x86.se x86.se

Categories

  • Access Control
  • Access Management
  • Active Directory
  • Ad Fraud
  • AdTech
  • Adversarial Exposure Validation
  • Afghanistan
  • Agent Security
  • AgentForce
  • Agentic AI
  • Agentic AI control
  • AI
  • AI & ML Security
  • AI adoption metrics
  • AI agents
  • AI Automation
  • AI councils
  • AI firewall
  • AI governance
  • AI identity
  • AI model
  • AI observability and logging
  • AI Safety
  • AI Security
  • AI security frontier
  • AI threat detection
  • AI-driven security
  • AI-native security
  • Airline
  • AitM
  • Akira
  • Altcoin
  • Amatera Stealer
  • Android
  • Anodot
  • Anthropic
  • Anti-Malware Research
  • Antitrust
  • API Security
  • Apple
  • Application Security
  • AppSec
  • AppSheet
  • APT
  • APT Groups
  • apt28
  • Archer Health
  • Artificial Intelligence
  • Ascend AI
  • Ascension
  • Asset Management
  • AsyncRAT
  • ATM Security
  • Attack Surface
  • Attack Surface Management
  • Authentication
  • Automation
  • AWS
  • Azure
  • backdoor
  • Backup Software
  • Banking Fraud
  • Banking Malware
  • Banking Security
  • Beagle red teaming
  • Behavioral analytics UBA
  • Binance
  • Bishop Fox
  • Bitcoin
  • Bitwarden
  • Black Basta
  • Black Hat 2025
  • Blackpoint Cyber
  • Blockchain
  • Botnet
  • Botnets
  • Breach
  • Breach and Attack
  • Breach Prevention
  • Breach Simulation
  • BreachForums
  • BRICKSTORM
  • Browser
  • Browser extension security
  • Browser Security
  • Business Continuity
  • C2
  • CA SiteMinder
  • Canada
  • Captcha
  • Carbon Black
  • Censorship
  • Centralized policy enforcement
  • ChatGPT
  • Children
  • ChillyHell
  • China
  • Chrome
  • CIO and CISO alignment
  • Cisco
  • CISO
  • CISO strategies
  • CISO strategy
  • Cl0p
  • ClaimPix
  • Claude
  • Claude Code
  • Claude Mythos Preview
  • ClickFix
  • Clop
  • Cloud
  • Cloud Computing
  • Cloud Security
  • Cloud Security,
  • CloudFlare
  • CloudSEK
  • Code Security
  • Codex Security
  • Coding
  • Cofense
  • command-and-control
  • Compliance
  • Compliance and audit readiness
  • Compliance GDPR HIPAA PCI
  • Conditional Access
  • ConnectWise RAT
  • Container Security
  • conti
  • Continuous Monitoring
  • Continuous Threat Exposure Management
  • Copilot
  • Copyright
  • Corporate Espionage
  • Counterfeiters
  • Credential hygiene
  • Credential Theft
  • Critical Infrastructure
  • CRM
  • CrowdStrike Falcon Fund
  • Crypto
  • Cryptocurrency
  • Cryptography
  • Cryptojacking
  • CVE-2021-43798
  • CVE-2023-21563
  • cve-2023-24932
  • CVE-2024-50623
  • CVE-2024-55956
  • CVE-2024-58260
  • CVE-2025-10035
  • CVE-2025-10547
  • CVE-2025-10725
  • CVE-2025-27915
  • cve-2025-30247
  • cve-2025-4008
  • CVE-2025-41250
  • CVE-2025-41251
  • CVE-2025-41252
  • CVE-2025-43400
  • cve-2025-49844
  • CVE-2025-52906
  • CVE-2025-57714
  • CVE-2025-59489
  • CVE-2025-59934
  • CVE-2025-59951
  • CVE-2025-61882
  • CVE-2025-9230
  • CVE-2025-9231
  • CVE-2025-9232
  • Cyber Attack
  • Cyber Attacks
  • Cyber Crime
  • Cyber Espionage
  • Cyber Extortion
  • Cyber Insurance
  • Cyber Resilience
  • Cyber Warfare
  • CyberArk
  • Cybercrime
  • Cyberespionage
  • Cybersecurity
  • Cybersecurity Innovations and Excellence
  • Cybersecurity News
  • Cybersecurity Training
  • Cyberwarfare
  • Dark Web
  • DarkForums
  • Darwinium
  • Data Breach
  • Data breach prevention
  • Data Breaches
  • Data Exfiltration
  • Data Exposure
  • Data Integrity
  • Data leak
  • Data leak prevention
  • Data Privacy
  • Data Protection
  • Data Security
  • Data Theft
  • Database Security
  • DDoS
  • DDoS attack
  • DDoS Attacks
  • Defend AI
  • Defense Technology
  • DeFi
  • denial-of-service
  • Detour Dog
  • Developer
  • Developer Security
  • Developer Tools
  • Developers
  • DevOps
  • DevOps Security
  • DevSecOps
  • Digital Advertising
  • Digital Crime
  • Digital Forensics
  • Discord
  • DNS
  • Documents
  • Driver Security
  • Dubai
  • Economic Espionage
  • Edge
  • Education
  • EggStreme
  • EggStremeAgent
  • Email Security
  • Empire Podcast
  • Employee AI governance
  • Encryption
  • Endpoint Security
  • Enterprise AI
  • Enterprise IT
  • Enterprise model security
  • Enterprise Security
  • Enterprise Software
  • Espionage
  • Ethereum
  • Europol
  • exploit
  • Exploits
  • exposure
  • Exposure Management
  • Exposure Validation
  • Extensions
  • Extortion
  • Facebook
  • Fake ID
  • Featured
  • Federal Security
  • File Transfer
  • Fileless
  • FIN11
  • Financial Crime
  • Financial Fraud
  • Financial Security
  • Firebox
  • firewall
  • Firewall Security
  • Firmware Security
  • ForcedLeak
  • ForgeCraft
  • ForgeRock
  • Fortra
  • France
  • Fraud
  • FraudGPT
  • FTC
  • Gaming
  • GDPR
  • Gemini AI
  • Gemini Trifecta
  • Generative AI
  • GitHub
  • GitHub Copilot
  • Global AI risk mapping
  • GoAnywhere
  • GoGra
  • Google
  • Google Cloud
  • Google Workspace
  • Government
  • Great Firewall of China
  • Hacking
  • Hacking News
  • Hacks
  • Hacktivism
  • Hardware
  • Hardware Security
  • Harvester APT
  • Healthcare
  • HexDex
  • Hiddengh0st
  • HIPAA
  • ics
  • ICS Security
  • ICS/OT
  • identity
  • Identity & Access
  • Identity and Access Management
  • Identity and Access Management (IAM)
  • Identity Governance
  • Identity Management
  • Identity Security
  • Identity theft
  • IIServerCore
  • Incident Response
  • India
  • Indirect Prompt Injection
  • Industrial Sabotage
  • Industry Recognition
  • Influencers
  • Info Stealer
  • Infostealer
  • Infrastructure
  • Infrastructure Security
  • Initial Access Broker
  • Insider Threat
  • Insider Threats
  • Internet of Things
  • iOS
  • IoT
  • IoT Research
  • IoT Security
  • IPI
  • IT Compliance
  • IT Operations
  • Jaguar Land Rover
  • Jailbreak attack protection
  • JavaScript
  • Jeremiah Fowler
  • JPEG
  • Kernel
  • Kido
  • Kubernetes
  • Lapsus$
  • LastPass Secure Access Experiences
  • Lat61
  • Law Enforcement
  • LayerX
  • leak
  • leaked
  • Leaks
  • Legal
  • Linux
  • Linux Security
  • LLM
  • LLM analysis
  • LLM Security
  • LNER
  • Lone None
  • Lone None Stealer
  • Los Pollos
  • Lua
  • machine learning
  • macOS
  • Magecart
  • Malvertising
  • Malware
  • Malware Analysis
  • Mandiant
  • MATANBUCHUS
  • MatrixPDF
  • MCP Server
  • Medusa
  • Messaging Security
  • Meta
  • MFA
  • Mic-E-Mouse
  • Microsoft
  • Microsoft Defender
  • Microsoft Entra
  • Microsoft Entra ID
  • Mid-sized enterprise cybersecurity
  • Military
  • Military Security
  • Misconfiguration
  • ML
  • Mobile
  • Mobile Security
  • Money Laundering
  • Muck Stealer
  • Multi-Factor Authentication (MFA)
  • Mustang Panda
  • Mythos AI
  • Nation-state
  • National Security
  • National Security,
  • NET-STAR
  • Netherlands
  • Network
  • Network Security
  • NPM
  • Nursery
  • Offensive AI
  • Offensive Security
  • Okta
  • Oleria
  • Online Fraud
  • Online Scam
  • Online Security
  • Open Source
  • Open Source Security
  • OpenAI
  • Operational Technology
  • OWASP Top 10
  • Owen Flowers
  • Pakistan
  • Palo Alto
  • Passkey support
  • Passport
  • Password Management
  • Password manager
  • Password Security
  • Patch Management
  • Patch Tuesday
  • Payment Security
  • PCI-DSS
  • PDF
  • Penetration Testing
  • Pentesting
  • PhaaS
  • Phantom Taurus
  • Philippine
  • Phishing
  • Phishing Protection
  • Phishing Scam
  • PingFederate
  • PoC
  • Podcast
  • Point Wild
  • Police
  • Popular
  • PowerShell
  • Press Release
  • Privacy
  • Privacy & Compliance
  • privilege escalation
  • Privileged Access Management (PAM)
  • Project Glasswing
  • Prompt injection defense
  • proof-of-concept
  • PropellerAds
  • ProSpy
  • PSF
  • Pure Logs Stealer
  • PureMiner
  • PyPI
  • Python
  • QRadar SIEM
  • Qrator Labs
  • Quantum Computing
  • Quantum Resistance
  • Ransom
  • Ransomware
  • Ransomware Defense
  • Raven AI
  • Raven Stealer
  • rce
  • Real-time policy enforcement
  • Recap
  • Red Teaming
  • Redis
  • RediShell
  • Regulation
  • Regulatory Compliance
  • Remote Access Trojan
  • RemoteCOM
  • Renault
  • Report
  • Research
  • Resource-constrained businesses
  • Risk Management
  • Russia
  • SaaS
  • SaaS Monitoring
  • SaaS Protect
  • SaaS Security
  • SailPoint
  • Salesforce
  • Samsung
  • SCADA
  • Scam
  • Scam Research
  • Scams and Fraud
  • Scattered Lapsus$ Hunters
  • Scattered Spider
  • SCOUT
  • ScreenConnect
  • Secrets Management
  • Secure Coding
  • Secure Messaging
  • Secure passwordless authentication
  • Security
  • Security Automation
  • Security Culture
  • Security Incident
  • Security Leadership
  • Security Operations
  • Security Testing
  • Security Training
  • security update
  • Security Validation
  • Senator
  • SentinelOne
  • SEO Poisoning
  • Seraphic Security
  • Server Security
  • Shadow AI
  • Shadow AI detection
  • Shadow AI risks
  • Shadow IT
  • Shadow IT risks
  • Shinobi Security
  • ShinyHunters
  • Shuyal Stealer
  • SIEM and conditional access integration
  • Signal
  • Silverfort
  • SIM Swapping
  • SimpleHelp RAT
  • Single Sign-On (SSO)
  • SMB
  • SMB Security
  • SMS
  • Snow
  • SOC Automation
  • SOC Operations
  • Social Engineering
  • Social Media
  • Software
  • Software Development
  • Software Integrity
  • Software Security
  • Software Supply Chain
  • spam
  • SpamGPT
  • Spotlight
  • Spying
  • Spyware
  • SSO
  • state-sponsored
  • Stealer
  • Straiker
  • StreamYard
  • Strela Stealer
  • Supply Chain
  • Supply Chain Attack
  • Supply Chain Security
  • Surveillance
  • SVG
  • Symantec
  • TeamPCP
  • Technology
  • Telegram
  • TFL
  • Thalha Jubair
  • Threat Detection
  • Threat Exposure
  • Threat Hunting
  • Threat Intelligence
  • Threat Intelligence,
  • Threat Mitigation
  • Threat Research
  • ThreatLocker
  • ToSpy
  • ToTok
  • TradingView
  • Training
  • TROJAN
  • Typosquatting
  • UAE
  • Udemy
  • UK
  • Ukraine
  • Unauthorized SaaS applications
  • UNC5221
  • UNC6692
  • Uncategorized
  • United Kingdom
  • United States
  • USA
  • Vane Viper
  • Varun Uppal
  • Venafi
  • Vibe Coding
  • Vidar
  • Vietnam
  • VoidProxy
  • VPN
  • VPN Security
  • Vulnerabilities
  • Vulnerability
  • Vulnerability Disclosure
  • Vulnerability Management
  • Vulnerability Research
  • WatchGuard
  • Web Browser
  • Web Hosting
  • Web Security
  • Web Server
  • Web Services
  • Web3
  • Webinar
  • Website Security
  • Website Security,
  • WestJet
  • WhatsApp
  • Whitepapers
  • Windoes
  • Windows
  • Windows Security
  • Winnti
  • Winos
  • Wireless Security
  • WitnessAI Secure AI Enablement Platform
  • Workflow Automation
  • Workflow Security
  • WormGPT
  • Xcape
  • XSS
  • Yadi Zhang
  • YoLink
  • YoLink Smart Hub
  • Zara
  • Zero Day
  • Zero Trust
  • Zero-Day
  • Zeroday
  • Zhimin Qian

x86.se x86.se

x86.se x86.se

What are You Looking For?

  • Malware
  • Vulnerabilities
  • Ransomware
  • Vulnerability
  • Cryptocurrency
  • Malvertising
3 Min Read
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
July 30, 2026

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pag…
13 Min Read
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
July 30, 2026

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A lot of security still comes down to trusting the wrong screen. This…
  • Cybersecurity News
  • Hacking News
3 Min Read
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
July 30, 2026

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an…
  • Cloud Security
  • Vulnerability
3 Min Read
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
July 30, 2026

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Hidden instructions in a Word document can make Microsoft 365 Copilot…
  • AI Security
  • Vulnerability

Explore Trending Topics

Malware
Vulnerabilities
Ransomware
Vulnerability
Security
Windows
  • AI Security
  • Network Security
4 Min Read
The Network Has Become the Control Plane for AI Security
July 30, 2026

The Network Has Become the Control Plane for AI Security

Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and…
  • Vulnerability
  • Web Security
5 Min Read
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
July 30, 2026

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The…
  • Cybercrime
  • Threat Intelligence
3 Min Read
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
July 30, 2026

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD)…
  • Email Security
  • Vulnerability
5 Min Read
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
July 30, 2026

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another…
  • Regulation
  • Supply Chain Security
3 Min Read
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
July 30, 2026

FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28.…
  • Software Security
  • Threat Intelligence
4 Min Read
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
July 30, 2026

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public…
  • Network Security
  • Vulnerability
2 Min Read
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
July 30, 2026

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure…
  • Software Security
  • Vulnerability
4 Min Read
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
July 29, 2026

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files…
  • Cybercrime
  • Law Enforcement
3 Min Read
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
July 29, 2026

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly…
  • Enterprise Security
  • Vulnerability
2 Min Read
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
July 29, 2026

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point…
  • Artificial Intelligence
  • Vulnerability
5 Min Read
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
July 29, 2026

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging…
  • DevOps
  • Vulnerability
3 Min Read
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
July 29, 2026

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access…
  • Mobile Security
  • Threat Intelligence
3 Min Read
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
July 29, 2026

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and…
  • Developer Security
  • Malware
3 Min Read
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
July 29, 2026

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated…
  • Artificial Intelligence
  • Encryption
5 Min Read
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
July 28, 2026

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an…
  • Endpoint Security
  • Linux
3 Min Read
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
July 28, 2026

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its…
  • Server Security
  • Vulnerability
4 Min Read
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
July 28, 2026

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces…
  • Enterprise Security
  • Vulnerability
2 Min Read
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
July 28, 2026

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical…
  • Linux
  • Vulnerability
3 Min Read
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
July 28, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw,…
  • AI Security
  • Vulnerability Management
3 Min Read
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
July 28, 2026

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation…
  • Threat Intelligence
  • Vulnerability
3 Min Read
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
July 28, 2026

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in…
  • AI Security
  • Software Security
5 Min Read
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
July 27, 2026

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for…
  • Botnet
  • IoT Security
3 Min Read
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
July 27, 2026

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device…
  • Vulnerability
  • Website Security
3 Min Read
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
July 27, 2026

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute…
  • Cybersecurity
  • Hacking
10 Min Read
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
July 27, 2026

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old…
  • Cyber Attack
  • Threat Intelligence
3 Min Read
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
July 27, 2026

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities…
  • DevSecOps
  • Software Supply Chain
2 Min Read
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
July 27, 2026

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before…
  • Browser Security
  • Malvertising
3 Min Read
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
July 25, 2026

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun…
  • Application Security
  • Vulnerability
3 Min Read
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
July 25, 2026

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected…
  • Cybercrime
  • Phishing
6 Min Read
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
July 25, 2026

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and…
  • Vulnerability
2 Min Read
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
July 25, 2026

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in…
  • Cybercrime
  • Ransomware
5 Min Read
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
July 25, 2026

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability…
  • Application Security
  • Vulnerability
3 Min Read
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
July 25, 2026

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June…
  • Artificial Intelligence
  • Malware
5 Min Read
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
July 24, 2026

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found…
  • Enterprise Security
  • Vulnerability
3 Min Read
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
July 24, 2026

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a…
  • Enterprise Security
  • Vulnerability
4 Min Read
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
July 24, 2026

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single…
  • Vulnerability
  • Web Security
4 Min Read
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
July 24, 2026

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as…
  • AI Security
  • Enterprise Security
7 Min Read
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
July 24, 2026

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively…
  • Artificial Intelligence
  • Threat Intelligence
5 Min Read
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
July 24, 2026

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky…
  • Browser Security
  • Threat Intelligence
3 Min Read
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
July 24, 2026

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating…
  • Vulnerability
  • Web Security
4 Min Read
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
July 24, 2026

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity…
  • Database Security
  • Vulnerability
3 Min Read
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
July 24, 2026

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and…
x86.se x86.se