Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
23-year-old botnet down
Aggregated from vendor advisories, security research, and industry publications.
23-year-old botnet down
More compliance-friendly stance could boost appeal of Fable
Palo Alto Networks is bolstering its flagship security platform with the acquisition of Console and its AI-native IT service management and automation technology. According to P…
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Base…
When it comes to AI and the mainframe, customers are moving from experimental to operational approaches and feeling comfortable enough to use AI to provide system insights and reco…
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect re…
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
The model provider gave METR the credits for free. An actual customer would not have been so lucky
The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alt…
Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
Security ... this time it will be different
Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Pr…
The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime…
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal cre…
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in q…
What does Enterprise Architecture (EA) mean when AI is everywhere in the stack? Enterprise Architecture is about nailing down relationships and functions while AI pushes back with …
To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent p…
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.…
Coruna and DarkSword are exploit frameworks that have successfully targeted Apple iPhones to steal cryptocurrency and harvest data including messages, email, location data, and bro…
30 years on, it's still alpha, but 0.4.16 brings plenty of bug fixes and quality-of-life improvements - just in time for Windows XP's 25th anniversary
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, w…
Big Red talks up superhuman coders after shedding 21,000 staff
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to maliciou…
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
New services promise private 100 Gbps links between the rival platforms without months of networking faff