We now have a better idea of how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in …
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking …
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing envir…
Unknown threat actors distribute malicious downloader functionality separated across several npm packages targeting users of Alibaba tools. The final…
Two agentic bug-hunting systems from Microsoft and Google-owned Wiz show that when it comes to finding and remediating software vulnerabilities, at l…
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on…
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational t…
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process af…
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. […
Malicious beta versions of the Joyfill npm packages @joyfill/components and @joyfill/layouts hide an obfuscated remote access trojan and credential s…
Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment
Ahead of DEF CON 2026 opening its doors in Las Vegas next week, conference organizers said they have imposed a ban on “Meta-style glasses with record…
Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability d…
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main proce…
An employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing I…
Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB S…
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, …
CAF Bank, which serves 14,000 charities, has suspended online banking as it fixes a vulnerability in how third-party software connects to its portal.…
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluati…
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabl…
Key Trends and Findings from Known Exploited Vulnerabilities, AI discovered vulnerabilities, and AI targeted technologies from the first half of 2026
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Reddit users found that by using a specific Google search query, it was possible to find Claude conversations that users had shared. This exposed sen…
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management…
Key Takeaways Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools and services …
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has be…
A prayer app launched by Pope Francis in 2019 contained a security flaw that exposed the personal information of hundreds of thousands of users befor…
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as s…
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagem…
A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are alrea…
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of mo…
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temp…
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue…
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracke…
Introduction Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on c…
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched …
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista Ve…
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The…
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts sho…
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breac…
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild…
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have …
Decades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another…