Linux Kernel Vulnerabilities & AI-Powered Malware
A massive influx of 432 Linux kernel vulnerabilities was disclosed, while AI-powered Dolphin X malware targets over 300 applications to exfiltrate sensitive data.
279 articles
A massive influx of 432 Linux kernel vulnerabilities was disclosed, while AI-powered Dolphin X malware targets over 300 applications to exfiltrate sensitive data.
Industry groups are pushing back against the Cyber Incident Reporting for Critical Infrastructure Act, seeking fewer reporting requirements and less information sharing.
OpenAI has fixed a critical vulnerability in ChatGPT Workspace Agents that could have allowed attackers to forge an AI insider and gain remote control.
FedRAMP 20X replaces narrative-heavy controls with Key Security Indicators, requiring organizations to continuously prove their security posture with machine-readable evidence.
Russian hackers exploit a Zimbra zero-click flaw to steal email data from organizations, using a combination of phishing attacks and the CVE-2025-66376 vulnerability.
Check Point's SmartConsole GUI admin panel has a zero-day flaw, tracked as CVE-2026-16232, allowing unauthenticated attackers to obtain an application login token with administrator privileges.
Vibe-coded apps are found to be riddled with exploitable security flaws, with 434 issues discovered in a recent study, highlighting the need for improved security measures in AI-assisted development.
A new index tracks disclosed material breaches, providing a resource for cybersecurity professionals and citizens to access information on cyber incidents.
A new Windows zero-day exploit, dubbed LegacyHive, allows attackers to escalate privileges on up-to-date Windows systems, granting admin access with additional credentials.
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy systems and a separate claim of a breach at its LabCentral portal.
The Department of War has suspended CMMC Phase 2's mandatory third-party assessment requirement, citing concerns over scalability and compliance costs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch the actively exploited Oracle E-Business Suite flaw by Saturday, July 18.
The security of operational technology (OT) systems is a growing concern, with legacy systems and real-world impacts making it a complex issue to address. OT security issues are distinct from IT security issues, with a greater emphasis on preventing denial of service (DoS) attacks that can have catastrophic consequences.
A flaw in the Claude Chrome extension allows malicious extensions to trigger predefined AI actions, potentially abusing access to connected services like Gmail and Salesforce.
Attackers are exploiting two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall SMA1000 appliances, with the goal of ransomware attacks.
Microsoft releases Windows 10 KB5099539 extended security update, fixing 570 vulnerabilities, including two exploited and one publicly disclosed zero-day flaws.
Researchers at Bitdefender demonstrate three attack techniques using Windows' bind links to evade endpoint detection and response products, highlighting a security problem that relies heavily on paths.
AI-generated code poses significant security risks, with 45% of code produced by AI tools being insecure, according to Veracode's 2025 GenAI Code Security report.
The US Treasury Department sanctioned two individuals and one entity for enabling ransomware attacks against US organizations, causing billions of dollars in losses.
Microsoft releases Windows 11 KB5101650 and KB5099414 cumulative updates to fix security vulnerabilities and add new features.
Microsoft released software updates to fix at least 570 security holes in its Windows operating systems and other software, including 60 critical bugs and three zero-day flaws.
The gap between vulnerability disclosure and exploitation is closing, with new flaws emerging at a rate of one every 7.4 minutes, and AI turning advisories into working exploits in under a day.
The Pentagon suspends CMMC phase 2 requirements pending a 60-day review, citing bureaucratic obstacles and a shortage of approved third-party assessors.
A recent data leak at CISA exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for almost six months before being notified.
The Dutch National Police suspect Dutch hackers were involved in a February breach at telecommunications provider Odido, affecting 6.2 million customers.
CISA strengthens protections after a major credential leak in May, improving vulnerability reporting and incident response plans.
Microsoft expects more Windows security updates as AI accelerates vulnerability discovery, allowing engineers to identify security issues before they can be exploited in zero-day attacks.
Zimbra urges customers to patch a critical stored cross-site scripting flaw in the Classic Web Client, which could allow attackers to steal session data or account settings.
Researchers have discovered a new attack method called 'Ghostcommit' that hides malicious instructions in images to fool AI agents and steal secrets from repositories.
The UK government has announced a new national cyber defense capability, Cyber Shield, which will utilize agentic AI to identify and remediate vulnerabilities and detect breaches.
AI agents are accelerating identity security gaps, with machine identities outnumbering human users by up to 50 to 1, and 43% of organizations experiencing breaches due to inadequate governance.
Six vulnerabilities in U-Boot bootloader could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks.
A former DigitalMint ransomware negotiator has been sentenced to 70 months in jail for deceiving clients and conspiring with ransomware affiliates to extort $75.3 million from five US companies.
The European Commission has filed legal referrals against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law covering critical infrastructure.
Google's Chrome 150 update patches 27 vulnerabilities, including two critical-severity flaws, with most discovered by Google, resulting in lower bug bounty rewards.
The newly established AI cybersecurity clearinghouse must address the gap between fast vulnerability discovery and slow patching to be effective.
BeyondTrust warns of critical flaws in its Remote Support and Privileged Remote Access software, which could allow attackers to bypass authentication and gain unauthorized access.
A class-action lawsuit against xAI and its Grok tool has expanded to include two new plaintiffs who claim the tool was used to create nonconsensual deepfake child sexual assault material.
A class of CI/CD weakness, named Cordyceps, allows attackers to exploit GitHub Actions workflows, even when security scanners report no issues.
Multiple U.S. Army websites were defaced with pro-Kurdish messages and insults to President Donald Trump, in a 404 hijacking campaign discovered by independent cybersecurity researcher Ronald Lovelace.
Attackers are now exploiting the Unified Communications Manager vulnerability patched in early June, with Cisco confirming active exploitation of CVE-2026-20230.
A Canadian hacker has been sentenced to 18 months in prison for a cyberattack on the Texas GOP website, while a researcher has published proof-of-concept code for dozens of zero-day vulnerabilities in open source projects.
Conduct a successful audit of AI-driven software development to identify AI-linked vulnerabilities and ensure protected products, as one in five organizations has experienced a serious security incident directly tied to AI-generated code.
A member of the European Parliament's PEGA Committee was infected with Pegasus spyware twice in 2022 and 2023, highlighting the need for stronger measures to prevent spyware abuses.
The UK's National Cyber Action Plan has been delayed amid the Labour leadership crisis, with its publication initially due on Monday, according to multiple sources.
The Department of Homeland Security is reviving a key cybersecurity information sharing effort with critical infrastructure, over a year after the Trump administration shut down the existing Critical Infrastructure Partnership Advisory Council.
The US government has lifted export controls on Anthropic's advanced cybersecurity AI models, Fable 5 and Mythos 5, after the company reached agreements with the government.
Hackers are exploiting a critical SimpleHelp flaw to deploy Djinn Stealer, a new cross-platform information stealer targeting Windows, macOS, and Linux.
Agentic AI has an identity problem, with attackers taking notice of the lack of proper identity and access management for autonomous digital actors.
Microsoft has quietly extended its free Windows 10 Extended Security Updates program to October 12, 2027, giving users an additional year to upgrade to a newer operating system.
The new MCP 2026-07-28 specification introduces a stateless protocol layer, bringing new security challenges and potential attack surfaces for enterprise-scale deployments.
The Linux Foundation's Akrites project establishes a shared Security Incident Response Team for coordinated discovery, patching, and public disclosure of OSS security defects.
A vulnerability in Lantronix EDS5000 serial-to-IP device servers, tracked as CVE-2025-67038, is being exploited in the wild, allowing attackers to inject arbitrary OS commands with root privileges.
A recent emergency directive from CISA highlights the limitations of patching in preventing cyber attacks, as a vulnerability in Check Point's Remote Access VPN was exploited by a Qilin ransomware affiliate.
Microsoft releases Windows 11 KB5095093 update with new Point-in-Time restore feature, fixing numerous bugs and improving system reliability.
Agentic AI can make bad decisions confidently and quickly if given incomplete or inaccurate context, posing significant security risks.
AIVEX, a new triage model, aims to reduce supply chain threats by providing context to vulnerability remediation priority, addressing the limitations of traditional SBOM, VEX, and CVSS scores.
The US government faces unique difficulties in protecting open-source software, with experts citing years of underinvestment and a lack of systematic vulnerability disclosure processes.
The time between vulnerability disclosure and exploitation has decreased to just 8 hours, making it crucial for organizations to prove exploitability without relying on patches or public exploits.
Two members of the Scattered Spider cybercrime group have pleaded guilty to hacking Transport for London, causing £29 million in financial damage.
The FortiBleed campaign has targeted over 430,000 FortiGate devices worldwide, using custom sniffers to steal credentials and authentication secrets from compromised firewalls.
Hackers are exploiting a medium-severity info disclosure bug in the Gravity SMTP WordPress plugin, affecting 100,000 sites and exposing sensitive information like API keys and credentials.
A new BootROM exploit called Usbliter8 affects millions of iPhones, allowing attackers to bypass Apple's SecureROM and execute arbitrary code with full system privileges.
A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio allows attackers to execute arbitrary commands on a host system by visiting a malicious webpage.
Microsoft attributes a recent Mastra AI supply chain attack to North Korean hacking group Sapphire Sleet, compromising over 140 npm packages.
Klue has confirmed a security incident where threat actors stole OAuth tokens to access customers' Salesforce environments, with the Icarus hackers claiming responsibility for the attack.
Accenture acquires majority stake in Dragos and purchases runZero and NetRise, investing $4.18 billion in industrial cybersecurity.
Apple released a firmware update for Beats Studio Buds, patching a critical vulnerability that allowed nearby attackers to listen via the microphone on unpaired devices.
Most organizations don't treat AI agents as identities, despite their ability to access critical business services and create security risks, with 65% of organizations experiencing a security incident involving an AI agent in the past year.
CISA warns Fortinet users to secure devices after the FortiBleed leak exposed nearly 74,000 firewall and VPN credentials, which have been used by threat actors to target government and private-sector organizations worldwide.
Sen. Mark Warner warns of widespread cuts and staffing gaps at the Cybersecurity and Infrastructure Security Agency, citing a dangerous underestimation of national threats.
F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems.
Klue suffered an OAuth breach, enabling the Icarus threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.
A data leak known as FortiBleed has exposed Fortinet and FortiGate VPN credentials for 73,932 devices worldwide, potentially allowing attackers to access internal networks.
Researchers found dozens of security vulnerabilities in Anthropic's Claude Code, highlighting the challenges of securing AI models with rapid update cycles.
A critical vulnerability in SimpleHelp remote management software, tracked as CVE-2026-48558, allows unauthenticated attackers to create privileged technician accounts on servers using OpenID Connect authentication.
The OptinMonster WordPress plugin was compromised in a supply-chain attack, affecting over 1.2 million websites, with malicious scripts collecting authentication tokens and creating rogue administrator accounts.
Cybersecurity experts disagree with the White House's decision to impose export controls on Anthropic's Fable 5 AI model, citing lack of evidence for unique threats.
Maine's official breach portal was used to publish fake data breach disclosures, including a false claim affecting 2.4 million VRChat users.
Cisco's SD-WAN management software is affected by a seventh actively exploited zero-day vulnerability this year, marked as CVE-2026-20245, allowing authenticated attackers to execute commands as root.
Microsoft released updates to fix nearly 200 security vulnerabilities, including 32 critical bugs, with exploit code publicly available for at least three weaknesses.
AI-driven threats are outpacing traditional security operations, with Gartner predicting a 50% reduction in exploit time by 2027, emphasizing the need for unified, AI-powered security stacks.
A proposal to establish a US Cyber Force as the country's latest military branch was narrowly defeated in the Senate Armed Services Committee with a 14-13 vote.
The Miasma credential-stealing attack framework's source code was briefly leaked on GitHub, potentially leading to increased supply-chain attacks on the open-source ecosystem.
Microsoft released fixes for over 200 security flaws, including one bug under active attack and a 'wormable' flaw in the Windows core.
CISA has ordered federal agencies to prioritize vulnerability patching based on four criteria, aiming to patch smarter and reduce the window for exploitation.
CISA has introduced a new directive requiring federal agencies to patch certain cyber vulnerabilities within three days to address the heightened threat environment posed by AI.
Microsoft warned that some Windows devices upgraded to Windows 11 24H2 or 25H2 may fail to install the latest monthly updates, showing 0x80073712 or 0x800f0993 errors.
Ivanti has patched two critical vulnerabilities in its Sentry solution, including a max-severity flaw that allows remote attackers to execute code with root privileges
Microsoft addressed 206 vulnerabilities in its June 2026 Patch Tuesday update, marking the vendor's largest monthly batch of security patches on record.
The rise of AI models like Anthropic's Claude Mythos threatens to disrupt the bug bounty and in-house offensive security industries, with potential to find thousands of zero-day vulnerabilities.
Researchers found that the OpenClaw AI agent can be tricked by phishing attacks, potentially exposing sensitive user data, including AWS credentials and customer records.
Meta accuses NSO Group of violating a court injunction by continuing to target WhatsApp users with spyware, despite a $168 million damages ruling.
Atsign's AI Architect uses cryptographic invisibility to protect AI-built applications from vulnerabilities and attacks by securing identities and making them invisible to attackers.
CISA plans to transform how it assesses cyber vulnerabilities and risks, prioritizing some over others to be more effective in an environment where risks are spiking.
Claude Mythos Preview can build working exploits targeting known vulnerabilities within hours, increasing threats faced by organizations in the patch gap.
A new Shai-Hulud supply-chain attack has trojanized 19 science-focused PyPI packages, compromising hundreds of thousands of downloads to steal developer secrets.
Vibe coding, a rapid AI-assisted development method, poses significant security risks as 45% of AI-generated code contains OWASP Top 10 vulnerabilities and many applications are deployed without security or authentication.
Over 20,000 Instagram accounts were hijacked after attackers exploited a flaw in Meta's AI-powered support system to reset passwords without two-factor authentication.
A critical bug in UniFi OS allows hackers to gain root access without authentication by chaining three vulnerabilities: CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910.
Over 900 US gas station tank gauge systems are exposed to attacks, vulnerable to security flaws including hardcoded credentials and SQL injection vulnerabilities.
Hackers are actively exploiting a critical vulnerability in the Everest Forms Pro plugin to take complete control of WordPress sites, creating rogue administrator accounts.
Hackers are actively exploiting a high-severity SolarWinds Serv-U flaw, tracked as CVE-2026-28318, to crash servers, with over 12,000 Serv-U servers exposed online.
Toshiba and Muji warned visitors of suspicious sign-in screens on their websites, potentially collecting credentials, after an issue with the external service hosted at polyfill[.]io.
CVE Lite CLI is a free, open-source command line tool that scans projects in seconds to find and fix vulnerable dependencies in JavaScript and Typescript files.
Anthropic's Project Glasswing program has expanded to 150 organizations in 15 countries, discovering over 10,000 high-severity software vulnerabilities since its launch in April.
A public dispute between Microsoft and a security researcher has reignited debate over vulnerability disclosure, with some experts arguing that the company's response was overly aggressive and harmed trust with the research community.
President Trump has signed an executive order for federal vetting of advanced AI models before public release, aiming to balance innovation and security.
Cisco warns of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20245, actively exploited in attacks to gain root privilege escalation.
CISA warns of cyberattacks targeting internet-exposed automatic tank gauge systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors.
AI models are discovering vulnerabilities faster than teams can patch them, leaving organizations caught between speed of discovery and slowness of remediation.
A VS Code zero-day vulnerability allows attackers to steal GitHub authentication tokens by tricking users into clicking a link, with exploit code already released.
A recent study by Adversa AI found that 98% of 100 tested AI agents have a 'lethal trifecta' of private data access, exposure to untrusted content, and ability for outbound actions, making them vulnerable to security risks.
The HTTP/2 Bomb exploit can knock major web servers offline in seconds by combining a compression bomb with a Slowloris-style hold, affecting over 880,000 websites.
A single VPN vulnerability led to data breaches at over 70 financial institutions, highlighting the risks of untested exposure in the banking sector.
A new DoS attack, dubbed HTTP/2 Bomb, can crash web servers in under a minute by exploiting default HTTP/2 configurations, affecting major web servers like NGINX, Apache, and Microsoft IIS.
Microsoft Exchange Online users are experiencing significant delays or failures in sending and receiving emails due to a widespread service issue.
Red Hat removed dozens of packages from its software distribution pipeline after attackers used a compromised GitHub account to distribute credential-stealing malware to developers, affecting 32 packages downloaded roughly 117,000 times a week.
Hackers used Meta's AI support bot to seize control of high-profile Instagram accounts, including those of the Obama White House and the Chief Master Sergeant of the U.S. Space Force.
The National Institute of Standards and Technology's National Vulnerability Database has a backlog of over 27,000 unprocessed security vulnerabilities, undermining its utility and public trust.
New vulnerabilities increased by 67% between 2023 and 2025, with the median time to exploitation dropping to 1.6 days, highlighting the need for immediate vulnerability alerts.
Over 30 Red Hat npm packages were compromised to steal developer credentials in a supply-chain attack distributing the Miasma malware variant.
Attackers are exploiting a critical authentication-bypass vulnerability in Palo Alto Networks firewalls, allowing remote attackers to bypass security restrictions and establish a VPN connection.
Attackers are now exploiting the critical Windows Netlogon vulnerability CVE-2026-41089, allowing remote code execution on targeted domain controllers with a CVSS score of 9.8.
A critical vulnerability in the WP Maps Pro plugin allows hackers to create rogue administrator accounts on WordPress sites without authentication.
Hackers are exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, to breach corporate networks via unauthorized VPN connections.
A newly discovered Linux flaw, dubbed CIFSwitch, allows attackers to gain root privileges on multiple distributions by exploiting a local privilege escalation vulnerability in the Linux kernel.
Hackers are exploiting a FortiClient EMS flaw to deliver an undocumented credential stealer called EKZ, disguised as a Fortinet endpoint update.
Google Chrome's DBSC feature is now available to all users, preventing account takeovers by cryptographically binding session cookies to a specific device.
A critical-severity zero-day vulnerability in Gogs exposes servers to remote code execution, allowing attackers to compromise the server and read every repository on the instance.
Microsoft has condemned the uncoordinated release of Windows zero-day vulnerabilities, calling them 'never justifiable' and warning of potential legal action against those who enable cybercrime.
A Department of Commerce inspector general report found that the National Institute of Standards and Technology's National Vulnerability Database is plagued by poor planning, duplication, and inefficiencies, resulting in a growing backlog of unprocessed security flaws.
Edamame's new platform aims to catch AI coding agents going off the rails by detecting code drift and attack patterns in real-time.
Security researchers discovered a bug chain in Zapier that could have granted access to millions of user accounts and connected systems, but the issues have been fixed.
Enforce strong Active Directory password rules without frustrating users by adopting passphrases, blocking weak and compromised passwords, and rethinking password expirations.
The SymJack attack turns AI coding agents into supply chain attack delivery systems by hijacking symlinks and injecting malicious code.
Anthropic's Mythos model has identified over 10,000 high- or critical-severity software vulnerabilities in its first month of operation, shifting the central problem in cybersecurity from discovery to verification and patching.
The White House has updated rules for federal agencies to keep logs of significant cyber activities, aiming to cut back on red tape and focus on evolving cybersecurity risks.
Apple has open-sourced its quantum-resistant cryptographic code and verification tools to enhance security across the industry.
Microsoft Defender can now automatically isolate hacked endpoints to prevent lateral movement and reduce the risk of further impact.
Drupal warns of exploitation attempts targeting a highly critical SQL injection vulnerability, tracked as CVE-2026-9082, affecting various Drupal versions using PostgreSQL.
A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to inject malicious JavaScript code, impacting over 700 domains.
Anthropic's Claude Mythos model has identified over 23,000 potential vulnerabilities across 1,000 open source software projects, with nearly 3,900 critical and high-severity issues expected to be confirmed.
The Underminr vulnerability allows attackers to hide malicious connections behind trusted domains, potentially affecting 88 million domains worldwide.
Trend Micro warns of an Apex One zero-day vulnerability exploited in attacks targeting Windows systems, with federal agencies ordered to patch by June 4.
Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS, which can be exploited by remote attackers without privileges.
Grafana's codebase and other data were stolen via a TanStack supply chain attack, but no customer production systems or operations were affected.
Attackers are exploiting CVE-2024-9643, an authentication bypass flaw in Four-Faith industrial routers, to compromise devices and fold them into botnets for further campaigns.
CISA has created a new pathway for researchers to report vulnerabilities to its Known Exploited Vulnerabilities catalog, enhancing its ability to identify and share critical threat information.
CISA acting director Nick Andersen warns of the risks posed by open-source vulnerabilities and the need for urgent security improvements to prevent widespread attacks.
Google accidentally leaked details of an unfixed Chromium flaw that allows remote code execution on devices, impacting all Chromium-based browsers.
The UK's proposed cybercrime law reform would offer limited legal protections, leaving most security researchers vulnerable to prosecution.
GitHub's internal repositories were impacted after an employee device was compromised through a poisoned Visual Studio Code extension, with critical secrets rotated and the highest-impact credentials prioritized first.
A reported public exposure of sensitive CISA credential data on GitHub has raised concerns and prompted Congress to demand answers from the agency.
Identity alone is no longer sufficient for cybersecurity, as device security must share the load to prevent attacks, with 44.7% of breaches involving stolen credentials.
Microsoft released Rampart and Clarity, two new AI-powered tools to help developers design more secure software and assist incident responders in the face of ongoing breaches.
Microsoft has shared mitigations for the YellowKey Windows zero-day vulnerability, tracked as CVE-2026-45585, which grants access to protected drives.
Microsoft blames a recent macOS security update for non-dismissible location prompts in the Teams app on some macOS systems, affecting users who have enabled location access in their Teams settings.
Microsoft is introducing the Driver Quality Initiative to improve Windows 11 driver quality, focusing on safer user-mode drivers and better Windows Update catalog hygiene.
A previously unknown vulnerability in Huawei enterprise router software was exploited in a zero-day attack, causing a nationwide telecoms outage in Luxembourg last year.
Microsoft has disrupted a malware-signing-as-a-service operation that abused its Artifact Signing platform to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals.
New AI models like Anthropic's Mythos and OpenAI's Daybreak are generating a flood of vulnerability reports, but many are low-quality submissions without proof of concept.
A new Windows zero-day exploit dubbed 'MiniPlasma' gives attackers SYSTEM access on fully patched Windows systems, with a proof-of-concept released by researcher Chaotic Eclipse.
The Canvas breach exposed 3.65 terabytes of data from 275 million users, highlighting the need for robust SaaS security and identity governance.
Microsoft Edge will no longer load saved passwords into memory on startup, following a security researcher's disclosure of the browser's behavior.
Microsoft and other major software vendors released a record volume of security patches this month, addressing over 1,000 vulnerabilities, with 118 fixes from Microsoft alone.
A max-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller and Manager is being exploited by a persistent threat group, with a CVSS rating of 10 and potential for high-impact operations.
Microsoft rejected a critical Azure vulnerability report, claiming the issue was expected behavior, despite the researcher documenting a silent patch.
Two vulnerabilities in the Avada Builder plugin allow hackers to read arbitrary files and extract sensitive information from the database, potentially leading to site credential theft.
Microsoft Edge stores passwords in process memory, posing a significant risk to enterprise security, especially in shared environments.
TeamPCP hackers are selling nearly 450 Mistral AI code repositories for $25,000 after a supply-chain attack compromised the company's codebase management system.
Microsoft is introducing Cloud-Initiated Driver Recovery, a feature that automatically rolls back faulty Windows drivers delivered through Windows Update.
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages, affecting over 40,000 websites.
A critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, is being exploited in zero-day attacks, allowing attackers to gain administrative privileges on compromised devices.
An 18-year-old flaw in NGINX, tracked as CVE-2026-42945, can be exploited for denial of service and potential remote code execution under certain conditions.
OpenAI is taking actions to protect users after a supply chain attack corrupted the signing keys used to verify the company's applications, with macOS users required to update by June 12.
Hackers are exploiting a critical authentication bypass vulnerability in the Burst Statistics WordPress plugin, tracked as CVE-2026-8181, to gain admin-level access to websites.
OpenAI confirms a security breach in the recent TanStack supply chain attack, which impacted hundreds of npm and PyPI packages, with two employees' devices breached and code-signing certificates rotated as a precaution.
Hackers targeted a PraisonAI vulnerability less than four hours after public disclosure, with exploitation attempts starting within three hours and 44 minutes.
Microsoft and Palo Alto Networks used AI to discover dozens of vulnerabilities in their own code, highlighting the potential of AI in cybersecurity.
A critical vulnerability in Exim mailer, identified as CVE-2026-45185, allows remote code execution on affected Linux and Unix servers.
Sweet Security introduces Agentic AI Red Teaming to counter the 'Mythos Moment' with automated continuous red teaming built on detailed knowledge of each client's infrastructure.
Microsoft has released Windows 11 KB5089549 and KB5087420 cumulative updates to fix security vulnerabilities and add new features, including an Xbox mode on desktop.
The US House Committee on Homeland Security is investigating a massive breach at Instructure's Canvas platform, which impacted millions of students and educators.
Google has launched a feature for Android phones to make it harder for spyware vendors to hide, with a new intrusion logging feature that keeps track of possible intrusions for forensic purposes.
Android 17 will introduce several security and privacy features, including expanded protections against banking scam calls and device theft.
A test of Anthropic's Claude Mythos model found only one low-severity vulnerability in the open source data transfer tool curl, casting doubt on the AI company's claims.
Google has identified a zero-day exploit believed to have been developed using artificial intelligence, designed to bypass two-factor authentication on an open source web-based system administration tool.
Google researchers found a zero-day exploit likely generated using AI, targeting a popular open-source web administration tool to bypass two-factor authentication protection.
Changing passwords doesn't immediately invalidate old credentials across every authentication path in Active Directory and hybrid Entra ID environments, leaving a window for attackers to maintain access.
A rogue version of the CheckMarx Jenkins Application Security Testing plugin was published on the Jenkins Marketplace, containing credential-stealing malware.
A build application firewall may be the solution to prevent supply chain attacks by inspecting each package that enters the build process.
RansomHouse hackers have claimed responsibility for a breach of Trellix's source code repository, leaking screenshots as proof of the intrusion.
Attackers are exploiting a zero-day vulnerability in Ivanti Endpoint Manager Mobile, with limited exploitation reported in the wild, requiring authenticated administrative access to implement.
Modern DLP controls often lack visibility into browser-based data movement, with 46% of sensitive file uploads sent to unsanctioned accounts.
The Trump administration is redirecting the CyberCorps Scholarship For Service program toward artificial intelligence, leaving current scholars uncertain about their future employability
The US government proposes 72-hour patch cycles for critical vulnerabilities, while a new Linux backdoor called PamDOORa is being marketed on a Russian cybercrime forum.
A flaw in the Claude Chrome extension allows any other plugin to hijack victims' AI, potentially extracting files and sending emails on behalf of users.
Ivanti warned customers to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile exploited in zero-day attacks, with over 850 IP addresses exposed online.
ShinyHunters extortion gang breached education technology giant Instructure, defacing Canvas login portals for hundreds of colleges and universities, threatening to leak stolen data if a ransom is not paid by May 12, 2026.
Suspected state-sponsored hackers have been exploiting a critical-severity PAN-OS firewall zero-day vulnerability, tracked as CVE-2026-0300, for nearly a month, allowing unauthenticated attackers to execute arbitrary code with root privileges.
A critical zero-day vulnerability, CVE-2026-0300, is being exploited in the wild, affecting some Palo Alto Networks' customers' firewalls, allowing unauthenticated attackers to run code with root privileges.
Palo Alto Networks warns of a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal, tracked as CVE-2026-0300, which is being exploited in attacks.
A defense technology company exposed user records and military training materials through API endpoints lacking authorization checks, affecting hundreds of user records and sensitive course information.
DAEMON Tools devs confirm breach, release malware-free version after supply chain attack trojanized software, impacting thousands of systems worldwide.
Australia has launched a Cyber Incident Review Board to conduct independent reviews of major cyberattacks, focusing on systemic lessons rather than individual culpability.
Approximately 5.4 million end-of-life package versions are not being checked by security tools, leaving organizations vulnerable to exploits.
Joey Melo, a Principal Security Researcher at CrowdStrike, discusses his approach to hacking AI systems, focusing on controlling the experience without changing the rules.
Attackers are actively exploiting a Linux vulnerability, dubbed 'Copy Fail', which allows for total control of a system with authenticated local access, affecting mainstream Linux kernels built since 2017.
Microsoft Defender has incorrectly identified legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, leading to false-positive alerts and removal of certificates from Windows systems.
Microsoft confirms that the April 2026 security updates cause failures in third-party backup applications using the psmounterex.sys driver due to a VSS service timeout.
Anthropic's AI model Mythos discovered thousands of unknown software vulnerabilities, highlighting the risk of AI agents exploiting security flaws and impersonating humans.
A Brazilian tech firm specializing in DDoS protection has been linked to a botnet responsible for massive DDoS attacks against Brazilian ISPs, with evidence suggesting a security breach and potential competitor involvement.
A severe authentication bypass vulnerability in cPanel, tracked as CVE-2026-41940, is being actively exploited in the wild, affecting over 1.5 million instances.
Microsoft has released the KB5083631 optional cumulative update for Windows 11, including 34 changes and fixes, such as a new Xbox mode and improved security for batch files.
ConsentFix v3 attacks automate OAuth abuse against Microsoft Azure, using social engineering and phishing to obtain tokens and hijack accounts despite multi-factor authentication.
Cisco has released an open source tool, Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models.
Microsoft has fixed a bug causing Remote Desktop security warnings to display incorrectly on devices with multiple monitors and different display scaling settings.
CISA has issued separate advisories for vulnerabilities in Zero Motorcycles electric bikes and Yadea T5 scooters that could allow attackers to upload malicious firmware or steal vehicles outright.
CrowdStrike has addressed a critical unauthenticated path traversal bug in its LogScale product, while Tenable patched a high-severity flaw in its Nessus scanner that could allow arbitrary file deletion and code execution with System privileges.
Over 10,500 Zimbra Collaboration Suite servers exposed to the internet are still unpatched against CVE-2025-48700, an actively exploited cross-site scripting flaw. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.
A newly disclosed vulnerability tracked as CVE-2026-41651, dubbed 'Pack2TheRoot,' allows local Linux users to gain root privileges through the PackageKit daemon. The high-severity flaw has existed for nearly 12 years and affects numerous popular distributions.
Microsoft is rolling out phishing-resistant passkey support for Entra-protected resources on Windows devices beginning late April, with general availability expected by mid-June 2026.
Attackers are actively exploiting CVE-2026-3844, a critical 9.8-severity vulnerability in the Breeze Cache WordPress plugin, enabling unauthenticated file uploads and potential remote code execution across hundreds of thousands of sites.
Apple pushed out-of-band security updates on April 22, 2026, to address CVE-2026-28950, a Notification Services bug that allowed deleted notifications to persist on iPhone and iPad devices.
More than 1,300 Microsoft SharePoint servers remain unpatched against CVE-2026-32201, a spoofing vulnerability that was exploited as a zero-day before patches arrived and continues to be abused in ongoing attacks.
CISA expanded its Known Exploited Vulnerabilities catalog by eight flaws on Monday, including three newly flagged issues in Cisco Catalyst SD-WAN Manager, Kentico Xperience, and Zimbra Collaboration Suite.
Pillar Security researchers discovered a vulnerability in Google's Antigravity AI developer tool that combined prompt injection with file-creation capabilities to bypass secure mode and grant attackers remote code execution.
Forescout Technologies has uncovered 20 new vulnerabilities in serial device servers from Silex and Lantronix, collectively dubbed BRIDGE:BREAK, enabling remote code execution, firmware tampering, and device takeovers in critical OT and healthcare environments.
Threat actors have spent over a year attempting to exploit CVE-2023-33538, a high-severity command injection flaw in discontinued TP-Link routers, but errors in their own exploit code have prevented any successful compromise, according to Palo Alto Networks.
Threat actors are actively exploiting three leaked Windows privilege escalation vulnerabilities in the wild, with only one patched so far. Huntress Labs confirmed all three exploits deployed in real attacks as of mid-April 2026.
A chained attack dubbed NomShub could allow adversaries to silently hijack developer machines through malicious repositories opened in Cursor AI, requiring no user interaction beyond a single click.
NIST has announced it will stop assigning severity scores and additional details to lower-priority vulnerabilities in the National Vulnerability Database, citing a 263% surge in submission volumes it can no longer keep pace with.
CISA has added CVE-2026-34197, a high-severity Apache ActiveMQ vulnerability discovered after 13 years, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by April 30.
A critical Apache ActiveMQ Classic flaw tracked as CVE-2026-34197, dormant in the codebase for 13 years, is being actively exploited just weeks after patched versions were released. CISA has added it to the Known Exploited Vulnerabilities catalog with a federal patch deadline of April 30.
A code regression introduced by a recent Microsoft Edge update has left Teams desktop users unable to paste content via right-click context menus. Microsoft is rolling out a staged fix while recommending keyboard shortcuts as a workaround.
A critical remote code execution flaw tracked as GHSA-xq3m-2v4x-88gg has been discovered in protobuf.js, a JavaScript library pulling nearly 50 million weekly npm downloads. Proof-of-concept exploit code is now public, though no active in-the-wild attacks have been observed.
Microsoft has confirmed that installing the April 2026 security update KB5082063 can cause LSASS crashes and endless restart loops on non-Global Catalog domain controllers in environments using Privileged Access Management.
A researcher calling themselves 'Chaotic Eclipse' has released a proof-of-concept exploit for a second Microsoft Defender zero-day dubbed 'RedSun,' which grants SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
Splunk has released security fixes addressing a high-severity remote code execution vulnerability tracked as CVE-2026-20204 in Splunk Enterprise and Cloud Platform, along with several other flaws across its product lineup.
Microsoft is investigating why this month's KB5082063 security update is failing to install on certain Windows Server 2025 systems, with affected machines reporting error code 0x800F0983.
NIST has announced it will only enrich CVE records that meet specific priority criteria, abandoning its longstanding goal of processing every submitted vulnerability as submission volumes grow exponentially.
Overwhelmed by a growing flood of vulnerabilities, NIST has announced it will limit in-depth CVE analysis to those in CISA's known exploited vulnerabilities catalog, federal government software, and critical software under Executive Order 14028.
A critical unauthenticated vulnerability in Nginx UI's Model Context Protocol endpoint is being actively exploited in the wild, enabling attackers to fully take over web servers without credentials. Over 2,600 publicly exposed instances remain potentially vulnerable.
CISA has added CVE-2025-60710, a Windows Task Host privilege escalation vulnerability patched by Microsoft in November 2025, to its actively exploited vulnerabilities catalog, giving federal agencies two weeks to patch.
Microsoft has confirmed that installing the April 2026 KB5082063 security update can push certain Windows Server 2025 machines into BitLocker recovery mode on first reboot, affecting systems with specific Group Policy configurations.
Siemens, Schneider Electric, Aveva, Rockwell Automation, ABB, Phoenix Contact, Mitsubishi Electric, and Moxa have all published new ICS security advisories, addressing vulnerabilities ranging from critical Wi-Fi flaws to privilege escalation and denial-of-service issues.
Microsoft's April 2026 Patch Tuesday addresses 167 security vulnerabilities, including an actively exploited SharePoint Server zero-day and the publicly disclosed BlueHammer flaw in Windows Defender. Google Chrome and Adobe Reader also received urgent security fixes this cycle.
Microsoft's April 2026 cumulative updates for Windows 10 and Windows 11 introduce new safeguards against phishing attacks that weaponize Remote Desktop Protocol (.rdp) files, including security warnings and disabled resource redirections by default.
Google has embedded a Rust-based DNS parser into the modem firmware of Pixel phones, starting with the Pixel 10 series, to eliminate an entire class of memory-safety vulnerabilities in a critical and remotely accessible attack surface.
SAP released 20 security notes on its April 2026 patch day, led by CVE-2026-27681, a critical 9.9-rated SQL injection vulnerability in Business Planning and Consolidation and Business Warehouse that enables arbitrary code execution.
A critical cryptographic validation bug in the widely deployed wolfSSL library allows improperly weak digests to be accepted during certificate verification, potentially letting attackers impersonate malicious servers. The flaw was patched in wolfSSL 5.9.1 on April 8, 2026.
OpenAI is rotating its macOS code-signing certificates after a compromised Axios npm package (version 1.14.1) was executed within a GitHub Actions workflow on March 31, 2026, potentially exposing credentials used to sign ChatGPT Desktop and other apps.
Adobe has pushed an out-of-band security update for Acrobat and Reader to address CVE-2026-34621, a zero-day vulnerability exploited in the wild since at least December that allows malicious PDFs to escape sandbox protections and execute arbitrary code.
A critical pre-authentication remote code execution vulnerability in the Marimo Python notebook platform was actively exploited within 10 hours of public disclosure, with attackers targeting cloud credentials and SSH keys.
Adobe has released out-of-band patches for a critical zero-day vulnerability in Acrobat and Reader, tracked as CVE-2026-34621 with a CVSS score of 9.6, which attackers have been exploiting since at least November 2025.
Fortinet has released an emergency hotfix for CVE-2026-35616, a critical 9.1-scored authentication bypass flaw in FortiClient EMS that is already being exploited in the wild. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies patch by April 9.
A cluster of software supply chain incidents — including Anthropic's accidental publication of over 500,000 lines of Claude Code source, plus attacks on Trivy, Axios, and KICS — reveal systemic failures in how development pipelines are secured.
Microsoft addressed 77 security vulnerabilities this Patch Tuesday, with no active zero-days but notable fixes including privilege escalation bugs, critical Office RCE flaws, and a first-of-its-kind CVE discovered by an autonomous AI penetration testing agent.
Palo Alto Networks researchers demonstrated how attackers can exploit excessive default permissions in Google Cloud's Vertex AI to steal credentials, exfiltrate sensitive data, and access restricted internal infrastructure.
Apple has broken with its usual patching practice by extending fixes for the DarkSword exploit chain to iOS 18 users who have not upgraded to iOS 26, following the tool's leak on GitHub on March 22.
Security vendor Noma disclosed 'GrafanaGhost,' an indirect prompt injection vulnerability in Grafana's AI assistant that could silently exfiltrate user data. Grafana has since patched the underlying image renderer flaw.
Chainguard has launched Factory 2.0, a rebuilt platform that uses agentic reconciliation bots and a controller/reconciler model to continuously harden open source artifacts across containers, libraries, GitHub Actions, and AI agent skills.
HackerOne suspended new vulnerability submissions to its Internet Bug Bounty program on March 27, citing a deepening imbalance between AI-accelerated bug discovery and the capacity of open source maintainers to fix reported flaws.
Anthropic unveiled Claude Mythos Preview on April 7, an LLM capable of finding and exploiting zero-days across major operating systems and browsers. The company's Project Glasswing initiative aims to keep the powerful model in defensive hands, but experts remain skeptical.
A researcher using the alias 'Chaotic Eclipse' publicly released a proof-of-concept exploit for an unpatched Windows zero-day called BlueHammer, citing frustration with Microsoft's Security Response Center. Security experts warn ransomware gangs and APT groups could weaponize the exploit within days.
Anthropic has launched Project Glasswing alongside Amazon, Apple, Microsoft, and others, deploying an unreleased AI model that has already uncovered thousands of previously unknown vulnerabilities—including bugs decades old.
A sophisticated zero-day vulnerability in Adobe Reader has been actively exploited since at least December, using maliciously crafted PDF files to steal data and potentially enable full system compromise.
Researchers from RSAC combined two adversarial techniques to circumvent Apple Intelligence's input and output filters, achieving a 76% success rate across 100 test prompts. Apple has since rolled out fixes in iOS 26.4 and macOS 26.4.
Researchers at Comparitech discovered 179 industrial control devices accessible without authentication via the Modbus protocol, as the US government warns of state-sponsored attacks targeting programmable logic controllers in critical infrastructure.
Microsoft researchers discovered a critical intent-redirection vulnerability in EngageLab's EngageSDK, a third-party Android SDK embedded in cryptocurrency wallet apps with over 30 million combined installs.
Google has launched Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, cryptographically tying authentication sessions to a user's device so that stolen cookies become worthless to attackers.
A threat actor crafted a working exploit for a critical unauthenticated remote code execution vulnerability in the Python notebook platform Marimo just 9 hours and 41 minutes after its public disclosure, according to cloud security firm Sysdig.
Researchers at Machine Spirits uncovered nine vulnerabilities in the open source Orthanc DICOM server, tracked CVE-2026-5437 through CVE-2026-5445, enabling attackers to crash servers, leak sensitive data, and potentially execute arbitrary code remotely.
Juniper Networks has issued fixes for close to three dozen vulnerabilities across Junos OS and related products, including a critical 9.8-severity default password flaw that could hand attackers full control of affected devices.
Google has shipped Chrome 147 with fixes for 60 security vulnerabilities, including two critical heap and integer overflow bugs in the WebML component that together earned anonymous researchers $86,000.
A critical privilege escalation flaw in the Linux kernel affects all major distributions. With active exploitation confirmed, administrators should prioritize patching immediately.
Google has released an emergency patch for a high-severity V8 type confusion vulnerability actively exploited in targeted attacks. All Chromium-based browsers are affected.
A critical SQL injection vulnerability discovered in a widely used WordPress plugin has put millions of websites at risk. Exploitation has been observed in the wild, and site administrators should take immediate action to patch or mitigate.