AI + skilled malware developers = security threat VoidLink, the newly spotted Linux malware that targets victims' clouds with 37 evil plugins, was generated "almost entirely by artificial...
The Problem: The Identities Left Behind As organizations grow and evolve, employees, contractors, services, and systems come and go - but their accounts often remain. These abandoned or “orphan”...
We've identified an aspect of Azure’s Private Endpoint architecture that could expose Azure resources to denial of service (DoS) attacks. The post DNS OverDoS: Are Private Endpoints Too Private?...
Introducing new-era DLP with an eye for secure visibility
Cybersecurity researchers have disclosed details of a malware campaign that's targeting software developers with a new information stealer called Evelyn Stealer by weaponizing the Microsoft Visual...
Oracle addresses 158 CVEs in its first quarterly update of 2026 with 337 patches, including 27 critical updates.Key takeaways:The first Critical Patch Update (CPU) for 2026, contains fixes for 158...
Cloudflare has addressed a security vulnerability impacting its Automatic Certificate Management Environment (ACME) validation logic that made it possible to bypass security controls and access...
Leaked API keys are no longer unusual, nor are the breaches that follow. So why are sensitive tokens still being so easily exposed? To find out, Intruder’s research team looked at what traditional...
Senior researcher Noura Aljizawi speaks with Nalah Ayed from CBC Ideas about her personal experience of returning to Syria to grieve for the first time in 13 years following the fall of the...
Tenable Research has discovered a server-side request forgery (SSRF) vulnerability in Java’s handling of client certificates during a TLS handshake. In certain configurations, this can be abused...
Picture this: You’re a utility executive. It’s August 2029. A heat wave grips 10% of the country, and your regional transmission organization is red-lining. Community concerns around rolling...
The United States’ attack on Venezuela has raised questions about domestic checks on power and signaled a challenge to international law and longstanding norms of sovereignty and the use of force....
Transport Canberra has launched a new investigation into its fleet of Chinese-made electric buses amid growing cybersecurity concerns. British media have reported that the UK’s National Cyber...
Uptake by European Union member countries of a measure intended to beef up continental cybersecurity has hardly been enthusiastic. 15 months after EU nation-states were supposed to have...
The Department of Homeland Security would need to follow stricter guidelines when using mobile biometric applications under legislation introduced Thursday by the ranking member of the...
The Wiz JetBrains IDE plugin is now generally available, enabling developers to fix risks before code leaves their local environment.
Update Chainlit to the latest version ASAP Two "easy-to-exploit" vulnerabilities in the popular open-source AI framework Chainlit put major enterprises' cloud environments at risk of leaking data...
LLM cybersecurity benchmarks fail to measure what defenders need: faster detection, reduced containment time, and better decisions under pressure.
FortiGuard Labs analysis of a multi-stage Windows malware campaign that abuses trusted platforms to disable defenses, deploy RATs, and deliver ransomware.
A strange charge appears on a bank account. An email claims a package is on the way. A social media account stops accepting a password that worked yesterday. When these moments hit, many people do...
AI poses substantial threats and opportunities for democracy in an important year ahead for global democracy. Despite the threats, AI technologies can also improve representative politics, citizen...
Global LLM use is growing rapidly; site visits to major LLM platforms increased threefold from April 2024 to August 2025, rising from an estimated 2.4 billion to nearly 8.2 billion monthly visits....
The UK’s National Cyber Security Centre (NCSC) is once again warning that pro-Russia hacktivists are a threat to critical services operators. The cyber arm of the UK’s sigint specialists at GCHQ...
Cyberattacks cost the global economy over £7 trillion a year — more than double the UK’s gross domestic product. The annual hit to the country alone is £27 billion. But one prediction that can be...
A Telegram-based guarantee marketplace known for advertising a broad range of illicit services appears to be winding down its operations, according to new findings from Elliptic. The blockchain...
Prompt injection for the win Anthropic has fixed three bugs in its official Git MCP server that researchers say can be chained with other MCP tools to remotely execute malicious code or overwrite...
Group-IB says crims forking out for Dark LLMs, deepfakes, and more at subscription prices Cybercrime has entered its AI era, with criminals now using weaponized language models and deepfakes as...
Eighteen months ago, it was plausible that artificial intelligence might take a different path than social media. Back then, AI’s development hadn’t consolidated under a small number of big tech...
Once again, data shows an uncomfortable truth: the habit of choosing eminently hackable passwords is alive and well
Key Points Introduction When we first encountered VoidLink, we were struck by its level of maturity, high functionality, efficient architecture, and flexible, dynamic operating model. Employing...