Latest news
-
AI Security via Sonar
AGENTS.md is a workaround, not a solution
AGENTS.md has won the fight to become the standard place to brief a coding agent, and deservedly so.
-
AI Security via Sonar
Sonar Supports OpenAI’s Call for Collective Action on Cyber Defense
The window to strengthen cyber defense is narrowing, as advanced AI models compress the time between vulnerability disclosure and exploitation from months to minutes…
-
Ransomware via Huntress
How Attackers Abuse VSS, and How Huntress Detects It
Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
-
Threat Intel via SOCRadar
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built…
-
via Infosecurity Magazine
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military
-
Breaches via Check Point Research
14th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US…
-
Vulnerabilities via CISA
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email…
-
Breaches via Infosecurity Magazine
Revolut Confirms Data Breach Through Fake Government Requests
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
-
Breaches via Malwarebytes Labs
Revolut gave customer IDs and financial data to a government impostor
Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an…
-
Vulnerabilities via Schneier on Security
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record number of…
-
AI Security via Wired
Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.
-
Vulnerabilities via Rapid7
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses…
-
AI Security via Palo Alto Networks Unit 42
Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
-
Vulnerabilities via Infosecurity Magazine
Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
-
Breaches via SOCRadar
UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, and Ghorer Bazar
UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, and Ghorer Bazar SOCRadar Dark Web Team identified several new underground posts, including an…
-
Vulnerabilities via NCSC-NL
NCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azure
Microsoft heeft 4 kwetsbaarheden verholpen in diverse Azure componenten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden…
-
Vulnerabilities via SOCRadar
GitLab CVE-2026-85706 Added to CISA KEV
GitLab CVE-2026-85706 Added to CISA KEV CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve…
-
Vulnerabilities via Malwarebytes Labs
A week in security (September 7 – September 13)
Here’s what we’ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware…
-
Vulnerabilities via Adversa AI
What is an agent harness (and how do you secure one)?
An agent harness turns a language model into an agent: loop, tools, context, approvals, sandbox. Nearly every agent vulnerability we have published lives there.
-
Threat Intel via Group-IB
Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit
A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket…
