The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested…
Tag: EN
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska,…
Sakura Internet Breach – Hackers Accessed 1.36 million Customers’ Personal Records
Sakura Internet has disclosed a potential breach involving its sales management system, placing the personal records of up to 1.36 million customer…
Rust Supply Chain Attack Linked to North Korean Hackers
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
DOJ Charges 17 Iranian Hackers in IRGC-Linked Campaign That Stole 31.5TB of Research Data
The U.S. Department of Justice has unsealed a 14-count superseding indictment against 17 alleged members of the Iran-based Mabna Institute, accusing them…
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to…
OpenAI Offers Zero Data Retention for Frontier AI Models With Private Safety Processing
OpenAI has announced Zero Data Retention for eligible API customers using its frontier AI models, alongside a new Private Safety Processing system…
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of…
Critical Spring Security Flaw Lets Attackers Gain Admin Access to LDAP Servers
A critical vulnerability in Spring Security’s embedded UnboundID LDAP server can allow remote attackers to gain administrative access to exposed in-memory…
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S.…
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities…
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base.
Microsoft Rolls Out 22 Fresh Security Patches
Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities.
Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
Three suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats,…
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability…
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun…
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490,…
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw
A software flaw in Coldcard hardware wallets has raised fresh concerns about the security of offline cryptocurrency storage after a software flaw in…
Cybersecurity Job Ads Requiring AI Skills Double
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again:…