Judgment day looms for UK's £8.35B Skynet military satellite comms upgrade
Supplier stumbles and MoD staffing shortages earn the program a red delivery rating
Aggregated from vendor advisories, security research, and industry publications.
Supplier stumbles and MoD staffing shortages earn the program a red delivery rating
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disc…
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on …
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator…
Biggest-ever DSA fine shows Brussels wants to bust the biz model behind China’s cheap e-commerce champs
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intell…
Single datacenter and just three services taken down by ‘upstream’ power problem, while the rest of a zone and region kept humming
French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
Cosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operat…
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances…
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed pr…
Plus dozens of PoCs in the public domain
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on t…
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Goo…
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model che…
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions.
IC3 says any account claiming to represent it is fake
An expired card, overzealous spam filter, and broken authenticator create havoc with a very clear moral
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today.
Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
Chinese open-weight model GLM 5.2 happily obliged
Convenience store and gas station chain Sheetz announced it is replacing VMware across its network of more than 830 retail locations with StorMagic’s SvHCI hyperconverged infrastru…
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protoc…
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltra…
Take a Network Break! In this week’s episode our red alert highlights two critical vulnerabilities in RabbitMQ, and we dig into listener follow-up about data centers in space. This…
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments…
OOXML may carry an ISO certificate, but only Office can be trusted to render it properly