Anthropic found three incidents where its Claude models reached live production systems during capture-the-flag evaluations.
Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
Researcher Hakon Maloy showed how hidden instructions in a Word file can alter Copilot output and copy themselves into new…
Okta's deal for Permiso Security merges identity threat detection with posture management as AI agents multiply.
North Korea-linked actors are using fake full-screen macOS updates to push ClickFix-style clipboard attacks.
CVE-2026-60004 lets a repository writer plant a git hook and run commands as the Gitea service account.
Hackers stole personal, financial and medical data from CareCloud's AWS environment in March.
Research finds tens of thousands of internet-facing BMCs disclosing IPMI password hashes without authentication.
A CVSS 9.5 Rails Active Storage flaw lets unauthenticated attackers read arbitrary server files through crafted image uploads.
Ruflo's unauthenticated MCP bridge earns a perfect CVSS 10 as researchers demonstrate AI memory poisoning.
CISA adds actively exploited Cisco FMC static credentials flaw to its known vulnerabilities catalog.
TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
DentaQuest is notifying over 23 million patients after the ShinyHunters extortion group stole 234 GB of data including Social Security…
Microsoft unveiled MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, scoring 96% on CyberGym benchmarks and cutting vulnerability discovery costs by…
CI/CD platforms have become prime targets for attackers seeking supply chain access, and JetBrains’ latest security advisory underscores the risk.
Broadcom shipped emergency patches for a critical VM escape vulnerability affecting VMware ESXi, vCenter, and Fusion products.
A coordinated cyberattack targeted operational technology systems at more than 30 community water utilities across Minnesota.
Data security company Cyera agreed to acquire agentic access management provider Oasis Security in a $1 billion deal.
Threat actors compromised captive Wi-Fi gateways at hotels to silently redirect business travelers to fake Microsoft 365 login pages.
Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers to turn compromised systems into covert relay nodes across the Middle…
BlackFog researchers dissect MedusaHVNC, a remote access trojan that exploits Windows hidden desktops to hijack browser sessions and evade detection.
Researchers released a Certighost exploit for a critical AD CS flaw that lets authenticated users escalate privileges to full domain…
Group-IB discovered HOLLOWGRAPH, malware that uses Microsoft 365 calendars as covert command channels with events dated to 2050.
US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.
Sign in to your account