Orchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond…
Category: EN
Singapore man pleads guilty to $245M crypto theft
A 22-year-old Singapore national has admitted to leading a criminal operation that stole more than $245 million in cryptocurrency from victims’ digital…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Jellyfin 12.0 releases security fixes
Jellyfin has released version 12.0 of its media server platform with several critical security patches addressing vulnerabilities that could expose files…
AI adoption that pays off is built around keeping humans in the driver’s seat
I’ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, “we’ve got…
Open Standard for Revocable API Keys Proposed
Security researchers have proposed an open standard designed to make API keys self-destruct within 60 seconds of being detected as leaked.
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Cymphony was valued at more than $100 million in a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund.
DeepSeek Harness Sandbox Bypass Flaw
Security researchers have identified a critical sandbox escape vulnerability in DeepSeek Harness, the open-source framework developed by DeepSeek for…
FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs
A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy…
ShinyHunters claims Florida DMV breach
The notorious cybercrime group ShinyHunters has claimed responsibility for breaching Florida’s Department of Highway Safety and Motor Vehicles, allegedly…
WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
AI-Assisted WeChat Worm Put 1 Billion Accounts at Potential Risk
Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls before Tencent mitigated the flaw.
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent of organizations believe they have visibility into their AI and machine…
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams,…
Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories
Cybercriminals are widening the reach of information-stealing malware by targeting the local data created by AI coding agents. The shift puts access…
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using…
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth…
Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root
Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access,…
Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code
Microsoft has released security updates for CVE-2026-69485, an Important-rated remote code execution vulnerability affecting the Windows Remote Desktop…
