Recent government data shows the scale of cyber threats facing security teams. According to the Cyber Security Breaches Survey 2025/2026, it’s estimated…
JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI…
Mythos Asks the Right Question. It Doesn’t Answer It.
AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve…
Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
Android malware scanners are increasingly misaligning with real-world risk by over-flagging legitimate, high-permission applications while quietly missing…
Managing cyber-physical risk in smart buildings
Smart buildings promise greater efficiency, improved sustainability and enhanced operational oversight. However, as building management systems, security…
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of…
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.…
Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the…
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the…
WhatsApp Adds End-to-End Encryption for Voice and Video Calls
WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its…
A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online
A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network. The toolkit lets operators create…
NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages
NVIDIA has revealed a significant security vulnerability in its BlueField data processing units (DPUs) that could allow virtual machine (VM) users to…
Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System
Broadcom has released a critical security advisory, VMSA-2026-0006, addressing multiple high-impact vulnerabilities across core VMware virtualization…
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
VulnGym Uses AI-Trained APT Attackers to Stress-Test Enterprise Patching Strategies
A new cybersecurity research tool called VulnGym utilizes reinforcement learning to simulate AI-trained advanced persistent threat (APT) attackers…
Threat Actor Claims Revolut Data Breach Exposes Financial Records of 75 Million Users
A threat actor has reportedly claimed to possess and sell a large dataset allegedly linked to the fintech company Revolut, purportedly affecting more than…
CISA Releases Checklist for Critical Infrastructure Organizations to Isolate Vital Systems
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center…
Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks
Russian intelligence-linked hackers have shifted tactics to target Signal users’ backup recovery keys, enabling full account takeover and access to…
AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers…
Contrast CVE Shield aims to protect applications while security teams deploy patches
Contrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced…
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and…
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face…
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating…
CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the FBI, and international partners, has…