Latest from todayDefCon security conference bans smart glasses with recording capabilitiesSmart eyewear users will be strictly monitored.By Maxwell CooterJul 31, 20262 minsData PrivacyData and Information SecurityPrivacy Google adds to confusion with new names for threat actorsBy Maxwell CooterJul 31, 20262 minsAnti MalwareSecuritySecurity Software Broadcom patches vulnerabilities all over VMwareBy Maxwell CooterJul 31, 20262 minsCloud SecuritySecurityMicrosoft almost gave away the keys to everyone’s Azure Cosmos DBsBy Maxwell Cooter Jul 31, 20262 minsCloud SecuritySecurity JetBrains says a crafted HTTP request could break TeamCityBy Shweta Sharma Jul 31, 20263 minsSecurityVulnerabilities After OpenAI, Anthropic finds Claude breached three organizations during cyber testsBy Gyana Swain Jul 31, 20266 minsArtificial IntelligenceCyberattacksIT Governance Copilot worm can spread through Microsoft Word docsBy Evan Schuman Jul 30, 202610 minsCyberattacksCybercrimeVulnerabilities A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?By Cynthia Brumfield Jul 30, 20268 minsCritical InfrastructureSecurity AI agents gain access to financial workflows amid growing governance gapsBy Shweta Sharma Jul 30, 20263 minsApplication SecurityArtificial IntelligenceIT Governance Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge Researchers say an unauthenticated vulnerability enables code execution, credential theft, AI memory poisoning, and persistent compromise. By Gyana Swain Jul 30, 2026 5 mins Artificial Intelligence Security Vulnerabilities Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover The OWAReaper implant can establish server-side mailbox permissions that remain after credentials are changed and affected devices are rebuilt. By Prasanth Aby Thomas Jul 30, 2026 4 mins Security Vulnerabilities A Scattered Spider member was indicted. Microsoft’s GDID went to trial. Investigators’ use of a little-known Windows device identifier to take down an alleged cybercriminal has raised privacy and transparency concerns about Microsoft telemetry. By John Leyden Jul 30, 2026 6 mins Cybercrime Privacy Windows Security CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks A new guide from CISA and allied cybersecurity agencies says organizations should build dedicated isolation points into operational technology to contain attacks and continue delivering essential services. By Taryn Plumb Jul 29, 2026 7 mins Critical Infrastructure Cyberattacks Cybercrime Mythos takes its first shot at post-quantum cryptography Anthropic’s Mythos AI model has helped discover two new cryptanalytic attacks, one against the NIST post-quantum digital signature candidate Hawk, and one against a weakened version of AES; neither threatens deployed technology. By Shweta Sharma Jul 29, 2026 4 mins Artificial Intelligence Data and Information Security Encryption OpenAI rogue AI agent’s attack expanded beyond Hugging Face Technical disclosures from Hugging Face, JFrog, and the Cloud Security Alliance show how the autonomous AI agent crossed multiple trust boundaries. By Gyana Swain Jul 29, 2026 5 mins Artificial Intelligence Security Vulnerabilities Ransomware report: VPNs in the crosshairs, AI attacks A roundup of recent ransomware trends, threat actor activity, and industries at risk. By CSO Staff Jul 29, 2026 4 mins Cybercrime Malware Ransomware Fortinet’s new FortiGate platform converges firewall, SASE technologies New FortiGate 1200G series with FortiSASE Outpost brings threat protection and cloud-delivered SASE to on-premises environments. By Michael Cooney Jul 28, 2026 2 mins Cloud Security Network Security Security A 13-year-old flaw is exposing tens of thousands of data center management systems Lava researchers found more than 36,000 internet-exposed baseboard management controllers vulnerable to a 13-year-old IPMI flaw, giving attackers a path beneath the operating system. By Taryn Plumb Jul 28, 2026 6 mins Business Enterprise Vulnerabilities Arista patches maximum severity vulnerability that is already being exploited The vendor said that the problematic VeloCloud Orchestrator functionality was ‘intended to be for internal use only.’ Analysts stress that intent is not enough. By Evan Schuman Jul 28, 2026 6 mins Network Security Security Vulnerabilities Infoblox joins crowded EASM market with DNS-centric approach The company is combining DNS expertise with external attack surface management and supply chain intelligence to help organizations identify exploitable internet-facing assets before attackers do. By Shweta Sharma Jul 28, 2026 3 mins Security Security Software Hugging Face breach shows why incident response needs a multi-model AI strategy Frontier AI model safety guardrails impeded Hugging Face’s analysis of attack evidence, forcing it to rely on an open-weight model for incident response instead. By Lucian Constantin Jul 28, 2026 9 mins Incident Response Security Infrastructure Security Operations Center Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts By compromising captive Wi-Fi gateways instead of user devices, attackers can silently redirect authentication traffic and steal Microsoft 365 credentials. By Taryn Plumb Jul 27, 2026 6 mins Cyberattacks Hacking Wireless Security Microsoft unveils multi-model agentic cyber stack for security operations Building on Microsoft’s extensive threat intelligence, security telemetry, and knowledge of customer environments, Project Perception’s specialized red, blue, and green team agents execute specialized playbooks to evaluate and update your security po By Lucian Constantin Jul 27, 2026 6 mins Application Security Security Infrastructure Security Operations Center Samsung’s AI-powered glasses could be looking at your data The data leakage and privacy violation potential is obvious, but a meaningful fix is anything but. By Evan Schuman Jul 27, 2026 7 mins Compliance Data Privacy Privacy Certighost haunts Microsoft Active Directory Certificate Services The Certighost vulnerability exploits a little-known AD CS fallback mechanism to trick certificate authorities into issuing trusted credentials. By Shweta Sharma Jul 27, 2026 4 mins Security Vulnerabilities OpenAI not part of the new Open Secure AI Alliance A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defense. By Peter Sayer Jul 27, 2026 3 mins Artificial Intelligence Security Top AIs invent same fake PyPl and npm package names Research reveals that slopsquatting remains a threat to developers using AI to aid coding. By Maxwell Cooter Jul 24, 2026 2 mins Artificial Intelligence Code Security Development Tools Tycoon2FA takedown reshapes the phishing landscape Some of the most common phishing techniques are declining, but not because attackers are giving up. By Shweta Sharma Jul 24, 2026 4 mins Communications Security Email Security Phishing Ransomware groups are hammering your vulnerable VPNs Campaigns against flaws in security systems from Palo Alto, Fortinet, Citrix, and Check Point underscore a rising trend in how cybercriminals gain footholds in corporate networks. By John Leyden Jul 24, 2026 5 mins Cybercrime Malware Ransomware 12345678910…430 Show me morePopularArticlesPodcastsVideos opinion 5 key priorities for your Black Hat agenda — and what to avoid By Jon OltsikJul 31, 20266 mins Black HatEventsIT Strategy press release Sponsored by CyberNewsWire Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities By CyberNews WireJul 29, 20264 mins Artificial IntelligenceCyberattacksData and Information Security opinion It’s easier to steal cargo than toothpaste By Max GraupnerJul 29, 20267 mins CybercrimeHackingTransportation and Logistics Industry podcast Moving Beyond the Checkbox in Human Risk Management By Joan GoodchildJul 30, 20269 mins Cyberattacks podcast The Security Debt Crisis Inside AI-Generated Code By Joan GoodchildJul 20, 20268 mins Cybercrime podcast AI-Generated Code and the Expanding Application Security Challenge By Joan GoodchildJul 15, 202615 mins Cybercrime video Moving Beyond the Checkbox in Human Risk Management By Joan GoodchildJul 30, 20269 mins Cyberattacks video The Security Debt Crisis Inside AI-Generated Code By Joan GoodchildJul 20, 20268 mins Cyberattacks video AI-Generated Code and the Expanding Application Security Challenge By Joan GoodchildJul 15, 202615 mins Cybercrime