The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
Hi, what are you looking for?
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.
A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked.
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse.
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.