An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The…
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet…
July Apple updates are especially important if you receive images
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
VERITAS project could change the way scientists secure AI
The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to…
Confidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in Use
Modern AI runs on shared, high-performance infrastructure that processes enormous volumes of sensitive data and valuable model weights.…
One-click Claude Desktop flaw could enable hidden prompt injection and code execution
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local…
Act Security Emerges from Stealth to Fight the Patch Problem
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments.
Axon Is Another License Plate Surveillance Company
Governments are switching, but I’m not sure it makes a difference : …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But…
Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains
Dysphoria has emerged as a fast-moving IoT botnet that has infected an estimated 200,000 devices worldwide. The malware targets routers, cameras,…
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released…
Vatican’s Click To Pray app exposed personal data from 700,000 users
Anyone could access other Click To Pray users’ personal information. The flaw went unfixed for more than six months after it was reported.
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon…
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks.
Scammers Pose as ShinyHunters to Blackmail Data-Breach Victims With Fake Webcam Videos
Victims of recent data breaches are receiving alarming emails that claim hackers recorded them through their webcams. The messages borrow the ShinyHunters…
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing.
Hackers Exploiting Arista VeloCloud Orchestrator 0-Day Vulnerability in the Wild
Arista Networks has issued a security advisory for CVE-2026-16812, a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator…
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected…
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
libssh2 Vulnerabilities Allow a Malicious SSH Server to Corrupt Client Memory
A set of high-severity vulnerabilities in libssh2 could expose SSH and SFTP client applications to memory corruption, crashes, and potential code…
Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations…
New Tengu Mirai Botnet Reboots Your IoT Device When You Try to Kill It
Tengu, a newly observed Mirai-based botnet, is making infected IoT devices far harder to clean. It targets internet-facing embedded Linux systems,…
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to…
LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed
A newly disclosed exploit dubbed LegacyHive is raising alarms across the cybersecurity community after researchers confirmed it executes successfully on…
Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote…