NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents” This article has been indexed from www.infosecurity-magazine.com Read the original article: NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
Chinese Company Starts Manufacturing DUV Chip Tools
Unnamed state-backed firm reportedly targets production of five immersion DUV lithography machines this year, in potential breakthrough This article has been indexed from Silicon UK Read the original article: Chinese Company Starts Manufacturing DUV Chip Tools
Shares In China’s CXMT Surge 466 Percent On Shanghai Debut
Hefei-based chipmaker, known for advances in high-end DRAM memory production, becomes China's most valuable listed firm This article has been indexed from Silicon UK Read the original article: Shares In China’s CXMT Surge 466 Percent On Shanghai Debut
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network…
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices This article has been indexed from www.theregister.com – Articles Read the original article: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027
AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition preserves traffic flow…
Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-sounding claims, there is no evidence…
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity…
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and…
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage This article has been indexed from www.infosecurity-magazine.com Read the original article: New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
PortSwigger Launches Burp AT to Transform Web Pentesting
PortSwigger has officially introduced Burp AT, an agentic AI assistant integrated directly into Burp Suite Professional. Now live… This article has been indexed from Hackers Online Club Read the original article: PortSwigger Launches Burp AT to Transform Web Pentesting
Google Adopts New Threat Actor Naming System
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. This article has been indexed from SecurityWeek Read the original article: Google Adopts New Threat Actor Naming System
China Chipmakers See Profits Surge 2,579.5 Percent
AI boom hits mainland China in first half of 2026, fuelling massive surge in profits as companies race to build data centres This article has been indexed from Silicon UK Read the original article: China Chipmakers See Profits Surge 2,579.5…
Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root Access
Progress has addressed five serious vulnerabilities affecting Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These vulnerabilities, tracked as CVE-2026-59686 through CVE-2026-59690, impact several older product releases and could lead to complete appliance compromise when exploited by…
Drone Follows Police Scotland Helicopter At Close Range
Drone passes within 50 feet of police helicopter, continues to follow it for about a minute in latest unmanned vehicle incident This article has been indexed from Silicon UK Read the original article: Drone Follows Police Scotland Helicopter At Close…
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited…
PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing
PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time. The new feature allows penetration testers to delegate specific investigative tasks to AI agents while retaining full control…
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure…
Microsoft Teams Vishing Attack Uses Quick Assist to Deploy GoGRPC Backdoor
A new Microsoft Teams vishing campaign is using fake IT support calls to gain remote access to corporate systems. The attackers then deploy GoGRPC, a Go-based backdoor that can run commands, collect system details, and maintain access to compromised devices.…
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools. This article has been indexed from Securelist Read the original article: Mirage Kitten targets Middle East and Africa…
Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video File
Multiple high-severity vulnerabilities have been identified in FFmpeg, the widely used open-source multimedia framework. These flaws impact media parsing, decoding, filtering, and encoding components and can be triggered when an application processes malicious files. Several issues can lead to heap…
Apple Delays First Smart Glasses to WWDC 2027 Over Privacy Concerns
Apple has postponed the reveal of its first smart glasses to WWDC in June 2027, with sales anticipated later that year, according to Bloomberg analyst Mark Gurm Thank you for being a Ghacks reader. This article has been indexed from…
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects
Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.…
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early…
