Latest stories — Page 100

OpenAI's Lockdown Mode Admits the Problem It Can't Quite Fix
The new containment feature reduces AI-enabled data exfiltration but doesn't stop it. Experts are divided on whether enterprises should trust a vendor to police itself.

12 Questions That Expose Whether Your Security Program Is Actually Working
Hard questions CISOs should already be asking, about blast radius, nonhuman identities, and whether vibe coding has eaten your attack surface.

UNC3753 Hit U.S. Professional Services Firms With Vishing and Walk-In Intrusions
Dozens of legal and financial firms were hit between January and May 2026 in a data-theft extortion campaign that blended phone-based social engineering with physical office visits.

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft
A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

FFmpeg Gets 21 New Bugs from an AI Fuzzer; Chrome 149 Ships a Record 429 Fixes
An autonomous agent dug up zero-days in the codec library that ships in everything. Google's browser shipped its largest single security release on record. Same week.

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected
The campaign tracked publicly as Miasma propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

Asin Android Spyware Surfaces in Arabic-Language Lures, ESET Says
ESET ties early-2025 campaigns to decoy sites posing as utilities, war-tracking tools and a fake government news portal.

Everest Forms Pro RCE Under Active Exploitation on WordPress Sites
CVE-2026-3300 carries a 9.8 CVSS. Attackers are using it to take over sites running unpatched versions of the premium form-builder plugin.

AI Tools Surge in Ransomware Markets, Lowering Entry Barriers
Underground markets are booming with AI-driven tools that put ransomware within reach of almost anyone with a credit card.

HTTP/2 Bomb: A Decade-Old Compression Trick Finally Gets a CVE
A chained HPACK attack lets small packets force runaway memory allocation on nginx, Apache, IIS, Envoy and Cloudflare's Pingora. Patches are partial. Exposure is wide.

$7M Says Autonomous Agents Can Fix the Identity Sprawl Problem
Offroad exits stealth with a bet that AI-driven security agents can manage what platform teams stopped being able to track manually, machine identities, third-party app permissions, and the rest of the non-human identity mess.

Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field
CVE-2026-4372 lets an attacker own any machine that loads a poisoned model. No warnings, no prompts, no trace. The trust_remote_code flag turned out to be decorative.

CISA Flags Magento Cache Extension Bug as Actively Exploited
CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

Unpacking the 'Son of Mythos': AI's Role in Vulnerability Discovery
Anthropic and OpenAI are widening access to frontier AI vulnerability tools. Security experts say the harder question isn't whether to use them.

Feds Sound Alarm on Exposed Fuel Tank Gauges as Hackers Probe Critical Infrastructure
CISA, the FBI, NSA and DOE warn that internet-facing ATG systems at fuel depots, hospitals and military sites are being scanned and hit. The fix is mostly operator hygiene.

Privilege Escalation Attacks Hit Kirki and Burst Statistics WordPress Plugins
Threat actors are actively exploiting flaws in two widely-used WordPress plugins to grab admin access and seize site control.

Agentic AI Is Doing What a Thousand Breach Reports Couldn't: Getting Boards to Open the Checkbook
Autonomous agents, AI-generated code, and frontier models capable of offensive cyber ops are finally making cybersecurity a board-level business conversation, not just an IT line item.

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed
A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root and a front-row seat to every executive call.

Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited
CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

Gamaredon Keeps Riding the WinRAR Path-Traversal Bug Into Ukrainian Endpoints
CVE-2025-8088 is months old and patched. The Russian crew is still landing GammaPhish, GammaWorm, and GammaSteel with it.

The Patch Window Is Now Measured in Hours
AI-assisted exploit development has collapsed the time between disclosure and mass exploitation. Traditional vulnerability management workflows weren't built for this pace.