India gives WhatsApp three days to defend username rollout amid security fears
Government of the messenger's largest market demands a pause while Meta explains how it plans to stop impersonators
Aggregated from vendor advisories, security research, and industry publications.
Government of the messenger's largest market demands a pause while Meta explains how it plans to stop impersonators
Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. [...]
Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. [...]
Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals pro…
Interesting paper: “Cybersecurity Mission Creep.” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity.…
Anthropic said Tuesday night that its AI model called Claude Fable 5 is now widely available. The post Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cy…
CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]
A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified C…
Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. [...]
Researchers show how context manipulation can cause agentic browsers to abandon safety guardrails and exfiltrate sensitive credentials. The post ‘BioShocking’ Attack Tricks AI Brow…
Attackers appear to have reverse-engineered Big Red's patch
CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft Shar…
Seeking a deeper meaning to a network error
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUF…
A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. [...]
Capabilities are racing ahead of rules to ensure tech is used safely and responsibly, Scientific Panel argues
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were i…
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concep…
Fortunately, they were professional red teamers. Unfortunately, they pwned the network
Alleged illicit GPU movements lead to seizure of $42 million house
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilitie…
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]
Hyperscalers continue to invest astronomical amounts in data infrastructure for AI workloads, even as they concede that the massive projects may not pan out as planned. Oracle, …
They're 90 percent human in some ways, can provide daily companionship psychological support
Risk factors galore
It's a 'complete BEC operations environment,' Talos researcher says
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future …
Safer, cheaper, and nothing to do with cybersecurity
Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]
Oh, yeah, we've been meaning to disable our secret steganography system