Latest news

  1. AI Security via Sonar

    AGENTS.md is a workaround, not a solution

    AGENTS.md has won the fight to become the standard place to brief a coding agent, and deservedly so.

  2. AI Security via Sonar

    Sonar Supports OpenAI’s Call for Collective Action on Cyber Defense

    The window to strengthen cyber defense is narrowing, as advanced AI models compress the time between vulnerability disclosure and exploitation from months to minutes…

  3. Ransomware via Huntress

    How Attackers Abuse VSS, and How Huntress Detects It

    Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.

  4. Threat Intel via SOCRadar

    VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch

    VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built…

  5. via Infosecurity Magazine

    Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

    MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military

  6. Breaches via Check Point Research

    14th September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US…

  7. Vulnerabilities via CISA

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email…

  8. Breaches via Infosecurity Magazine

    Revolut Confirms Data Breach Through Fake Government Requests

    An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data

  9. Breaches via Malwarebytes Labs

    Revolut gave customer IDs and financial data to a government impostor

    Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an…

  10. Vulnerabilities via Schneier on Security

    Microsoft’s Patching

    Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record number of…

  11. AI Security via Wired

    Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe

    An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.

  12. Vulnerabilities via Rapid7

    CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

    OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses…

  13. AI Security via Palo Alto Networks Unit 42

    Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

    We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.

  14. Vulnerabilities via Infosecurity Magazine

    Hackers Exploit Maximum Severity Flaw in GitLab

    CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0

  15. Breaches via SOCRadar

    UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, and Ghorer Bazar

    UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, and Ghorer Bazar SOCRadar Dark Web Team identified several new underground posts, including an…

  16. Vulnerabilities via NCSC-NL

    NCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azure

    Microsoft heeft 4 kwetsbaarheden verholpen in diverse Azure componenten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden…

  17. Vulnerabilities via SOCRadar

    GitLab CVE-2026-85706 Added to CISA KEV

    GitLab CVE-2026-85706 Added to CISA KEV CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve…

  18. Vulnerabilities via Malwarebytes Labs

    A week in security (September 7 – September 13)

    Here’s what we’ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware…

  19. Vulnerabilities via Adversa AI

    What is an agent harness (and how do you secure one)?

    An agent harness turns a language model into an agent: loop, tools, context, approvals, sandbox. Nearly every agent vulnerability we have published lives there.

  20. Threat Intel via Group-IB

    Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

    A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket…