Barracuda finds phishing emails designed to manipulate both human users and AI assistants
Gartner Defines New ISOC Security Tool Category
Gartner has defined a new category of security tools called Integrated Security Operations Center (ISOC), marking a significant shift in how the industry…
The trust gap that AI watermarking can’t close
By Alex Laurie, GTM CTO, Ping Identity Generative AI has made content creation effortless, but establishing where content originates – and whether it can…
Chinese Hacker Uses AI in South Korean Bank Campaign
Multiple South Korean financial institutions suffered data breaches in a campaign where a suspected Chinese threat actor deployed AI-powered pentesting…
CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight…
De Kalb County, Indiana fell prey to vendor impersonation billing
The Star reports that the DeKalb County government fell victim to a cybersecurity incident for the second time in little more than a year. This time, it…
From Automation to Infection (Part III): Naming, Measuring, and Detecting Malicious AI Agent Skills
In Part I and Part II of this series, we looked at an initial sample of 3,016 AI agent skills and showed how they were becoming a new supply-chain…
UAT-11985: AI-assisted AitM phishing targeting Taiwan
Cisco Talos Intelligence has identified an advanced persistent threat campaign targeting individuals affiliated with Taiwan-based research organizations…
SonicWall and Splunk Patch Critical Vulnerabilities
Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.
Amazon has an uncomfortably personal profile on you
Amazon thinks it knows your body, your family, and your life. You didn’t sign up for it, and we couldn’t find a way to opt-out.
Middle managers want tighter human oversight of AI than their bosses, TeamViewer research finds
Executives may be more relaxed about handing IT decisions to AI than the managers who answer to them, according to new research from TeamViewer. The study…
What Is Agentic Pentesting? What It Proves, and Where It Stops.
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it…
Hackers exploit critical Atlassian flaw after public PoC release
A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in…
Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and…
It Wasn’t Me, It Was the AI Agent” May Not Avoid Liability Under New Senate Proposal
Odia Kagan of FoxRothschild writes: “It wasn’t me, it was the AI agent” may not help companies avoid civil or criminal liability under a new bipartisan…
Context Over Alerts: SOC Evolution Strategy
Security operations centers face a fundamental challenge that more alerts cannot solve.
US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward
Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive…
Europol and US GAO Warn of Quantum Computing Threats
Europe’s leading law enforcement agency and the US government’s spending watchdog released reports this week urging organizations to accelerate adoption…
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. […]
Ransomware Recovery Scheme Nets $11M Markup
A ransomware recovery operator has been exposed for running a scheme that generated $11 million in markups by secretly paying ransoms and reselling…
Microsoft Teams to get support for third-party deepfake detection tools
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. […]
Oracle Health breach affects nearly 20M
Oracle Health has confirmed that a data breach impacted approximately 20 million individuals, marking a substantial increase from figures reported in…
