Skip to content
Security feed

Cybersecurity news & advisories

Aggregated advisories, threat intel, and news from 21+ trusted sources — updated every 4 hours. Subscribe via RSS ↗

21 / 21 active
Advisory
Threat Intel
Research
News
Media
Podcast
431 articles Updated 19 Jul 2026 20:15 UTC
News Cyber Security News

Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories

Vuln Breach

This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed…

↗ Open article
Research SANS Internet Storm Center

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

Vuln

We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our…

↗ Open article
News The Hacker News

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Malware APT

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer…

↗ Open article
News The Hacker News

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Vuln APT

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June…

↗ Open article
News Cyber Security News

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

Malware Research

A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a…

↗ Open article
News Cyber Security News

Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI

Breach

Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic…

↗ Open article
News Cyber Security News

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

Ransom Breach

A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network…

↗ Open article
News Cyber Security News

Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

Vuln

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain…

↗ Open article
News Cyber Security News

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

Vuln

A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated…

↗ Open article
Research Rapid7 Blog

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 ↗ Vuln

Overview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . While the official GitHub security…

↗ Open article ↗ CVE feed
News The Hacker News

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Research

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of…

↗ Open article
News The Hacker News

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the…

↗ Open article
Research Rapid7 Blog

Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements

Metasploit Wrap Up Housekeeping While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The…

↗ Open article
News The Hacker News

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Malware Research Crypto

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed…

↗ Open article
News Cyber Security News

OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

Vuln DoS

A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the…

↗ Open article
Research Rapid7 Blog

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

CVE-2026-58644 ↗ Vuln

Overview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The…

↗ Open article ↗ CVE feed
News Cyber Security News

Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States

Ransom

Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing…

↗ Open article
News Cyber Security News

EY Data Breach – Hackers Gain Access to IT Support System and Download Documents

Breach

Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window…

↗ Open article
News The Hacker News

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

Malware

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n…

↗ Open article
News Cyber Security News

PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools

A new open-source tool is bringing autonomous AI agents into offensive security workflows. PentestCode, a hard fork of OpenCode rebuilt specifically for penetration testing , runs security tools, analyzes their output…

↗ Open article
News The Hacker News

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Breach APT Research

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor…

↗ Open article
News The Hacker News

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Malware

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding…

↗ Open article
Threat Intel Malwarebytes Labs

Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords

Breach

Shark’s cloud-connected robot vacuums are currently exposed by an unpatched AWS (Amazon Web Services) IoT (Internet of Things) policy flaw that could turn one compromised device into a remote-control skeleton key for…

↗ Open article
News The Hacker News

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the…

↗ Open article
News The Hacker News

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways…

↗ Open article
Media Schneier on Security

Details of Alan Turing’s Voice Encryption System

Really interesting piece of cryptographic history : In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously…

↗ Open article
News The Hacker News

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Ransom

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV…

↗ Open article
Threat Intel Malwarebytes Labs

How to use GitHub safely

GitHub is rapidly becoming the go-to platform for sharing software. Originally built for developers to collaborate on code, it now hosts millions of projects ranging from hobby scripts to widely used applications. That…

↗ Open article
News The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Malware

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and…

↗ Open article
News The Hacker News

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Malware APT Research

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term…

↗ Open article
News The Hacker News

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

CVE-2026-58644 ↗ Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring…

↗ Open article ↗ CVE feed
News The Hacker News

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems…

↗ Open article
News The Hacker News

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

Ransom Malware

A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage…

↗ Open article
Media Schneier on Security

Protecting Privacy in an AI Era

Privacy

Daniel Solove argues in the Wall Street Journal (alternate link ) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable…

↗ Open article
Threat Intel Malwarebytes Labs

The backlash against Flock cameras is spreading

Privacy

Flock-style ALPR systems carry serious privacy and civil-liberties risks, and the backlash is now starting to show up in agency decisions too. For those not yet familiar with Flock, Flock Safety operates an automated…

↗ Open article
News The Hacker News

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim…

↗ Open article
Research Rapid7 Blog

Sunsetting the Public AttackerKB Platform

Vuln

What’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence. On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a…

↗ Open article
News The Hacker News

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Malware Research

Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight…

↗ Open article
News The Hacker News

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

Malware

ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind…

↗ Open article
News The Hacker News

20+ Hijacked Government Websites Became
an Attack Channel

Malware

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat…

↗ Open article
News The Hacker News

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment…

↗ Open article
News The Hacker News

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

Malware APT

An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin…

↗ Open article
Threat Intel Malwarebytes Labs

Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom

Security updates are not just for enterprises with a dedicated security team and a change-management calendar. For consumers and small businesses, they are one of the simplest ways to shut down known attack paths before…

↗ Open article
News The Hacker News

AI Can Find Bugs, But Human Knowledge Still Proves Them

Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate…

↗ Open article
Threat Intel Malwarebytes Labs

Samsung backs down on threat to delete health data

If you pay for something, you expect it to work as intended. The vendor shouldn’t start turning features off just because you won’t accept its new rules. Someone should tell Samsung, which just upset users of its health…

↗ Open article
News The Hacker News

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the…

↗ Open article
News The Hacker News

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

Vuln

OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong…

↗ Open article
News The Hacker News

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

CVE-2026-53412 ↗ Vuln

Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom…

↗ Open article ↗ CVE feed
News The Hacker News

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Malware Research

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language…

↗ Open article
Research Rapid7 Blog

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)

CVE-2026-15409 ↗ CVE-2026-15410 ↗ Vuln

Overview On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF)…

↗ Open article ↗ CVE feed
News The Hacker News

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Phishing Malware

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes…

↗ Open article
Threat Intel Malwarebytes Labs

Claude for Chrome flaw could let rogue extensions access your Gmail

First reported in May, ClaudeBleed is basically a “fake remote control” problem. A sneaky browser extension can pretend to be Claude’s own website and secretly drive the Claude for Chrome extension to read your data and…

↗ Open article
News The Hacker News

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

CVE-2026-15718 ↗ Vuln

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the…

↗ Open article ↗ CVE feed
Research Rapid7 Blog

Investigating Persistence Mechanisms in AWS

Overview In the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn't have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM…

↗ Open article
Threat Intel Malwarebytes Labs

July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days

Vuln

Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‑days. July now triples that count , reinforcing that the era of “small” Patch Tuesdays may be over as AI‑driven…

↗ Open article
News The Hacker News

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS…

↗ Open article
News The Hacker News

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Vuln Research

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of…

↗ Open article
News The Hacker News

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this…

↗ Open article
News The Hacker News

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that…

↗ Open article
News The Hacker News

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Malware Breach

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are…

↗ Open article
Threat Intel Malwarebytes Labs

This fake Apple app can unlock your Mac’s password vault

Malware

CrashStealer is a new macOS infostealer that masquerades as Apple’s CrashReporter component, uses an Apple‑notarized installer to slip past Gatekeeper, tricks users into handing over their password, and then…

↗ Open article
News The Hacker News

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Vuln

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The…

↗ Open article
Research SANS Internet Storm Center

Recent DShield SIEM Update, (Tue, Jul 14th)

The last update to the DShield SIEM [4] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.

↗ Open article
Research Rapid7 Blog

Patch Tuesday - July 2026

Vuln

Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published…

↗ Open article
Advisory Tenable Security Advisories

[R1] Tenable Agent Versions 11.2.1 and 11.1.4 Fix a Path Traversal Vulnerability

Vuln

[R1] Tenable Agent Versions 11.2.1 and 11.1.4 Fix a Path Traversal Vulnerability Aaron Roy Tue, 07/14/2026 - 17:30 A vulnerability has been identified where path traversal of the Tenable Agent's plugin directory could…

↗ Open article
News The Hacker News

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Vuln

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count…

↗ Open article
News Krebs On Security

Microsoft Patches a Record 570 Security Flaws

Vuln

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its…

↗ Open article
Research SANS Internet Storm Center

Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)

Vuln

This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed…

↗ Open article
News The Hacker News

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

Vuln

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is…

↗ Open article
News The Hacker News

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Research

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a…

↗ Open article
News The Hacker News

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

Malware Research

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a…

↗ Open article
Media Schneier on Security

Upcoming Speaking Engagements

Privacy Research

This is a current list of where and when I am scheduled to speak: I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026. I’m speaking at Boston Leadership…

↗ Open article
News The Hacker News

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Research

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging…

↗ Open article
Research Rapid7 Blog

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

CVE-2026-55040 ↗ Vuln Research

Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution…

↗ Open article ↗ CVE feed
News The Hacker News

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Research

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware…

↗ Open article
News The Hacker News

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Privacy Research

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk…

↗ Open article
News The Hacker News

How Pentera Turns AI Security Workflows into Validation Engines

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals…

↗ Open article
News The Hacker News

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and…

↗ Open article
Threat Intel Malwarebytes Labs

Warning: Scammers are using FaceTime to empty bank accounts

Apple is urging users to treat any suspicious FaceTime call or message as untrusted, especially if it involves payments, refunds, password resets, or requests for personal information. This warning appears in a broader…

↗ Open article
Threat Intel Any.Run Malware Analysis

​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​

Phishing

Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. By combining trusted platforms, anti-bot checks, and convincing login pages, ithelps attackers…

↗ Open article
Threat Intel Malwarebytes Labs

The inside job that cost ransomware victims millions

Ransom

When a ransomware crew locks up your servers, the outside negotiator you hire has to know everything about you so that they can negotiate a smaller ransom payment. You tell them what your cyber-insurance covers and what…

↗ Open article
News The Hacker News

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

Research

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab…

↗ Open article
News The Hacker News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

Ransom Malware

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including…

↗ Open article
Research Rapid7 Blog

Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East

Gopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7 From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab…

↗ Open article
News The Hacker News

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

Malware DoS Research

A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did…

↗ Open article
News The Hacker News

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Vuln Ransom

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been…

↗ Open article
News The Hacker News

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Malware Breach Research

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on…

↗ Open article
News The Hacker News

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Research

Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its…

↗ Open article
News Krebs On Security

Lessons Learned from CISA’s Recent GitHub Leak

Breach

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public…

↗ Open article
Threat Intel Malwarebytes Labs

Trusting your kids online isn’t enough (Lock and Code S07E14)

This week on the Lock and Code podcast… There is a lot going on right now regarding the safety of kids online. In the United States, the majority of state legislatures have passed age verification laws requiring a…

↗ Open article
Threat Intel Malwarebytes Labs

Ghostcommit attack hides malicious AI instructions in images

Research

Ghostcommit is a proof of concept that shows how AI assistants used to review software code can be tricked by hidden instructions embedded in images. The academic ASSET Research Group showed that an attacker can place…

↗ Open article
Threat Intel Malwarebytes Labs

Fake crypto gift card sites are getting harder to spot

You want to turn some crypto into a gift card. You search, click a promising result, and land on a site that looks polished and legitimate: a dark theme, trust badges, and promises of instant delivery and no ID checks…

↗ Open article
Research Trail of Bits

Rust-proof your code with our new Testing Handbook chapter

We’ve added a new chapter to our Testing Handbook : a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs…

↗ Open article
Threat Intel Malwarebytes Labs

A week in security (July 6 – July 12)

Vuln Malware

Last week on Malwarebytes Labs: This new Windows malware can take over your PC and wipe it clean How mule betting scams recruit ordinary people Two Chrome updates in two days fix critical vulnerabilities How World Cup…

↗ Open article
Research Rapid7 Blog

Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit

Vuln

More AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new…

↗ Open article
Media Schneier on Security

Friday Squid Blogging: “Squidbleed” Vulnerability

Vuln

In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t…

↗ Open article
Threat Intel Malwarebytes Labs

This new Windows malware can take over your PC and wipe it clean

Malware Research

Microsoft published new research on GigaWiper, a modular Golang backdoor for Windows that combines robust remote access with multiple ways to permanently destroy systems and data. GigaWiper is a Windows backdoor that…

↗ Open article
Threat Intel Malwarebytes Labs

How mule betting scams recruit ordinary people

Mule betting or third-party betting account scams are a form of money mule scam where criminals recruit or coerce people into opening gambling accounts in their own name. The criminals then use those accounts to place…

↗ Open article
Media Schneier on Security

AI Surveillance and Social Progress

Privacy

In the near future, AI -powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong—shoplift, litter, jaywalk, you name it—the system…

↗ Open article
Threat Intel Malwarebytes Labs

Two Chrome updates in two days fix critical vulnerabilities

Vuln

Updating Chrome is becoming an almost daily task lately. But it’s too important to ignore. On Wednesday, July 8, Google released another Chrome update, just one day later after the previous one . Between them, the two…

↗ Open article
Threat Intel Malwarebytes Labs

How World Cup crypto prediction sites take your money

Research

Crypto prediction and betting sites are appearing around the World Cup, and researchers have already tracked scams aimed at fans, including fake ticketing, fixed-match betting, prediction scams, and fan-branded meme…

↗ Open article
Threat Intel Malwarebytes Labs

6.9 million driver’s license numbers stolen from AssuranceAmerica

Breach

Insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of up to 6.9 million people. AssuranceAmerica provides car and rental insurance to…

↗ Open article
Threat Intel Malwarebytes Labs

Microsoft fixes RoguePlanet zero-day in Defender

CVE-2026-50656 ↗ Vuln

Microsoft issued a security update that fixes the zero-day vulnerability known as RoguePlanet in Microsoft Defender. RoguePlanet is tracked as CVE-2026-50656 , a Microsoft Defender elevation of privilege (EoP)…

↗ Open article ↗ CVE feed
Research Rapid7 Blog

Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?

The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit , we…

↗ Open article
News Krebs On Security

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Vuln

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures…

↗ Open article
Research Trail of Bits

Mutation testing comes to DAML

In April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt…

↗ Open article
Threat Intel Any.Run Malware Analysis

Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN

Malware Research

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X . This analysis started with an exposed public index on 198[.]245[.]53[.]26…

↗ Open article
Podcast Darknet Diaries

176: NSL

One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to…

↗ Open article
Research Rapid7 Blog

A Day With Your Vector Command Red Team Pod

Anyone trying to understand continuous red teaming usually gets the same high-level explanation: it is ongoing, attacker-informed, and designed to uncover risk between formal assessments. Useful as that description is…

↗ Open article
Research Rapid7 Blog

Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more

Vuln

It's Time to Upgrade Your SMB Session This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use…

↗ Open article
News Krebs On Security

FBI Seizes NetNut Proxy Platform, Popa Botnet

Malware

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut , a sprawling residential proxy service operated by the publicly-traded Israeli…

↗ Open article
Research Rapid7 Blog

Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture

Vuln

Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and…

↗ Open article
Research Trail of Bits

GPT-5.5-Cyber built a zlib fuzzing lab in a day

Vuln

We’re running Patch the Planet , an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source…

↗ Open article
Research Rapid7 Blog

5 Myths About AI in the SOC Security Teams Need to Rethink

AI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how…

↗ Open article
Research NIST Cybersecurity Insights

Verifiable Digital Credential Presentment

This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are…

↗ Open article
Research Trail of Bits

Shipping post-quantum cryptography to Python

Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and…

↗ Open article
Research Rapid7 Blog

Modernizing Global Vulnerability Standards For The Age Of AI

Vuln

As AI-driven vulnerability discovery accelerates, the cybersecurity ecosystem is being forced to examine whether the standards, disclosure processes, and prioritization frameworks defenders rely on can still keep pace…

↗ Open article
Research Rapid7 Blog

Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

Help shape the future of Metasploit Framework We are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting…

↗ Open article
Research Rapid7 Blog

Experts on Experts: Why AI and Compliance Are Forcing A New Security Operating Model

Policy

This week on Experts on Experts, I sat down with Sabeen Malik , Rapid7’s VP of Global Government Affairs and Public Policy, to discuss a shift security leaders can’t afford to treat as separate threads: frontier AI…

↗ Open article
Advisory Tenable Security Advisories

[R2] Nessus Version 10.12.1 Fixes SQL Injection Vulnerabilities

Vuln

[R2] Nessus Version 10.12.1 Fixes SQL Injection Vulnerabilities Aaron Roy Wed, 06/24/2026 - 14:16 Vulnerabilities have been identified in Nessus version 10.12.0 and lower. An attacker can potentially perform SQL…

↗ Open article
Research NIST Cybersecurity Insights

Advancing Product Security: New IoT Guidance and New Engagement

It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance…

↗ Open article
Advisory Tenable Security Advisories

[R3] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities

Vuln

[R3] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities Aaron Roy Tue, 06/23/2026 - 16:43 Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several…

↗ Open article
Research Rapid7 Blog

Why SIEM is Moving Toward Unified Security Operations: Rapid7 Named a Major Player in IDC MarketScape

Rapid7 has been named a Major Player in the IDC MarketScape: Worldwide SIEM 2026 Vendor Assessment (#US54126826, June 2026). This is the first IDC SIEM MarketScape to bring the enterprise and SMB markets into a single…

↗ Open article
News Krebs On Security

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London , the entity responsible for the public transport network in the…

↗ Open article
Threat Intel Any.Run Malware Analysis

EvilTokens: How “Ghost” Code Threatens US and European Businesses

EvilTokens can hide serious account takeover risk from your SOC through “ghost” code that appears only after browser-side decryption. As a result, static URL analysis may miss the most important part of the attack…

↗ Open article
Research Trail of Bits

Introducing Patch the Planet

Vuln

What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source…

↗ Open article
Research Rapid7 Blog

Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more

Vuln

This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new…

↗ Open article
News Krebs On Security

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Malware

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts…

↗ Open article
Research Trail of Bits

Factoring "short-sleeve" RSA keys with polynomials

What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enough for us to detect these incorrectly generated keys in the…

↗ Open article
News Krebs On Security

Who Runs the Ransomware Group ‘The Gentlemen?’

Ransom

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises…

↗ Open article
News Krebs On Security

A Record-Breaking Patch Tuesday for June 2026

Vuln

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly…

↗ Open article
Research Trail of Bits

The sorry state of skill distribution

Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of…

↗ Open article
Threat Intel Any.Run Malware Analysis

From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises

Malware Research

A previously unidentified cyberattack is quietly spreading through US businesses — and most security tools are not catching it. Researchers at ANY.RUN have identified a new backdoor called JS.MonoGlyphRAT, an advanced…

↗ Open article
News Krebs On Security

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on…

↗ Open article
Threat Intel Any.Run Malware Analysis

Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More

Phishing Malware

May 2026 showed how fast routine business activity can turn into real security exposure. ANY.RUN observed phishing campaigns, fileless malware delivery, credential theft, OTP interception, and remote access abuse…

↗ Open article
News Krebs On Security

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation…

↗ Open article
Research Trail of Bits

Bringing full YAML anchor support to zizmor

Vuln Malware

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor LiteLLM…

↗ Open article
Advisory Tenable Security Advisories

[R1] Sensor Proxy Version 1.4.0 Fixes Multiple Vulnerabilities

Vuln

[R1] Sensor Proxy Version 1.4.0 Fixes Multiple Vulnerabilities Jason Schavel Thu, 05/21/2026 - 16:00 Sensor Proxy leverages third-party software to help provide underlying functionality. Several of the third-party…

↗ Open article
Advisory Tenable Security Advisories

[R2] Tenable Network Monitor 6.5.4 Fixes Multiple Vulnerabilities

Vuln

[R2] Tenable Network Monitor 6.5.4 Fixes Multiple Vulnerabilities Jason Schavel Thu, 05/14/2026 - 13:00 Tenable Network Monitor leverages third-party software to help provide underlying functionality. Several of the…

↗ Open article
Threat Intel Any.Run Malware Analysis

LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises

Ransom Malware Research

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X . Credential theft malware rarely announces itself with ransomware-level noise…

↗ Open article
Research Trail of Bits

gosentry brings LibAFL-grade fuzzing to Go's native interface

Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path constraints are hard to solve. Structured inputs usually need…

↗ Open article
Threat Intel Any.Run Malware Analysis

New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know

Phishing Research

A new large-scale phishing campaign is targeting U.S. organizations with fake event invitations that lead to credential theft, OTP interception, or RMM tool installation. ANY.RUN researchers found that the campaign uses…

↗ Open article
Research Trail of Bits

Escalating a Windows driver registry bug to a kernel write primitive

We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples : a deceptively simple Linux ping program and a Windows driver registry handler. If you…

↗ Open article
Research NIST Cybersecurity Insights

Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week

Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part…

↗ Open article
Research Trail of Bits

Extending Ruzzy with LibAFL

LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode . Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing…

↗ Open article
Research MITRE ATT&CK

ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage…

ICS/OT

ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage, and Detection Strategies for Mobile ATT&CK v19 is here, and this release has been a long time coming. The Defense Evasion…

↗ Open article
Threat Intel Any.Run Malware Analysis

Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore

Phishing

CISOs are under pressure to prove that their security programs can detect threats early, reduce business risk, and support fast, confident response. But that becomes harder when attackers stop relying on obviously…

↗ Open article
Research NIST Cybersecurity Insights

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance

In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define…

↗ Open article
Threat Intel Any.Run Malware Analysis

Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time

Phishing Malware Research

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X . A new phishing campaign targeting Brazilian users demonstrates how modern…

↗ Open article
Research Google Security Blog

AI threats in the wild: The current state of prompt injections on the web

Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact…

↗ Open article
Advisory Tenable Security Advisories

[R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion

Vuln

[R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion Jason Schavel Thu, 04/23/2026 - 14:30 A vulnerability has been identified in Nessus on Windows where an attacker to create a junction, enabling the…

↗ Open article
Advisory Tenable Security Advisories

[R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion

Vuln

[R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion Jason Schavel Thu, 04/23/2026 - 14:10 A vulnerability has been identified in Nessus Agent on Windows where an attacker to create a junction, enabling the…

↗ Open article
Research Trail of Bits

Trailmark turns code into graphs

We’re open-sourcing Trailmark , a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude…

↗ Open article
Threat Intel Any.Run Malware Analysis

New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses

Malware APT Research

Editor’s note: The research is authored by Mauro Eldritch, offensive security expert and a founder of BCA LTD, a company dedicated to threat intelligence and hunting. You can find Mauro on X . The recent wave of…

↗ Open article
Research Trail of Bits

We beat Google’s zero-knowledge proof of quantum cryptanalysis

Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum computers will break elliptic curve cryptography keys in as…

↗ Open article
Advisory Tenable Security Advisories

[R3] Tenable Identity Exposure Version 3.77.17 Fixes Multiple Vulnerabilities

Vuln

[R3] Tenable Identity Exposure Version 3.77.17 Fixes Multiple Vulnerabilities Aaron Roy Tue, 04/14/2026 - 10:54 Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several…

↗ Open article
Research Google Security Blog

Bringing Rust to the Pixel Baseband

Vuln

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation…

↗ Open article
Research Google Security Blog

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement , Device Bound Session Credentials (DBSC) is now entering public…

↗ Open article
Research Trail of Bits

Master C and C++ with our new Testing Handbook chapter

We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code . We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases…

↗ Open article
Advisory Tenable Security Advisories

[R2] Stand-alone Security Patch Available for Tenable Security Center Versions 6.5.1, 6.6.0, 6.7.2 and 6.8.0: SC202604.1

Vuln

[R2] Stand-alone Security Patch Available for Tenable Security Center Versions 6.5.1, 6.6.0, 6.7.2 and 6.8.0: SC202604.1 Aaron Roy Tue, 04/07/2026 - 11:35 Security Center leverages third-party software to help provide…

↗ Open article
Research Trail of Bits

What we learned about TEE security from auditing WhatsApp's Private Inference

WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such as message summarization. To make this possible, Meta built a…

↗ Open article
Research Trail of Bits

Simplifying MBA obfuscation with CoBRA

Malware

Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and software protectors rely on it because no standard simplification…

↗ Open article
Research Google Security Blog

Google Workspace’s continuous approach to mitigating indirect prompt injections

Posted by Adam Gavish, Google GenAI Security Team Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This…

↗ Open article
Research Trail of Bits

Mutation testing for the agentic era

Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures execution, not verification. Test suites with high…

↗ Open article
Research MITRE ATT&CK

Defense Evasion Split: A Tale of Two Tactics

By Allison Henao and Alice Koeninger, Art by Cat Self If you’ve been following the ATT&CK community channels, you’ve probably heard us talking about changes to Enterprise’s Defense Evasion tactic ( ATT&CKcon 5.0 …

↗ Open article
Research Google Security Blog

VRP 2025 Year in Review

Vuln

Posted by Dirk G ö hmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!…

↗ Open article
Research Trail of Bits

How we made Trail of Bits AI-native (so far)

This post is adapted from a talk I gave at [un]prompted , the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or download the slides …

↗ Open article
Research Google Security Blog

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible"…

↗ Open article
Research Trail of Bits

Try our new dimensional analysis Claude plugin

We’re releasing a new Claude plugin for developing and auditing code that implements dimensional analysis, a technique we explored in our most recent blog post . Most LLM-based security skills ask the model to find…

↗ Open article
Research Trail of Bits

Spotting issues in DeFi with dimensional analysis

Using dimensional analysis, you can categorically rule out a whole category of logic and arithmetic bugs that plague DeFi formulas. No code changes required, just better reasoning! One of the first lessons in physics is…

↗ Open article
Research NIST Cybersecurity Insights

Reflections from the Second NIST Cyber AI Profile Workshop

Thank you to everyone who participated in the Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) Workshop in January! The input we received on the Preliminary Draft during this workshop has…

↗ Open article
Research NIST Cybersecurity Insights

All aboard: the NIST Cybersecurity for IoT Program is headed to our next stop! Share your input on where we’re headed during our Future Directions Two-Day Workshop on March 31st

Workshop Details… We’re looking forward to hearing from the community during our “Future Directions” Workshop! Date: March 31 - April 1, 2026 Where: NIST’s Gaithersburg campus! Registration and Details: HERE Can’t make…

↗ Open article
Advisory Tenable Security Advisories

[R1] Stand-alone Security Patch Available for Tenable OT version 4.2.40: tenable-ot-platform-137

Vuln

[R1] Stand-alone Security Patch Available for Tenable OT version 4.2.40: tenable-ot-platform-137 Jason Schavel Thu, 03/19/2026 - 15:06 An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration…

↗ Open article
Research Google Security Blog

Cultivating a robust and efficient quantum-safe HTTPS

Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a…

↗ Open article
Research Google Security Blog

Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We’ve shared how Android’s proactive, multi-layered scam defenses utilize…

↗ Open article
Research NIST Cybersecurity Insights

Celebrating Two Years of CSF 2.0!

Celebrate this milestone with us! Email us at csf [at] nist.gov (csf[at]nist[dot]gov) or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing…

↗ Open article
Research Google Security Blog

Keeping Google Play & Android app ecosystems safe in 2025

Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that…

↗ Open article
Research Google Security Blog

New Android Theft Protection Feature Updates: Smarter, Stronger

Posted by Nataliya Stanetsky, Fabricio Ferracioli, Elliot Sisteron, Irene Ang of the Android Security Team Phone theft is more than just losing a device; it's a form of financial fraud that can leave you suddenly…

↗ Open article
Research NIST Cybersecurity Insights

Celebrating Data Privacy Week with NIST’s Privacy Engineering Program

Privacy

Grab your party hats – it’s Data Privacy Week! Data Privacy Week is a global initiative led by the National Cybersecurity Alliance to spread awareness about online privacy and empower individuals and businesses to…

↗ Open article
Research NIST Cybersecurity Insights

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

Understanding mDL credential formats Standards in the VDC Ecosystem In our first blog post in this series, we highlighted that VDCs can represent a wide range of credentials, from a driver’s license to a diploma to…

↗ Open article
Research Google Security Blog

HTTPS certificate industry phasing out less secure domain validation methods

Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root…

↗ Open article
Research Google Security Blog

Further Hardening Android GPUs

Privacy

Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in…

↗ Open article
Research Google Security Blog

Architecting Security for Agentic Capabilities in Chrome

Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome…

↗ Open article
Research Google Security Blog

Android expands pilot for in-call scam protection for financial apps

Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust & Safety Lead Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every…

↗ Open article
Research NIST Cybersecurity Insights

A NICE Retrospective on Shaping Cybersecurity’s Future

Rodney Petersen has served as the Director of NICE at the National Institute for Standards and Technology (NIST) for the past eleven years where his focus has been on advancing cybersecurity education and workforce…

↗ Open article
Research Google Security Blog

Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Privacy

Posted by Dave Kleidermacher, VP, Platforms Security & Privacy, Google Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy…

↗ Open article
Research Google Security Blog

Rust in Android: move fast and fix things

Vuln

Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in new code quickly yields durable and compounding gains. This year we look at how…

↗ Open article
Research Google Security Blog

How Android provides the most effective protection to keep you safe from mobile scams

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity…

↗ Open article
Research Google Security Blog

HTTPS by default

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the…

↗ Open article
Research MITRE ATT&CK

ATT&CK v18: Detection Strategies, More Adversary Insights

ATT&CK v18: The Detection Overhaul You’ve Been Waiting For We’ve spent the last six months focused on making ATT&CK more usable and actionable for defenders, and with the help of the community the results are here!…

↗ Open article
Research NIST Cybersecurity Insights

Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers

Update: The comment period for your feedback on the second public draft of NIST IR 8259 has been extended through December 10, 2025. Over the past few months, NIST has been revising and updating Foundational Activities…

↗ Open article
Research Google Security Blog

Accelerating adoption of AI for cybersecurity at DEF CON 33

Privacy

Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security Team Empowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle…

↗ Open article
Research Google Security Blog

Supporting Rowhammer research to protect the DRAM ecosystem

Vuln Research

Posted by Daniel Moghimi Rowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows…

↗ Open article
Research Google Security Blog

How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials

Posted by Eric Lynch, Senior Product Manager, Android Security, and Sherif Hanna, Group Product Manager, Google C2PA Core At Made by Google 2025, we announced that the new Google Pixel 10 phones will support C2PA…

↗ Open article
Research Google Security Blog

Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification

Privacy

Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that…

↗ Open article
Research NIST Cybersecurity Insights

Let’s get Digital! Updated Digital Identity Guidelines are Here!

Today is the day! Digital Identity Guidelines, Revision 4 is finally here...it’s been an exciting journey and NIST is honored to be a part of it. What can we expect? Serving as a culmination of a nearly four-year…

↗ Open article
Research NIST Cybersecurity Insights

Reflections from the First Cyber AI Profile Workshop

Thank you to everyone who participated in the Cyber AI Profile Workshop NIST hosted this past April! This work intends to support the cybersecurity and AI communities — and the input you provided during this workshop is…

↗ Open article
Research Google Security Blog

Introducing OSS Rebuild: Open Source, Rebuilt to Last

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As…

↗ Open article
Research MITRE ATT&CK

What Comes After Detection Rules? Smarter Detection Strategies in ATT&CK

By Lex Crumpton Updated: October 22, 2025 Key updates: - Website example images added - No more Log Source SDO → log sources now live as a x_mitre_log_sources field on the Data Components SDO. - No more <detects> SRO…

↗ Open article
Research Google Security Blog

Advancing Protection in Chrome on Android

Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection , which extends Google’s Advanced Protection Program to a device-level security setting for…

↗ Open article
Research NIST Cybersecurity Insights

Nine Years and Counting: NICE RAMPS Communities Keep Expanding Opportunities in Cybersecurity Work and Learning

A lot has changed in America’s cybersecurity workforce development ecosystem since 2016: employment in cybersecurity occupations has grown by more than 300,000 [1]; the number of information security degrees awarded…

↗ Open article
Research Google Security Blog

Mitigating prompt injection attacks with a layered defense strategy

Posted by Adam Gavish, Google GenAI Security Team With the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging…

↗ Open article
Research NIST Cybersecurity Insights

The Impact of Artificial Intelligence on the Cybersecurity Workforce

The NICE Workforce Framework for Cybersecurity ( NICE Framework) was revised in November 2020 as NIST Special Publication 800-181 rev.1 to enable more effective and rapid updates to the NICE Framework Components…

↗ Open article
Research NIST Cybersecurity Insights

Cybersecurity and AI: Integrating and Building on Existing NIST Guidelines

What is NIST up to? On April 3, 2025, NIST hosted a Cybersecurity and AI Profile Workshop at our National Cybersecurity Center of Excellence (NCCoE) to hear feedback on our concept paper which presented opportunities to…

↗ Open article
Research NIST Cybersecurity Insights

Five Years Later: Evolving IoT Cybersecurity Guidelines

The Background…and NIST’s Plan for Improving IoT Cybersecurity The passage of the Internet of Things (IoT) Cybersecurity Improvement Act in 2020 marked a pivotal step in enhancing the cybersecurity of IoT products…

↗ Open article
Research NIST Cybersecurity Insights

Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week

This week we’re celebrating National Small Business Week—which recognizes and celebrates the small and medium-sized business (SMB) community’s significant contributions to the nation. SMBs are a substantial and critical…

↗ Open article
Research MITRE ATT&CK

ATT&CK v17: New Platform (ESXi), Collection Optimization, & More Countermeasures

By: Amy Robertson and Adam Pennington Our goal with ATT&CK v17 is to help defenders stay aligned with where adversaries are headed by looking at where they’ve recently been. This release aims to inform defensive efforts…

↗ Open article
Research NIST Cybersecurity Insights

Celebrating 1 Year of CSF 2.0

It has been one year since the release of the NIST Cybersecurity Framework (CSF) 2.0 ! To make improving your security posture even easier, in this blog we are: Sharing new CSF 2.0 resources; Taking a retrospective look…

↗ Open article
Research NIST Cybersecurity Insights

Privacy-Preserving Federated Learning – Future Collaboration and Continued Research

Privacy Research

This post is the final blog in a series on privacy-preserving federated learning . The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the…

↗ Open article
Research NIST Cybersecurity Insights

NIST’s International Cybersecurity and Privacy Engagement Update – New Translations

Privacy

As the year comes to a close, NIST continues to engage with our international partners to strengthen cybersecurity, including sharing over ten new international translations in over six languages as resources for our…

↗ Open article
Research NIST Cybersecurity Insights

Data Pipeline Challenges of Privacy-Preserving Federated Learning

Privacy

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for…

↗ Open article
Research NIST Cybersecurity Insights

Kicking-Off with a December 4th Workshop, NIST is Revisiting and Revising Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST IR 8259!

In May 2020, NIST published Foundational Cybersecurity Activities for IoT Device Manufacturers (NIST IR 8259), which describes recommended cybersecurity activities that manufacturers should consider performing before…

↗ Open article
Research NIST Cybersecurity Insights

Unlocking Cybersecurity Talent: The Power of Apprenticeships

Cybersecurity is a fast-growing field, with a constant need for skilled professionals. But unlike other professions — like medicine or aviation — there’s no clear-cut pathway to qualifying for cybersecurity positions…

↗ Open article
Research NIST Cybersecurity Insights

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

If you are interested in the world of digital identities, you have probably heard some of the buzzwords that have been floating around for a few years now… “verifiable credential,” “digital wallet,” “mobile driver’s…

↗ Open article
Research MITRE ATT&CK

v16 Cloud Rebalancing, Analytics

V16 Brings (Re)Balance: Restructured Cloud, New Analytics, and More Cybercriminals In v16, we’re all about balance — striking that perfect chord between familiar and pioneering to keep things real and actionable. This…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

IoT Assignment Completed! Report on Barriers to U.S. IoT Adoption

The 16 members of the NIST-managed Internet of Things (IoT) Advisory Board have completed their report on barriers to the U.S. receiving the benefits of IoT adoption, along with their recommendations for overcoming…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Scalability Challenges in Privacy-Preserving Federated Learning

Privacy

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Managing Cybersecurity and Privacy Risks in the Age of Artificial Intelligence: Launching a New Program at NIST

Privacy

The rapid proliferation of Artificial Intelligence (AI) promises significant value for industry, consumers, and broader society, but as with many technologies, new risks from these advancements in AI must be managed to…

↗ Open article
Research NIST Cybersecurity Insights

Learning, Sharing, and Exploring with NIST’s New Human-Centered Cybersecurity Community of Interest

Human-centered cybersecurity (also known as ‘usable security’) involves the social, organizational, and technological influences on people’s understanding of and interactions with cybersecurity. By taking a…

↗ Open article
Research MITRE ATT&CK

Introducing TAXII 2.1 and a fond farewell to the TAXII 2.0 Server

As mentioned in our 2024 Roadmap and the v15 release blog , we’re excited to introduce our new TAXII server and the latest addition to the ATT&CK Workbench software suite: the MITRE ATT&CK Workbench TAXII 2.1 Server …

↗ Open article
Research NIST Cybersecurity Insights

Implementation Challenges in Privacy-Preserving Federated Learning

Privacy

In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong (University of Liverpool), Dr. Mat Weldon ( United Kingdom (UK) Office of National Statistics (ONS)), and Dr. Michael Fenton (Trūata) who were winners in the…

↗ Open article
Research NIST Cybersecurity Insights

Protecting Trained Models in Privacy-Preserving Federated Learning

Privacy

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for…

↗ Open article
Research NIST Cybersecurity Insights

NIST’s International Cybersecurity and Privacy Engagement Update – Mexico City, RSA Conference, and More

Privacy

The last few months have brought even more opportunities for NIST to engage with our international partners to enhance cybersecurity. Here are some updates on our recent international engagement: Conversations have…

↗ Open article
Research NIST Cybersecurity Insights

Check Your Wallet? How Mobile Driver’s Licenses are Changing Online Transactions

Can you recall the last time you opened a bank account? It’s likely you walked into a local bank branch and spoke to a representative who asked for your driver’s license and social security card to verify your identity…

↗ Open article
Research NIST Cybersecurity Insights

Latest NICE Framework Update Offers Improvements for the Cybersecurity Workforce

I joined NIST as the first full-time manager of the NICE Framework in October 2020, just one short month before NICE published the first revision NIST Special Publication 800-181, the NICE Workforce Framework for…

↗ Open article
Research MITRE ATT&CK

ATT&CK v15 Brings the Action

ATT&CK v15 Brings the Action: Upgraded Detections, New Analytic Format, & Cross-Domain Adversary Insights v15 is all about actionability and bringing defenders’ reality into focus — we prioritized what you need to…

↗ Open article
Research MITRE ATT&CK

ATT&CK 2024 Roadmap

Enhancing usability, expanding scope, optimizing defenses 2023 was dynamic year for ATT&CK. We marked a decade of progress since the framework’s inception and achieved some key milestones to make ATT&CK more accessible…

↗ Open article
Research MITRE ATT&CK

ATT&CK v14 Unleashes Detection Enhancements, ICS Assets, and Mobile Structured Detections

ICS/OT

Credit: https://flic.kr/p/dzyK9x CC BY-SA 2.0 ATT&CK has been brewing up something eerie for this Halloween — a release so hauntingly powerful that it will send a chill down the spine of even the most formidable…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.