Latest stories — Page 100

Illustration: a server room corridor at night
AI Security

OpenAI's Lockdown Mode Admits the Problem It Can't Quite Fix

The new containment feature reduces AI-enabled data exfiltration but doesn't stop it. Experts are divided on whether enterprises should trust a vendor to police itself.

3 min read
Illustration: A large dark server room filled with rows of blinking rack servers
AI Security

12 Questions That Expose Whether Your Security Program Is Actually Working

Hard questions CISOs should already be asking, about blast radius, nonhuman identities, and whether vibe coding has eaten your attack surface.

3 min read
Illustration: an empty modern law-firm reception desk at dusk
Threat Intelligence

UNC3753 Hit U.S. Professional Services Firms With Vishing and Walk-In Intrusions

Dozens of legal and financial firms were hit between January and May 2026 in a data-theft extortion campaign that blended phone-based social engineering with physical office visits.

3 min read
Illustration: a developer workstation with a glowing monitor showing abstract blue code editor panels
Vulnerabilities

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft

A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

3 min read
Illustration: a dense terminal window on a dark monitor showing scrolling C code and crash backtraces
Vulnerabilities

FFmpeg Gets 21 New Bugs from an AI Fuzzer; Chrome 149 Ships a Record 429 Fixes

An autonomous agent dug up zero-days in the codec library that ships in everything. Google's browser shipped its largest single security release on record. Same week.

3 min read
Illustration: a dark server room with cascading green code reflections on glass partitions
Threat Intelligence

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected

The campaign tracked publicly as Miasma propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

3 min read
Illustration: a generic Android-
Threat Intelligence

Asin Android Spyware Surfaces in Arabic-Language Lures, ESET Says

ESET ties early-2025 campaigns to decoy sites posing as utilities, war-tracking tools and a fake government news portal.

3 min read
Illustration: a glowing laptop screen showing an abstract WordPress-
Vulnerabilities

Everest Forms Pro RCE Under Active Exploitation on WordPress Sites

CVE-2026-3300 carries a 9.8 CVSS. Attackers are using it to take over sites running unpatched versions of the premium form-builder plugin.

3 min read
Illustration: A dark underground marketplace bustling with AI tools being exchanged between anonymous figures
Ransomware

AI Tools Surge in Ransomware Markets, Lowering Entry Barriers

Underground markets are booming with AI-driven tools that put ransomware within reach of almost anyone with a credit card.

3 min read
Illustration: Macro close-up of dense copper server rack wiring and port arrays
Vulnerabilities

HTTP/2 Bomb: A Decade-Old Compression Trick Finally Gets a CVE

A chained HPACK attack lets small packets force runaway memory allocation on nginx, Apache, IIS, Envoy and Cloudflare's Pingora. Patches are partial. Exposure is wide.

3 min read
Illustration: a dense server rack backplane with hundreds of glowing fiber optic connectors in cool blue and amber
Identity & Access

$7M Says Autonomous Agents Can Fix the Identity Sprawl Problem

Offroad exits stealth with a bet that AI-driven security agents can manage what platform teams stopped being able to track manually, machine identities, third-party app permissions, and the rest of the non-human identity mess.

3 min read
Illustration: a circuit board with glowing green data pathways running across its surface
AI Security

Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field

CVE-2026-4372 lets an attacker own any machine that loads a poisoned model. No warnings, no prompts, no trace. The trust_remote_code flag turned out to be decorative.

3 min read
Illustration: a dimly lit e-commerce warehouse server rack with a single red status LED glowing
Vulnerabilities

CISA Flags Magento Cache Extension Bug as Actively Exploited

CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

3 min read
Illustration: a modern computer server room, with glowing monitors displaying complex data visualizations
AI Security

Unpacking the 'Son of Mythos': AI's Role in Vulnerability Discovery

Anthropic and OpenAI are widening access to frontier AI vulnerability tools. Security experts say the harder question isn't whether to use them.

3 min read
Illustration: a fuel storage tank farm at dusk, large white cylindrical tanks with catwalks and piping
Threat Intelligence

Feds Sound Alarm on Exposed Fuel Tank Gauges as Hackers Probe Critical Infrastructure

CISA, the FBI, NSA and DOE warn that internet-facing ATG systems at fuel depots, hospitals and military sites are being scanned and hit. The fix is mostly operator hygiene.

3 min read
Illustration: A close-up, macro
Vulnerabilities

Privilege Escalation Attacks Hit Kirki and Burst Statistics WordPress Plugins

Threat actors are actively exploiting flaws in two widely-used WordPress plugins to grab admin access and seize site control.

2 min read
Illustration: A vast server room at night, rows of illuminated rack hardware stretching to a vanishing point
AI Security

Agentic AI Is Doing What a Thousand Breach Reports Couldn't: Getting Boards to Open the Checkbook

Autonomous agents, AI-generated code, and frontier models capable of offensive cyber ops are finally making cybersecurity a board-level business conversation, not just an IT line item.

3 min read
Illustration: a modern black IP conference phone sitting on a polished corporate boardroom table
Vulnerabilities

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed

A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root and a front-row seat to every executive call.

3 min read
Illustration: a generic unbranded smartphone on a dark slate surface
Vulnerabilities

Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited

CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

3 min read
Illustration: a darkened workstation desk with an open laptop showing an abstract file archive extraction interface glowing
Threat Intelligence

Gamaredon Keeps Riding the WinRAR Path-Traversal Bug Into Ukrainian Endpoints

CVE-2025-8088 is months old and patched. The Russian crew is still landing GammaPhish, GammaWorm, and GammaSteel with it.

3 min read
Illustration: a dimly lit server rack with amber warning LEDs blinking
Opinion

The Patch Window Is Now Measured in Hours

AI-assisted exploit development has collapsed the time between disclosure and mass exploitation. Traditional vulnerability management workflows weren't built for this pace.

3 min read
© 2026 Threat Vectr