ESET Research catalogs the changes of UAC-0099’s MATCHBOIL downloader from 2024 to 2026
Tag: EN
Australian Gov’t Weighs Mandatory AI Incident Reporting
In the wake of an agentic attack against its own Medicare systems, Australia’s government is feeling out what regulations might look like for frontier AI…
How Hackers Exploit AI agents Claude Code Enterprise Network Intrusions
HOC Shorts Adversaries are transitioning from using Large Language Models (LLMs) as passive reference tools to actively exploit…
Dread Dark Web Forum Hijacked, Operators Claim Control of Domain Keys (Updated)
Dread dark web forum appears hijacked after a pinned post claimed control of the project and domain keys, while denying plans to leak user data.
OWASP Top 10 For LLM Applications: Complete Guide
By HOC Team | Updated: October 2026 | Read time: ~18 min Large Language Models (LLMs) have fundamentally…
Evolution of Web3 in Cloud Supply Chain Attacks
Unit 42 details how threat actors leverage Web3 infrastructure and open-source supply chain attacks to breach enterprise cloud environments
Shaq Got Hacked. Now He’s Pitching for a VPN
At a recent event for security firm NordVPN, NBA superstar Shaquille O’Neal revealed that he got hacked—and warned the public about the need to “have…
AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI
AI Agents, Security Debt, and Governance: Dave Lewis on the Real Risks of AI in Cybersecurity Host David Shipley interviews Dave Lewis of 1Password about…
CVE-2026-21589: Critical Pre-Authentication File Read Affects Atlassian Data Center Products
Atlassian has released an out-of-band security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting a broad range of its…
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out…
Citizen Lab Slams Trump Administration, ‘Techno-Fascist’ Executives
The Citizen Lab’s Ron Deibert warns the US government is pushing for pervasive surveillance and says certain technology executives are all too happy to…
Building your AI vulnerability harness, Part 1
Vulnerability scanners produce findings faster than manual triage can process them. Your developers ship more code with more dependencies, and the volume…
Critical Atlassian File Access Flaw Draws Attacks Across Eight Products
CVE-2026-21589 is being exploited after a public PoC, putting self-hosted Jira, Confluence, Bitbucket and other Atlassian products at risk.
FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor
The FBI and DOJ seized domains and disrupted scanning and spear-phishing tools used by Flax Typhoon, a China-linked…
Texas AG Says Oracle Health’s 2025 Breach Affected 20M Individuals
A Texas AG filing says Oracle Health’s 2025 breach affected nearly 20 million people, while major questions about access and attribution remain.
Google Chrome Update Fixes 247 Security Flaws, Including 4 Critical Bugs
Google Chrome 155 fixes 247 security vulnerabilities, including four Critical use-after-free flaws. See what security teams should do now.
Configuring your AI vulnerability harness, Part 2: The steering file
This post shows you how to configure an AI model to perform structured, evidence-based vulnerability triage with the consistency of a seasoned security…
New Report Finds 43% of Security Pros Still Use Passwords
The 2026 Global State of Authentication report finds 43% of security pros still use passwords at work despite passkey awareness and rising AI phishing…
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness.
Anthropic Gives Vetted Defenders Fewer Claude Guardrails
Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.
