Cybersecurity researchers at Wiz found CosmosEscape in Azure’s Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed…
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
The best compliance programs aren’t the biggest ones. They’re the ones built on a short list of questions that can actually be answered, and that still…
Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities
The Stable channel has been updated to Chrome version 151.0.7922.71.72 for Windows and macOS, and 151.0.7922.71 for Linux, with the rollout taking place…
Location Sharing: Convenience at the Cost of Safety
Location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users…
Senator Wyden urges federal VPN purge
Senator Ron Wyden has urged federal cybersecurity agencies to remove all insecure, internet-facing VPN systems from government networks within two years,…
Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes
London, UK, 30 July 2026 – New data from Heimdal’s telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine.…
MCP Server Security: The Blind Spot in Your AI Stack
Short version: an MCP server is the tooling layer that lets an AI agent act on external systems. Hosted remotely, it is an API endpoint like any other —…
Update your iPhone, iPad and Mac to fix Apple security holes
Apple issued a large July security update with several image processing related vulnerabilities that could compromise your device.
Novee brings continuous AI pentesting to mobile apps
Novee announced the expansion of its AI penetration testing platform to mobile applications. With this addition, Novee becomes the industry’s first…
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.
New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances
GenieLocker, a newly identified ransomware linked to the financially motivated Toy Ghouls group, targets Windows, Linux, and VMware ESXi systems and has…
Hackers abuse Microsoft Teams in ransomware campaign through fake IT support
Researchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.
Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion
Analog Devices, Inc., a leading U.S. semiconductor manufacturer specializing in analog, mixed-signal, and digital signal processing technology, has…
Amazon Attributes Earlier npm Supply Chain Attacks to North Korea’s Sapphire Sleet
Amazon has linked a series of high-profile npm supply chain compromises spanning 2025 and 2026 to the North Korean threat group Sapphire Sleet, suggesting…
Hackers Are Exploiting Nearly One in Four Vulnerabilities Before Defenders Get a CVE
Attackers are exploiting a significant portion of vulnerabilities even before defenders receive a published CVE (Common Vulnerabilities and Exposures). In…
Tribeca Film Festival Data Breach Exposes 666K Records
Security researcher Jeremiah Fowler discovered four publicly accessible databases containing nearly 666,000 records linked to the Tribeca Film Festival,…
New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances
A critical vulnerability, dubbed CosmosEscape, in Microsoft Azure Cosmos DB could have let attackers seize control of virtually every database hosted on…
Microsoft Warns of Rising ACR Stealer Campaigns Targeting Enterprise Credentials
Microsoft has observed an uptick in attacks using the ACR Stealer information-stealing malware family. Attackers distributed the malicious payload…
Vatican’s Click To Pray app exposed personal data from 700,000 users
Anyone could access other Click To Pray users’ personal information. The flaw went unfixed for more than six months after it was reported.
Experts react as Department for Education cyber attack exposes 607,000 records
The Department for Education (DfE) has confirmed that a cyber attack on two of its external-facing systems resulted in the theft of around 607,000…
API Security for Government Services: Protecting Citizen-Facing Applications
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: API Security for Government Services: Protecting Citizen-Facing Applications
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access…
TA488 Exploits Outlook Web Access Flaw with Half-Click Attack
TA488 is exploiting a Microsoft Outlook Web Access vulnerability to compromise users through half-click attacks.
Axon Is Another License Plate Surveillance Company
Governments are switching, but I’m not sure it makes a difference : …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But…