for...
Cyberattacks targeting the Ministry of Foreign Affairs and its affiliated agencies nearly tripled in the first half of this year compared to the same period last year, data showed, raising fresh...
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash...
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
Governments are switching, but I’m not sure it makes a difference: …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only...
Wiz enables organizations to continuously assess environments against the CISA KEV catalog, automating risk prioritization, rapid remediation, and forensic triage workflows.
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812...
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
A vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem that could allow for remote code execution. VeloCloud Orchestrator is a centralized management platform used to...
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique...
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.