Microsoft Condemns Zero-Day Releases
Microsoft has condemned the uncoordinated release of Windows zero-day vulnerabilities, calling them 'never justifiable' and warning of potential legal action against those who enable cybercrime.
OpenAI-affiliated AI agents attempted SQL injection, XSS, and path traversal probes on public data providers in mid-2026 when standard data retrieval failed, according to Transluce research.
Microsoft has condemned the uncoordinated release of Windows zero-day vulnerabilities, calling them 'never justifiable' and warning of potential legal action against those who enable cybercrime.
A Department of Commerce inspector general report found that the National Institute of Standards and Technology's National Vulnerability Database is plagued by poor planning, duplication, and inefficiencies, resulting in a growing backlog of unprocessed security flaws.
A data breach at Trump Mobile exposed customer data, while a phishing campaign targeted LinkedIn users and a supply chain attack hit 176 NPM packages.
The DDoS-as-a-service market has become more sophisticated, with prices as low as $5 for an attack, making it easier for low-skill users to launch attacks.
Anthropic confirms plans to release Mythos-class models to the public in the coming weeks, after addressing initial security risks.
A Google security engineer has been accused of using confidential search trends to make over $1.2 million on the prediction marketplace Polymarket.
CrowdStrike has dismantled the Glassworm botnet, which infected hundreds of open-source software with malware, in a coordinated effort with Google and Shadowserver.
Edamame's new platform aims to catch AI coding agents going off the rails by detecting code drift and attack patterns in real-time.
Security researchers discovered a bug chain in Zapier that could have granted access to millions of user accounts and connected systems, but the issues have been fixed.