Latest news

  1. Vulnerabilities via CERT/CC

    VU#280377: Dokploy is vulnerable to OS command injection

    Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and…

  2. Threat Intel via Infosecurity Magazine

    FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

    ESET said FamousSparrow has replaced SparrowDoor with SparroWocky

  3. Vulnerabilities via Cisco PSIRT

    Cisco Secure Email Gateway SQL Injection Vulnerability

    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary…

  4. Breaches via Graham Cluley

    US Coast Guard and FBI board oil tanker to investigate cyber attack

    An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers…

  5. AI Security via Check Point Research

    AI Threat Landscape Digest: July–August 2026

    The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real…

  6. Vulnerabilities via Wiz

    Exploring the new AWS Sign Up experience

    This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of…

  7. Threat Intel via Security Affairs

    SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

    Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher…

  8. Breaches via Malwarebytes Labs

    Revolut phishing texts appear days after data breach

    Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we…

  9. AI Security via Wiz

    Building an AI Detection Engine That Understands Agent Intent

    Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior

  10. Threat Intel via The Hacker News

    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility…

  11. Threat Intel via Flashpoint

    Flashpoint Named A Customer Favorite in The Forrester Wave™

    Blogs Blog Flashpoint Named A Customer Favorite in The Forrester Wave In this blog we explore the recently published Forrester Wave: External Threat Intelligence Service…

  12. AI Security via HIPAA Journal

    Free Webinar: Is AI Putting Your Practice at Risk?

    AI tools are already in your practice. The question is whether you know about it and whether they are HIPAA compliant. Most practices are using AI in some form already…

  13. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a…

  14. AI Security via Adversa AI

    Why vibe coding security is the next enterprise nightmare

    Vibe coding is democratizing software development, but it is also creating a massive shadow AI attack surface. Security teams cannot rely on bans to address this risk…

  15. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  16. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability

    Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

  17. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability

    Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

  18. AI Security via Microsoft Security Response Center

    CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability

    Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

  19. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

  20. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability

    Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.