A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
Global Security News
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
Global Security News
Mamdani Targets ‘Greedy Algorithm’ of Corporations in a New Brand of Politics
Politicians on the left and right are watching how the New York mayor’s tactics play out in world’s center of capitalism.
Global Security News
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available. BIG-IP APM is a software component in F5’s BIG-IP hardware platform that…
Global Security News
Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
HealthTech apps need secure architecture, encrypted data, strong access controls, continuous testing, and post-launch monitoring to protect patient information.
Global Security News
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. […]
Global Security News
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found. The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security…
Global Security News
How device code phishing gives scammers access to your account
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts. The message claims the code will let you open the document or join the meeting. In fact, it approves…
Global Security News
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. […]
Global Security News
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated…
Global Security News
Pentagon cyber chief: The demand far exceeds supply
The Pentagon’s top civilian cyber policy official said Tuesday her single priority is expanding the cyber options available to the president and the defense secretary, describing a gap between what commanders are asking for and what the force can deliver. “I’m focused on one single priority, and that is building a more robust set of…
Global Security News
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below – gocommunity-io/dockerd (222 downloads) kreuzwenker/
Global Security News
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
Global Security News
Ryuk ransomware operator sentenced to 2 years in prison
A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday. Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and…
Global Security News
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a…
Global Security News
DoorDash Spent $1.4 Million Trying to Stop Mamdani From Becoming Mayor. Now We Know Why.
Last year, well before DoorDash’s $131.5 million settlement with New York City for underpaying 264,000 delivery workers was announced Tuesday, the company spent around $1.4 million on the campaign to stop Zohran Mamdani, who oversaw the historic settlement, from becoming mayor. At the time, DoorDash’s campaign contributions in the run-up to the 2025 mayoral election…
Global Security News
Lenovo Expands Virtualization Portfolio for AI-Ready IT
Lenovo is expanding its virtualization portfolio with new infrastructure, deployment services, and validated solutions designed to give enterprises more flexibility as they modernize legacy environments and prepare for AI workloads. The additions include the ThinkAgile VX850 V4, expanded Infrastructure Deployment Services, and new Express Solutions spanning Microsoft, Red Hat, Nutanix, and SUSE technologies. For channel…
Global Security News
Fastly Launches AI Runtime Controls for Enterprise Agents
Fastly is expanding its edge platform with three AI-focused security and governance capabilities designed to give enterprises — and the MSPs and MSSPs supporting them — more control over how AI models, applications and autonomous agents interact with enterprise infrastructure. The new AI Runtime Control, AI Firewall and API Security capabilities are intended to apply…
Global Security News
Facing Congressional Scrutiny, Flock Details New Search Guardrails
The company says it cut its default data-retention period to seven days from 30, added standardized search categories and will require case numbers.
Global Security News
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. […]
Global Security News
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
Global Security News
Anthropic Leaders Back Startup Developing System to Detect Biological Threats
Pilgrim has raised $25 million and has developed a 50-pound device that detects biological threats.
Global Security News
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
Global Security News
Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
MSSP Tier 1 analysts can cut phishing triage time with interactive analysis, fresh threat intelligence, clearer evidence and complete Tier 2 handoffs worldwide.
Global Security News
CVE-2026-87902: Critical WordPress Core Flaw Enables Unauthenticated RCE Under Certain Conditions
WordPress has released an emergency security update addressing a critical vulnerability in its Core software that can allow an unauthenticated attacker to load arbitrary local PHP files and, under specific server and theme conditions, achieve remote code execution. Tracked as CVE-2026-87902, the vulnerability affects WordPress releases from version 4.7.0 through 7.1.1 and carries a CVSS…
Global Security News
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe Bridge is a creative asset manager that lets you preview, organize, edit, and publish multiple creative assets quickly and easily. Adobe Connect is a secure, highly customizable web conferencing and virtual training platform used for…
Global Security News
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks. The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s…
Global Security News
CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Exploited for Remote Code Execution
F5 has disclosed a critical zero-day vulnerability affecting BIG-IP Access Policy Manager (APM) that is already being exploited in the wild. Tracked as CVE-2026-94127, the flaw can allow an unauthenticated remote attacker to execute arbitrary code on vulnerable BIG-IP systems by sending specially crafted traffic to an affected OAuth configuration. The vulnerability is a heap-based…
Global Security News
CVE-2026-93616: Check Point Management Server Zero-Day Exploited in Targeted Attacks
Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management infrastructure after confirming exploitation in targeted attacks. Tracked as CVE-2026-93616 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated attacker with network access to the vulnerable management service to upload and execute arbitrary scripts. The vulnerability…
Global Security News
GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these applications use to authenticate themselves can remain valid for years unless manually revoked. If leaked, those keys can potentially give attackers administrative control over an organization’s…
Global Security News
From admin to architect: Jamf’s vision for the autonomous Apple enterprise
Now a private company, Jamf opened its big annual event for Apple enterprise management teams, JNUC, by taking big steps to exploit artificial intelligence in the management of Apple fleets. During her keynote speech at the Kansas City event, CEO Beth Tschida shared some of the details of the platform-scale overhaul the company has set…
Global Security News
How to fix your Windows File History if the September update broke it
A bug in the Windows Sept patch Tuesday update may stop File History from working. But a new optional update fixes it.
Global Security News
AI Has Cracked the Most Diabolical Problems in Math. Why Can’t It Solve Chess?
Chess engines can beat grandmasters—but they can’t agree on a single infallible strategy. And, instead of ruining the game, artificial intelligence is now uncovering new ways of playing.
Global Security News
Hundreds of Leaked GitHub App Keys Still Authenticate
GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access
Global Security News
Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and…
Global Security News
InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. […]
Global Security News
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker’s server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and…
Global Security News
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud.
Global Security News
Cofense measures employee readiness against real-world phishing threats
Cofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving security teams evidence of program effectiveness rather than training completion. This measurement advances Secure Behavior Management (SBM), an…
Global Security News
How One Kubernetes YAML Can Hand Over a GCP Organization
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. […]
Global Security News
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Global Security News
80,000 relay servers help users in China slip past U.S. AI region bans
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and illicit activity,” said Scott Fisher, Senior Principal Engineer at Team Cymru. Earlier this…
Global Security News
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead…
Global Security News
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below – @memtensor/memos-cloud-openclaw-plugin versions
Global Security News
Portnox detects and removes unauthorized AI applications from managed devices
Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability addresses shadow AI: generative AI applications that increasingly act as autonomous agents, reaching local files, remote resources, and enterprise data with…
Global Security News
Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials and other information exposed in data breaches can circulate across dark web marketplaces, forums and other sources. For…
Global Security News
Finnish AI Cloud Startup Verda Raises $189M, Tops $1B Valuation
Finnish AI infrastructure startup Verda has raised $189 million in an oversubscribed Series B round, pushing its valuation above $1 billion as it expands GPU capacity across Europe. Emergence Capital led the round, joined by Supermicro, MUFG Innovation Partners, Varma, Lifeline Ventures, 6 Degrees Capital, byFounders, Tesi, and several angel investors. The financing brings Verda’s…
Global Security News
Okta Expands AI Agent Security and Governance
Okta is expanding its identity security controls for AI agents, adding new capabilities for agent discovery, access governance, runtime enforcement, and rapid response as enterprises deploy more autonomous AI across their environments. The new capabilities build on Okta’s blueprint for the secure agentic enterprise, introduced in March 2026, and are designed to answer four increasingly…
Global Security News
DarkMe RAT trades zero-days for plain phishing emails
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on…
Global Security News
Barracuda brings AI security and governance within reach of smaller organizations
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance. Barracuda AI Data Security represents a major milestone in Barracuda’s expanding AI Security…
Global Security News
Lookout targets smishing, voice cloning, and vishing with real-time mobile protection
Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques. Frontier AI is transforming social engineering by enabling attackers to create highly…
Global Security News
Fake Claude Max giveaway tricks users into handing over their Google account credentials
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users. “Phishing…
Global Security News
Nearly 70% of workers use AI regularly now – but many get no time to upskill
ZDNET Exclusive: A new Workera report shows businesses and employees aren’t on the same page about AI upskilling. Here’s what organizations need to know.
Global Security News
KDDI, Exaforce Expand Agentic SOC Services in US, EMEA
KDDI America and KDDI Europe are adding Exaforce’s agentic SOC platform to their managed security portfolios, giving the cybersecurity vendor a new route to multinational enterprises across the US and EMEA. Under separate partnership agreements, the two KDDI subsidiaries will market and sell the Exaforce Agentic SOC Platform directly to enterprise customers while also incorporating…
Global Security News
Introducing the Agentic Skills Marketplace: Curated AI Capabilities for the Modern SOC
For years, SOC Prime has focused on one core problem: curating behavioral detection rules that cover both the threats that never go away and the new ones that emerge every day. As agentic AI changes how security teams work, we see the same opportunity opening up in a new area — and we’re expanding our…
Global Security News
Fake Claude Max giveaway hides a Google account phishing trap
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and…
Global Security News
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. […]
Global Security News
Why AI is Leaving Many Employees More Overworked and Less Productive
Plus, Meta’s Muse app sparks fears of financial-sector disruption
Global Security News
The president has called for AI leadership. Here’s the mission.
America leads the world in artificial intelligence. As it should. But tech leaders keep warning, with alarming frequency, that we are at risk of losing control. President Donald Trump has called for an AI czar and an “AI Force.” The details remain unclear, but the announcement underscores something fundamental. A technology this consequential demands clear…
Global Security News
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other…
Global Security News
Exabeam APEX Partner Program Exceeds H1 Pipeline Target
Exabeam’s channel-driven new-logo pipeline exceeded its first-half 2026 global target by 138%, giving the cybersecurity vendor an early measure of momentum one year after launching its APEX Partner Program. The company also reported expansion bookings at 125% of plan as it continues to build around a channel-first growth strategy. The results come alongside year-over-year gains…
Global Security News
ShinyHunters claims FBI breach was revenge for “false” report
Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group. In a very long post on its leak site,…
Global Security News
Ransomware Attacks Reach Record High for 2026
A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data
Global Security News
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security…
Global Security News
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a “major step up from Opus 5,” and “achieves the best scores of any model to date on our automated behavioral audit,…
Global Security News
Microsoft: September Windows updates break Always On VPN connections
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. […]
Global Security News
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel’s AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04…
Global Security News
EvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold…
Global Security News
ServiceNow vs. Salesforce for IT Partners: Key Differences
ServiceNow and Salesforce are moving deeper into each other’s territory as AI agents, automation, low-code development, and customer service reshape the enterprise software market. For IT partners, that growing overlap creates a more complicated opportunity. Choosing where to build expertise is no longer simply a question of IT workflows versus CRM; it increasingly depends on…
Global Security News
Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer
The network’s job has always been simple: watch the traffic. Authority stopped there. Related: AI agents have a Lord Of The Flies problem For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, each with a fixed address. An AI agent isn’t physical, and it has no fixed…
Global Security News
Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies
According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In…
Global Security News
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026,…
Global Security News
GPT-6 Sol and Luna arrive with 50% lower API prices
OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API users can access them as…
Global Security News
AI Biotech Enveda Doubles in Value to $2 Billion
Backed by a former J&J CEO, the startup plans to advance its drug candidates into late-stage trials.
Global Security News
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees
Global Security News
Hello, Googlebook: The complete FAQ on Google’s Android-ChromeOS combo
Googlebook, Googlebook, Googlebook. Google’s mysterious new Android- and ChromeOS-combining laptops have been the talk of the town here in the land o’ Googley matters for much of this year already — and their name also makes for an incredibly challenging tongue-twister to say, as an added layer of intrigue. (Seriously: Try saying it 10 times…
Global Security News
Gadgets Are Going Premium—and Manufacturers Are Raking It In
Higher prices and lower volumes appear here to stay, shaking up the device industry.
Global Security News
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server.…
Global Security News
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation…
Global Security News
Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Built for long and complex tasks Opus 5.5 is designed for codebase migrations, software…
Global Security News
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents
Global Security News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has…
Global Security News
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
Global Security News
Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth…
Global Security News
Okta bets on identity to control AI agents, but is identity enough?
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary control plane for securing AI,” said Okta CEO and co-founder Todd McKinnon in an earnings call in late August, telling investment analysts that…
Global Security News
Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. […]
Global Security News
CVE-2026-87902: how close is your WordPress to remote code execution?
WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), which stems of how the CMS resolves page templates, with a real path to remote code execution.…
Global Security News
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. […]
Global Security News
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed…
Global Security News
Prismor: Open-source runtime control plane for AI agents
Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block.…
Global Security News
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI…
Global Security News
Weekly Update 522: Live From Oslo with Scott Helme
Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving – sorry! But get through that and have a listen to Scott’s experiences with how Report URI is identifying malware-infected machines within orgs, all due to CSP reporting. It’s a super cool use of the technology,…
Global Security News
Product showcase: Scamwise checks the red flags before you take the bait
Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with no account required. Scamwise is included in the Savi app for iOS and Android, which is currently available…
Global Security News
Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management
New Competency Dashboard in Cofense Command Center measures organizational readiness against phishing and connects employee behavior with real-world threat signals News highlights Cofense Command Center, the orchestration layer for measurement and reporting across the Cofense Platform, brings more of the phishing defense lifecycle into a single view beginning with how employees recognize, report and respond to…
Global Security News
Nearly two-thirds of tested websites fail every bot test
Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. Bot traffic grows nine times faster than human traffic The company…
Global Security News
Rabbit’s new OS lives in the cloud and borrows your laptop to get things done
Rabbit, the Santa Monica company that makes the r1 handheld, released OS3, an agentic operating system. It runs in Rabbit’s cloud and operates a user’s computers through a local agent that installs with one command. The user states a goal in a chat, and OS3 picks the device, then works desktop software, local files and…
Global Security News
Agentic Security Starts With Data that Machines Can Trust
The age of artificial intelligence has brought an end to the security operating model that served organisations for much of the past decade.
Global Security News
NetBSD 10.2 security fixes close a remote kernel bug in ipfilter
A NetBSD box at the edge of a network, filtering traffic with ipfilter, has been carrying a kernel flaw that someone outside the machine can set off. The bug is a remotely triggerable null pointer dereference in ipfilter, meaning the kernel tries to read memory through a pointer that leads nowhere. In kernel code, that…
Global Security News
A Vulnerability in F5 BIG-IP Access Policy Manager Could Allow for Remote Code Execution
A vulnerability has been discovered in F5 BIG-IP Access Policy Manager (APM) that could allow for remote code execution. BIG-IP APM is a widely deployed network access and identity management solution used across government agencies, financial institutions, healthcare organizations, and large enterprises to control application and network access. Successful exploitation of this vulnerability could result…
Global Security News
ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
