As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly.
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks.
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification.
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment.
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base.
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.
We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.