Other noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accused of hack cover-ups.
Hi, what are you looking for?
Other noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accused of hack cover-ups.
Industry professionals comment on various aspects of Fable 5, including dual-use capabilities, safeguards, and tiered access.
The hackers published 5GB of data, including customer personal information and credentials for the RTKBase platform.
The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.
An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak.
Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation.
Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks.
As alert volumes outpace human capacity, organizations are turning to AI, automation, and deeper context to separate real threats from the noise.
The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.
Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.
Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.
A PowerShell script included in patch files appears to be triggering false positives by multiple security engines.
The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances
The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources.
The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode.
The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information.
The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.
As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations.
Cyera is positioned as one of the most valuable privately held cybersecurity firms in the world with total funding topping $2 billion.