Latest stories — Page 71

Threat Intelligence

Week in Brief: Russia's Cellebrite Use, Five Eyes AI Warning, macOS Backdoor, Scattered Spider Pleas

Four stories that deserved more attention: state-backed mobile forensics against activists, an intelligence alliance's AI threat advisory, a new Mac implant, and a high-profile cybercrime case moving toward resolution.

2 min read
Vulnerabilities

Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP

A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.

2 min read
Identity & Access

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed

The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

2 min read
Vulnerabilities

Linux act_pedit OOB Write Poisons Page Cache, Hands Local Users Root

CVE-2026-46331 weaponizes a traffic-control bug to overwrite cached binaries. Working PoC dropped a day after disclosure.

2 min read
Vulnerabilities

PTC Windchill RCE Lands on CISA's KEV After Web Shells Show Up in the Wild

A pre-auth code execution bug in PTC's PLM stack is being actively exploited. If you run Windchill or FlexPLM, the patch clock started a while ago.

2 min read
Vulnerabilities

DirtyClone: New DirtyFrag-Family Kernel Bug Hands Local Users Root

CVE-2026-43503 (CVSS 8.8) corrupts file-backed memory through a cloned skb. A working PoC is now public.

3 min read
Identity & Access

Guardian Agents and the Identity Layer That Doesn't Exist Yet

Autonomous agents are inheriting human permissions at machine speed. The IAM stack wasn't built for this, and the governance gap is widening.

3 min read
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again — abusing GitHub Actions workflows and now reaching Go modules.

2 min read
Policy & Regulation

Zero Trust in OT: A Pragmatic 90-Day Action Plan

Aligning zero trust architecture with operational technology environments through a strategic, actionable 90-day plan.

2 min read
Threat Intelligence

Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant

Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.

3 min read
AI Security

Frontier AI Is a Pressure Test, Not a New Threat Model

The arrival of capable AI models like Mythos changes attacker economics. It doesn't change which controls actually matter — and most organizations are still failing the old ones.

3 min read
Policy & Regulation

Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt

Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.

3 min read
Threat Intelligence

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome

Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

2 min read
AI Security

MCP's Enterprise Overhaul Hands Security Problems to Developers

A major revision to the Model Context Protocol repositions itself as enterprise-ready — then quietly offloads the hard security work onto the teams building on top of it.

3 min read
Policy & Regulation

GDPR Turns Ten: A Decade of Fines, Frustration, and Unfinished Business

Six billion euros in penalties later, Europe's data regulation has reshaped corporate behavior — and created a compliance burden that companies say is quietly strangling AI development on the continent.

2 min read
Identity & Access

Philip Martin Takes the CISO Chair at Uber

The former Coinbase security chief steps into one of tech's more scrutinised security roles, bringing a résumé that spans crypto, defence contracting, and cloud infrastructure.

2 min read
Policy & Regulation

ICS Security's 25-Year Reunion Is Headed to Nashville

The Industrial Control Systems Cybersecurity Conference marks a quarter-century in October 2026, touching down at the W Nashville for three days of OT threat intelligence.

2 min read
Threat Intelligence

Featured Chrome Ad Blocker with 10M+ Installs Carries Dormant JS Injection Capability

Researchers flagged a Featured-badge extension that can pull and execute remote JavaScript — a capability common to supply-chain abuse clusters tracked across the Chrome Web Store.

2 min read
Threat Intelligence

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective — and that's the problem.

2 min read
Identity & Access

Account Takeovers Still Outrunning Detection, Vendors Push Behavioral AI as Answer

Compromised credentials remain the cheapest entry point on criminal marketplaces. A new webinar argues behavioral models, not static rules, are the only way to close the gap.

2 min read
Threat Intelligence

Iranian Group Handala Claimed It Could Poison California's Water. Forensics Say Otherwise.

California Water Service brought in Mandiant after Handala threatened disruption. Investigators found no evidence the group ever touched operational technology.

2 min read
© 2026 Threat Vectr