Category: EN

Agentic AI Pentesting Platforms Comparison

Agentic AI transforms Penetration Testing from a periodic consulting practice to a continuous validation discipline. While traditional pentests remain relevant, particularly for complex business logic or regulated environments, the rapid evolution of cloud-native systems necessitates more frequent evaluations. Between formal…

Modelplane: Open-source control plane for AI inference

Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have built this coordination layer…

New infosec products of the month: June 2026

Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI. Asimily turns device…

Malware gaslights AI

Mac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI’s Patch the Planet, and FortiBleed Fallout Mac malware called “Gaslight,” attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating it via a…

Kitana Shows How AI Is Reshaping Adversary-in-the-Middle Fraud

Kitana combines AI-assisted development with adversary-in-the-middle attacks to steal credentials and payment information in real time. The post Kitana Shows How AI Is Reshaping Adversary-in-the-Middle Fraud appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability These…

FortiBleed Turns FortiGate Access Into Enterprise Credential Theft

Arctic Wolf found FortiBleed uses stolen FortiGate credentials to gain enterprise access. The post FortiBleed Turns FortiGate Access Into Enterprise Credential Theft  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: FortiBleed…

Operation Endgame Disrupts StealC Malware Infrastructure

Operation Endgame disrupted StealC infrastructure and seized millions of stolen credentials through a coordinated public-private effort. The post Operation Endgame Disrupts StealC Malware Infrastructure  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…

Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet

Curl fixed 18 vulnerabilities, including a 25-year-old bug, with issues spanning auth bypass, memory safety, and host validation in libcurl. Curl maintainers addressed eighteen vulnerabilities with a single update, and one of them goes back 25 years. That’s not a…

Polymarket says hackers stole users’ funds

The prediction market giant Polymarket said it’s refunding users who had funds stolen due to a third party breach. This article has been indexed from Security News | TechCrunch Read the original article: Polymarket says hackers stole users’ funds