Surtr Defense, a portfolio company of Robinhood Ventures Fund II, builds a hardware-agnostic operating system for drone defense, and the startup sits in a fund cohort that treats counter-UAS as core security infrastructure. RVII lists on the New York Stock Exchange on Aug 13, and the prospectus groups Surtr alongside…
Didit, backed by Robinhood Ventures Fund II, builds identity verification and fraud infrastructure for the financial stack.
Silmaril Security, an RVII portfolio company, builds runtime security for self-improving AI systems that outpace signature-based defenses.
Robinhood Ventures Fund II lists Aug 13 on the NYSE as RVII with a security cohort spanning digital identity, AI…
OpenAI halted internal work on its upcoming Astra model after evaluations suggested it could reach the critical cyber capability threshold.
Kaspersky says the Head Mare group exploited a two-flaw chain in unpatched TrueConf servers to poison client installers with the…
PortSwigger's HTTP Terminator generated and proved new HTTP desynchronization techniques and helped expose a patched Apache Traffic Server zero-day.
Tenet Security's Ghostjacking demo shows attackers planting instructions in logs that AI agents read and execute, targeting Cloudflare, Datadog, and…
The denim maker told the SEC that a social engineering attack hit three employee computers and led to exfiltration of…
A researcher found the Connective browser extension used by two million Belgians could be abused to read card data, steal…
IEH Corporation told the SEC that a phished employee's Microsoft 365 mailbox exposed engineering files and potentially export-controlled technical data.
A cyberattack forced all three North Carolina port facilities to delay gate openings and shift to manual processing, with the…
Two firms found independent ways to turn Atlassian's Rovo assistant into a one-click data leak.
Nearly 800 npm packages hide a cross-platform RAT and infostealer behind fake README instructions.
Google ties a vishing wave against finance and legal firms to UNC6671, which calls staff on personal phones.
WordPress ships an emergency fix for a pre-auth XSS chain that ends in PHP code execution.
Huntress documents a macOS ClickFix stealer that can drain crypto wallets and keychains.
A healthcare billing vendor says 3.8 million people's records were taken from its data center.
Attackers used an unknown Metabase flaw to grab admin access and customer data before a patch shipped.
Federal agencies have days to patch an exploited Progress ADC bug that drew hundreds of attack attempts.
A pre-auth XSS chain that needs only a crafted username ends in PHP code execution on stock installs.
Two research teams found ways to make Atlassian's AI assistant ship Jira and Confluence data to attacker servers.
Cisco's internal review with frontier AI models found 12 SD-WAN and IOS XE bugs, three rated 9.9.
Microsoft tracked a macOS ClickFix network that fingerprints visitors before serving its stealer lures.
Sign in to your account