Home
Products & Services
Technology
Medical
Security
Home
Products & Services
Technology
Medical
Security
Security
Updates
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl
08-10-2026 00:18
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx.
07-10-2026 23:13
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the applianc
07-10-2026 21:47
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's
07-10-2026 21:04
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the
07-10-2026 21:03
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise
07-10-2026 17:27
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) vir
07-10-2026 17:26
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS sc
07-10-2026 17:19
What Is Agentic Pentesting? What It Proves, and Where It Stops.
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is
07-10-2026 17:12
Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
Southern Company is notifying customers that their utility account information was accessed by hackers. The post appeared first on .
07-10-2026 14:15
Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
The individual was detained in May and has been extradited to Germany to face hacking charges. The post appeared first on .
07-10-2026 13:47
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing init
07-10-2026 13:37
Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform
Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers. The post appeared first on .
07-10-2026 13:06
Advantest Discloses Data Breach Months After Ransomware Attack
The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack. The post appeared first on .
07-10-2026 12:37
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The act
07-10-2026 12:27
Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track. The post appeared first on .
07-10-2026 10:51
Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models. The post appeared first on .
07-10-2026 10:07
ASOS Confirms Cyberattack, Data Breach
Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users. The post appeared first on .
07-10-2026 09:46
Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies
Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations The post appeared first on .
07-10-2026 07:58
Android’s October 2026 Updates Patch 25 Vulnerabilities
The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation. The post appeared first on .
07-10-2026 06:55
Atlassian Patches Critical Vulnerability Affecting 8 Products
Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post appeared first on .
07-10-2026 06:37
Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System
The Arizona Supreme Court said the information was copied for people dating back as far as 30 years. The post appeared first on .
07-10-2026 01:32
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Man
07-10-2026 00:08
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious s
06-10-2026 23:54
Samsung’s October Update Patches 9 Critical Security Flaws Across Galaxy Devices
Samsung’s October 2026 security update patches nine critical Android flaws and multiple Galaxy vulnerabilities. Here’s what users should update. The post appeared first on .
06-10-2026 20:09
AI Agents Leaked 13,000 Screenshots: Why Enterprise Approval Controls Failed
A reported leak of 13,000 screenshots shows how AI agents can bypass weak approval and audit controls even when organizations have written policies. The post appeared first on .
06-10-2026 17:29
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack work
06-10-2026 17:27
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unau
06-10-2026 16:56
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workfl
06-10-2026 16:32
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angu
06-10-2026 14:51
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post appeared first on .
06-10-2026 14:15
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post appeared first on .
06-10-2026 12:47
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and
06-10-2026 12:28
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, cit
06-10-2026 12:26
Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks
Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post appeared first on .
06-10-2026 11:48
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. T
06-10-2026 11:30
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026
Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind. The post appeared first on .
06-10-2026 11:01
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the web
06-10-2026 10:52
Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post appeared first on .
06-10-2026 10:34
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens. The post appeared first on .
06-10-2026 09:38
The quest for simplicity: Why SMBs want advanced protection without the complexity
The cybersecurity market is often making it tougher for SMBs to keep threats at bay
06-10-2026 09:00
Social Engineering Detection Moves Into the Live Conversation
Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering. The post appeared first on .
06-10-2026 08:38
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on
05-10-2026 21:51
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs i
05-10-2026 19:50
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and P
05-10-2026 17:25
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagatio
05-10-2026 17:16
St. Lucie County Finds Unpermitted Flock Cameras, Raising Privacy Concerns
St. Lucie County found 14 unpermitted Flock cameras, with 11 publicly unclaimed, raising questions about ownership, data access, and device oversight. The post appeared first on .
05-10-2026 16:14
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put us
05-10-2026 16:08
Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post appeared first on .
05-10-2026 14:26
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a
05-10-2026 13:39
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post appeared first on .
05-10-2026 13:00
California Man Charged in Alleged $300M AI Server Smuggling Scheme to China
A California tech executive faces federal charges over an alleged $300 million scheme to route export-controlled AI servers to China through Southeast Asia. The post appeared first on .
05-10-2026 12:36
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post appeared first on .
05-10-2026 12:35
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7
05-10-2026 12:10
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post appeared first on .
05-10-2026 11:00
Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach. The post appeared first on .
05-10-2026 10:42
Alleged ShinyHunters Leader Arrested in Jordan
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post appeared first on .
05-10-2026 07:16
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post appeared first on .
05-10-2026 05:14
Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force
The announcement comes after Trump hosted top executives of AI companies at the White House last week. The post appeared first on .
04-10-2026 14:57
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Di
04-10-2026 12:52
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns
04-10-2026 12:50
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on Sept
03-10-2026 20:08
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, obse
03-10-2026 20:06
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, secu
03-10-2026 16:30
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post appeared first on .
03-10-2026 11:45
Fortra Patches Critical Vulnerabilities in BoKS
The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post appeared first on .
03-10-2026 11:34
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI mode
02-10-2026 23:03
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakist
02-10-2026 23:03
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVS
02-10-2026 22:32
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing an
02-10-2026 17:53
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone e
02-10-2026 17:00
In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post appeared first on .
02-10-2026 14:30
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API servin
02-10-2026 13:31
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post appeared first on .
02-10-2026 13:15
Crypto Scammers Hijack Microsoft’s Official X Account
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post appeared first on .
02-10-2026 11:46
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability,
02-10-2026 11:19
In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post appeared first on .
02-10-2026 11:14
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post appeared first on .
02-10-2026 09:34
FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny
The FTC is investigating OpenAI, Anthropic and other AI firms over potential consumer harms, safety claims and risks tied to increasingly autonomous AI systems. The post appeared first on .
02-10-2026 08:50
AI Agents Aimed SQL Injection at US and Canadian Government Sites
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post appeared first on .
02-10-2026 08:38
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post appeared first on .
02-10-2026 08:07
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was o
01-10-2026 22:25
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A publi
01-10-2026 22:15
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed
01-10-2026 20:07
Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post appeared first on .
01-10-2026 18:00
Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post appeared first on .
01-10-2026 17:16
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices ou
01-10-2026 17:15
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first w
01-10-2026 16:12
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The
01-10-2026 16:03
Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post appeared first on .
01-10-2026 14:30
Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post appeared first on .
01-10-2026 14:30
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post appeared first on .
01-10-2026 14:17
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflo
01-10-2026 13:19
AI Has Changed Attack Speed, Not Security Fundamentals
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The post appeared first on .
01-10-2026 13:15
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post appeared first on .
01-10-2026 12:55
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post appeared first on .
01-10-2026 11:40
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded f
01-10-2026 11:24
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post appeared first on .
01-10-2026 10:51
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified mali
01-10-2026 10:51
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post appeared first on .
01-10-2026 10:42
source : hackernews, securityweek, techrepublicsecurity, welivesecurity