Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.
Hi, what are you looking for?
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm.
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
The Israeli company has nearly $2 billion in total assets under management since 2014.
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.