Apple iCloud Mail vulnerabilities allowed spoofed sender addresses
Two vulnerabilities discovered in Apple’s iCloud Mail infrastructure allowed authenticated users to send emails that appeared to originate from any @icloud.c...
Two vulnerabilities discovered in Apple’s iCloud Mail infrastructure allowed authenticated users to send emails that appeared to originate from any @icloud.c...
AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto...
Quarantining rogue AI agents isn't enough if their credentials and access remain active.
Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individ...
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the countr...
Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new featur...
Stellar Cyber has announced Stellar Cyber 7.0, a release that advances the Human-Augmented Autonomous SOC from a vision for applying AI to security operation...
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely.
Russian group Star Blizzard expands phishing campaigns with a new malware delivery RedFlick technique, using scheduled tasks to deliver the CosmicPulse backd...
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vuln...
AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could allow ...
Microsoft Defender for Identity is the best ITDR solutions starting point for most estates often already licensed while CrowdStrike leads platform-consolidat...
Okta’s Auth0 line is the best CIAM for most product teams the benchmark ecosystem with the procurement fast-pass while Amazon Cognito and Microsoft Entra Ext...
Microsoft is the best passwordless starting point for most workforces passkeys and Windows Hello ride licensing you already own while HYPR leads the dedicate...
South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of data breaches impacting major banks and other financial insti...
Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) e...
Unknown attackers compromised the official Microsoft account on X, promoting a cryptocurrency token in what appeared to be a pump-and-dump scheme.
Dutch Institute for Vulnerability Disclosure was breached through two Zammad 0-days in an AI-powered attack that led to remote code execution and root access.