A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security...
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software...
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending...
Eve's dropping in on Alice and Bob
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a...
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts...
Beware the SparroWocky, my son! The backdoor that bites…
Dell security advisory (AV26-934)
Tanium security advisory (AV26-935)
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE....
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. The post The AI hacking...
Check Point security advisory (AV26-933)
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a...
AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460
Officials from the departments of Justice and Homeland Security have less than a month to write rules for private companies to conduct offensive cyber operations under federal control, as industry...
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI...
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains...
Cisco security advisory (AV26-932)
Frontier artificial intelligence (AI) continues to advance, and an increasing number of experts contend that the creation of superintelligence is possible. Although progress might slow or even...
The United States’ busiest container port for global trade foiled more than 120 million cyberattack attempts in August, posing a persistent threat to its operations as it grapples with shifting...
For nearly three decades, the Pentagon has put off upgrading its antiquated computer networks, instead focusing its funds on cutting-edge weapons systems. But as artificial intelligence grows in...
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in...
Anthropic CEO Dario Amodei’s call for an antitrust waiver for AI firms to work together on a safety standard is being met with skepticism in Washington, where policymakers are questioning tech...
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking,...
OpenAI has disclosed six more examples of “unexpected or concerning” behavior by its technology, as it warned that the pace of development could not continue at “maximum speed for much longer”...
Controlling coding agent overpermissioning is key to security. But recent frontier AI incidents show that problems don’t stop there.
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal...
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
Settra is a newer ransomware variant that was first observed in June 2026. Based on public reporting, the attackers behind the variant have targeted virtual private networks (VPNs) or used...
Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior
Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. The post Authorities seize...
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them...
Even a temporary staging server needs to be locked down.
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as "The Odyssey," and uses the Solana blockchain to hide its C2 infrastructure.
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice...
Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these...
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS...
Platforms comply just enough to avoid being blocked, leaving the regulator chasing debt
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters...
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as...
The Transportation Security Administration recently deployed Ace, an artificial intelligence agent built using Salesforce technology, to help travelers receive timely responses to questions about...
City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
British, American and Dutch security agencies issued a warning on Tuesday exposing a spyware tool being used by Iranian state-sponsored hackers to target individuals perceived as posing a threat...
Batteries are taking center stage in the energy world. Battery deployment, both to power electric vehicles and to store electricity for the grid, has skyrocketed in recent years. Last year, more...
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared...
New York healthcare provider Premier Medical Group (PMG) is notifying over 280,000 patients that their personal and medical information was stolen in a data breach. PMG offers in-depth patient...
Cybersecurity compliance APAC 2026 has moved from guidance to enforcement across three of Southeast Asia's largest economies, almost in step. Singapore's Cyber Security Agency issued an updated...
If anything, 2026 has made clear that cybersecurity is no longer a background concern. Today, security is at the front and center of many conversations, woven into almost every major story of the...
Spain’s data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial intelligence agent, a case that suggests...
Flock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
This is a test - it is only a test
A behind-the-scenes look at how Recorded Future earned its spot as a threat intelligence leader in the latest Forrester Wave.
Experts from Recorded Future and Mastercard explore how security organizations can shift to proactive, machine-speed defense by leveraging high-quality threat intelligence and adhering to evolving...