IT Security News: today roundup Microsoft outlined AI-focused security platform updates for Ignite 2026. US businesses maintain climate technology investments despite shifting federal support. Citrix issued patches for two actively exploited zero-day RCE flaws. Malwarebytes published its weekly security news…
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
Cloudflare plans to issue quantum-safe TLS certificates
The move will be part of a major overhaul of the ecosystem for website authentication.
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Sean Cairncross talked about regulations, China, pilot projects and more Thursday.
Proton Extends Easy Switch to Microsoft 365
Proton has extended its Easy Switch for Business migration tool to support Microsoft 365, enabling organizations to transfer email, calendars, and…
AI cuts software developers some slack
My mom used to say that Hodges’s law was “Junk expands to fill the space allotted for it.” We lived in three houses over the years, each one bigger than…
‘NeedyMantis’ Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and…
Attackers have been exploiting critical Zimbra flaw to steal emails
A simple email gives the attackers the ability to remotely inject OS commands.
OpenAI reveals ‘novel’ encryption bypass used in distillation attack
The company said individuals associated with Chinese company MoonshotAI were behind parts of the attack, but did not offer hard evidence for the claim.
Japanese Railway Operators Hit with Cyber Attacks
Three major Japanese transport operators have disclosed significant cyber attacks within days of each other, compromising customer data but leaving…
Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
Meta is once again repositioning itself to target the enterprise market. This week, the company announced the Meta Enterprise Platform , which it says…
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
The teenager-run cybercrime group victimized roughly 500 organizations in less than two years.
ShinyHunters expands Oracle PeopleSoft campaign
Google Threat Intelligence Group warned Friday that ShinyHunters (tracked as UNC6240) has launched an expanded campaign targeting vulnerable Oracle…
Observability for AI-native systems: New SLIs beyond latency and error rate
When HTTP 200 means nothing An AI assistant can return a response in under a second, maintain 99.9% availability and still give customers a fabricated…
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one…
AI policy circles targeted in China-linked phishing operation
Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S. think…
Validating AI models and agents with property-based testing
Testing deterministic systems is relatively straightforward. Create an assertion that the system should pass, and automate validating it against a series…
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
WaterISAC reckons with range of threats after summer of cyberattacks
Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is…
Unsloth’s model picker had a code-execution problem
True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow…
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI…
KillSec Ransomware Group Dismantled, 16-Year-Old Suspected Admin Arrested
An international police operation has disrupted the KillSec ransomware group, with three suspects arrested, five servers seized and…
Gossips on Cryptography: Part 4
In this blog, we will continue our discussion from the previous parts. If you have not read them, please read them first. Parts 1 & 2 – Caesar Cipher,…
The dream of enterprise semantics: Why this time is different
In most companies, the struggle to answer a new question fast has nothing to do with a lack of data. The problem is a lack of semantics. Or to put it…
