Latest stories — Page 101

Illustration: a darkened data center aisle with a single network firewall appliance illuminated by a red status LED
Vulnerabilities

Palo Alto GlobalProtect Auth Bypass Hits Live Exploitation

CVE-2026-0257 lets attackers stand up unauthorized VPN sessions against PAN-OS and Prisma Access. Patches are out. So are the exploits.

3 min read
Illustration: A wide server room corridor at night, bathed in cool blue and amber warning lights
Policy & Regulation

India Sets a 12-Hour Clock on Exploited Vulnerabilities. Can Enterprises Actually Do It?

CERT-In's new AI-threat framework resets expectations around patch velocity, but the real test is whether organizations even know what's exposed.

3 min read
Illustration: a dimly lit operations center at night, blue and amber monitor glow
Threat Intelligence

GREYVIBE: New Russian-Speaking Cluster Tied to Sustained Operations Against Ukraine

Researchers attribute an August 2025 campaign wave to a previously undocumented actor whose tasking patterns align with Kremlin interests.

3 min read
Illustration: AI-driven cyber operations visual, depicting autonomous systems in a digital landscape
AI Security

AI in Cyber Operations: From Scripts to Autonomous Systems

AI's role in cyber operations is not just about speed anymore. It's about scale and autonomy, reshaping offensive capabilities.

2 min read
Illustration: a double helix DNA strand rendered in cool blue light inside a cracked glass display case, dark background
Policy & Regulation

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach

AG Rob Bonta is going after Chrome Holding Co., the shell 23andMe rebranded into after its bankruptcy, arguing the company failed to adequately protect the genetic and personal data of millions of users.

2 min read
Illustration: a dimly lit corporate legal office at dusk
Policy & Regulation

Microsoft Reasserts Coordinated Disclosure Norms After Researcher Drops Zero-Days

Redmond is invoking CVD principles after a researcher publicly posted unpatched flaws, raising fresh questions about the boundary between disclosure ethics and platform enforcement.

3 min read
Illustration: a glowing server rack in a dark data center
Vulnerabilities

FortiClient EMS Flaw Sees Fresh Exploitation After April Hotfix

Attackers are still hitting a critical FortiClient EMS vulnerability that Fortinet patched, and flagged as actively exploited, months ago.

2 min read
Illustration: a green circuit board with glowing amber trace lines branching unpredictably away from a central node
AI Security

French Startup Edamame Builds Runtime Watch for AI Coding Agents

The platform uses host telemetry and AI analysis to flag intent drift, secret theft, and supply-chain interference in real time, before the damage lands.

3 min read
Illustration: A digital landscape depicting AI-driven cyber threats
AI Security

Exploitation Industrialized: Navigating the New AI Battlefield

AI-driven attacks are rewriting the economics of exploitation. Defenders who know their own environment still have a structural edge, but only if they use it.

3 min read
Illustration: AI-driven cyber attack visualization
Threat Intelligence

The Bot That Learned to Lie: Inside the New Generation of AI-Driven DDoS

Defenders describe attack waves that pause, study traffic patterns, and resume from fresh infrastructure, behavior that looks less like a script and more like a sparring partner.

3 min read
Illustration: AI-driven DDoS attacks, showing AI algorithms targeting a network
Policy & Regulation

Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules

Machine-learning-driven flood attacks are adapting mid-stream to evade filters, and existing incident-reporting frameworks weren't written with that in mind.

3 min read
Illustration: A digital shield protecting a SharePoint server
Vulnerabilities

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork

CVE-2026-45659 is a deserialization flaw that doesn't ask for much, and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

2 min read
Illustration: A digital battlefield with identity as the central focus
Identity & Access

The Perimeter Is Gone. Attackers Already Knew That.

Modern intrusions rarely crack the wall. They walk through the front door, wearing your credentials.

3 min read
Illustration: a phishing attack targeting Microsoft 365 users, showing a hacker bypassing security measures
Identity & Access

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA

The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

3 min read
Illustration: A CISO facing a decision of whether to pay a ransom, with digital locks and keys symbolizing cybersecurity
Ransomware

More Than Half of CISOs Would Pay a Ransomware Demand. The Maths Are Not Flattering.

A survey of 750 CISOs in the US and UK finds 58% would hand over money to ransomware operators, despite law enforcement advice, incomplete decryption rates, and the lingering question of whether the data stays exclusive.

3 min read
Illustration: AI scanning for software vulnerabilities
AI Security

Ten Thousand Bugs, One Model: Inside Anthropic's Project Glasswing

Claude Mythos Preview has scanned more than 1,000 open-source projects and surfaced thousands of critical flaws. The bottleneck has moved, and the patch queue is not moving fast enough.

4 min read
Illustration: A digital lock symbol over a network diagram, representing cybersecurity
Vulnerabilities

Cisco's Secure Workload Earns a Perfect 10, in the Wrong Sense

An unauthenticated REST API flaw rated CVSS 10.0 lets remote attackers reach sensitive data. Cisco has issued fixes.

2 min read
Illustration: a hacker exploiting a Windows driver without hardware, with a focus on code interaction diagrams
Vulnerabilities

When the Hardware Isn't There: Coaxing Vulnerable Drivers Into Range

BYOVD research keeps colliding with a stubborn problem, many kernel drivers refuse to talk unless their device is plugged in. New work shows how to make them talk anyway.

3 min read
Illustration: A digital representation of a botnet network with police arrest imagery in the background
Policy & Regulation

Justice Department Charges Ottawa Man With Operating Kimwolf DDoS Botnet

Federal prosecutors say Jacob Butler, 23, developed and rented out a variant of the AISURU botnet for paid denial-of-service attacks.

3 min read
Illustration: A computer server with a warning sign indicating a critical vulnerability
Vulnerabilities

LiteSpeed cPanel Plugin Flaw Hands Root to Any Logged-In User, and the Vendor Won't Say How Many Hosts Are Hit

CVE-2026-48172 carries a CVSS of 10.0, is already being exploited, and LiteSpeed has not answered three questions about exploitation telemetry.

3 min read
Illustration: An AI scanning software code for vulnerabilities
AI Security

Anthropic Says Project Glasswing AI Has Flagged 10,000 High-Severity Bugs in a Month

The Claude-based scanner has been pointed at widely deployed open-source code since October. Anthropic has not named the affected projects.

3 min read
© 2026 Threat Vectr