SC Media
20 articles
CISA red team finds critical infrastructure vulnerabilities
The assessments, detailed in CISA advisory AA26-237A, targeted a Government Services and Facilities Sector entity (Organization A) and a Water and Wastewater...
Dark Caracal group enhances cyberespionage with new GoCaracal malware
Arctic Wolf researchers discovered GoCaracal during an investigation into a targeted intrusion in Venezuela.
How to Evaluate AI Agent Security and Control Vendors
How to Evaluate EDR, XDR, and MDR Based on Response Outcomes
Shadow AI surges as 80% of employee AI tools evade IT oversight
Reco’s The State of Agent Security 2026 report highlights shadow AI, MCP risks and AI vulnerability trends.
Cellebrite launches portable field kit for military data extraction
The Cellebrite Tactical Extraction Kit, or C-TEK, is a backpack-sized kit containing ruggedized hardware and Cellebrite software, including Inseyets and Digi...
Ring adopts new TAKE encryption standard for smart home devices
The TAKE standard utilizes a rotating set of encryption keys that are temporarily stored in the cloud and accessible by Ring to power active user features.
Nimbus Manticore expands infrastructure and malware arsenal
Nimbus Manticore, associated with the Tortoiseshell (Imperial Kitten) cluster, has been observed using an SSH-based tunneling utility and a C++ backdoor simi...
Carhartt data breach claims inflated by synthetic data, analysis finds
ShinyHunters had claimed to leak 50GB of Carhartt's data on August 13, following a negotiation attempt after an initial extortion demand of $3.3 million.
FBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructure
The platforms, operated by a China-based group identified as QTFY and linked to Nanjing Xinjiuwei Network Technology Company, provided hacking services to en...
Ubiquiti patches 3 critical remote code execution vulnerabilities
The vulnerabilities include improper input validation in the UniFi Protect Application (CVE-2026-77537), a CRLF injection flaw in UniFi OS devices (CVE-2026-...
Boston Scientific operations disrupted by ongoing cyberattack
The cyberattack on Boston Scientific has caused a global disruption to the company's IT systems and business applications.
Unified vision: An executive playbook for data risk management
Fragmented efforts following a data incident will lead to confusion and high legal bills. Here's a better approach.
A Founder's Journey: From Software Engineer to US Special Operations to AI Founder - Snehal Antani - FS #16
Over 100 US water utilities had cyberattacks in July, says CISA
More than 100 water systems faced attacks in July as CISA urges utilities to reduce OT exposure.
OWASP updates top 10 security risks for LLM applications
OWASP’s 2026 LLM Top 10 highlights prompt injection, AI agents and emerging RAG security risks.
LACMA data breach exposes customer and employee information
The Los Angeles County Museum of Art (LACMA), one of the largest art museums in the western United States, has announced that a data breach last year exposed...
Fake recruiter scams target corporate credentials on mobile devices
Researchers at Zimperium's zLabs have identified these campaigns, tracked as RecruitTrap, impersonating major companies such as Amazon, Apple, and Deloitte.
Nucleus Security unveils AI engine to enhance exposure management
Nucleus Helix integrates with the company's existing Data Core, which stores asset, vulnerability, and ownership information.