Latest news
-
Vulnerabilities via CERT/CC
VU#280377: Dokploy is vulnerable to OS command injection
Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and…
-
Threat Intel via Infosecurity Magazine
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Email Gateway SQL Injection Vulnerability
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary…
-
Breaches via Graham Cluley
US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers…
-
AI Security via Check Point Research
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real…
-
Vulnerabilities via Wiz
Exploring the new AWS Sign Up experience
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of…
-
Threat Intel via Security Affairs
SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher…
-
Breaches via Malwarebytes Labs
Revolut phishing texts appear days after data breach
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we…
-
AI Security via Wiz
Building an AI Detection Engine That Understands Agent Intent
Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior
-
Threat Intel via The Hacker News
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility…
-
Threat Intel via Flashpoint
Flashpoint Named A Customer Favorite in The Forrester Wave™
Blogs Blog Flashpoint Named A Customer Favorite in The Forrester Wave In this blog we explore the recently published Forrester Wave: External Threat Intelligence Service…
-
AI Security via HIPAA Journal
Free Webinar: Is AI Putting Your Practice at Risk?
AI tools are already in your practice. The question is whether you know about it and whether they are HIPAA compliant. Most practices are using AI in some form already…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a…
-
AI Security via Adversa AI
Why vibe coding security is the next enterprise nightmare
Vibe coding is democratizing software development, but it is also creating a massive shadow AI attack surface. Security teams cannot rely on bans to address this risk…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
-
AI Security via Microsoft Security Response Center
CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
