Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol…
China’s Moonshot AI Seeks Nvidia Blackwell Chips
Beijing-based start-up reportedly seeking access to more of Nvidia’s advanced chips to train next major release
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn…
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in…
OpenAI’s Rogue AI Agent Breached Second Company, Report Says
Reuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters…
Rogue OpenAI Agent Also Compromised Second Firm
Rogue OpenAI agent that hacked Hugging Face also penetrated customer system at Modal Labs, used it to launch attack
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security…
Apple Surpasses $5tn Valuation Amid AI Plunge
Investors look to Apple as relatively safe bet, as spending jitters spur sell-off of AI-related stocks
Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated…
Ofgem Proposes Stiffer Rules For Data Centre Projects
UK energy regulator publishes consultation on more stringent processes designed to weed out speculative data centre plans
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
Bank of Baroda Data Breach – Hackers Gained Access Via Employee Email Account
Bank of Baroda has confirmed a cybersecurity incident in which attackers gained unauthorized access to an employee’s email account, exposing internal…
FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments
Fortinet has announced the FortiGate 1200G series, the newest addition to the FortiGate G series with FortiSASE Outpost, which brings cloud-delivered…
Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely
A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This…
Stolen Meta and Google ad accounts are worth more than the money they hold
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete…
WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2
A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete…
WhatsApp brings end-to-end encrypted voice and video calls to the web
WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without…
Root Evidence puts real-world evidence at the center of vulnerability prioritization
Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world…
Torq makes AI SOC investigations continuously self-learning
Torq has introduced Torq SOC Brain, a new layer of the Torq AI SOC Platform that continuously learns from historical investigations, analyst decisions,…
Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection
A newly analyzed Android remote access trojan (RAT) dubbed “Flying Eagle” is leveraging Accessibility Services to enable large-scale surveillance,…
1Password targets standing privileges with new access management capabilities
1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables…
Google Australia Customers Now Benefit From Imperva Cloud-Native WAAP Security
Many Australian businesses have moved their applications and data to cloud-native architectures for agility, scalability, and sovereignty. However, this…
Tines introduces AI-native platform for secure enterprise workflow automation
Tines has launched Tines 3B, an AI-native platform for building, running and governing enterprise workflows, applications and agents securely at scale. AI…