Latest stories — Page 72

AI Security

CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running

Boards want AI returns. Employees want access. Compliance teams want guardrails. The CIO is stuck in the middle of all three.

3 min read
Threat Intelligence

Mistic Backdoor Shows Up in IAB-Brokered Intrusions Across Four Verticals

A quiet new implant tied to the KongTuke access broker is landing on insurance, education, IT, and professional services networks — and it's not riding a CVE to get there.

3 min read
Policy & Regulation

Compliance Theatre Has a Reckoning Coming. FedRAMP 20x Is the Opening Act.

Most SOC 2 and ISO 27001 reports audit a curated version of history, not operational reality. A federal cloud-security overhaul is forcing the question nobody wanted to answer: does passing audits actually mean anything?

3 min read
Vulnerabilities

Cisco Catalyst SD-WAN Bug Hit as Zero-Day Months Before Disclosure

Mandiant says an unidentified actor exploited CVE-2026-20245 for at least two months before Cisco's public advisory, gaining root on affected appliances.

2 min read
Threat Intelligence

Mistic Backdoor Ties to IAB Selling Enterprise Footholds to Ransomware Gangs

A new in-memory backdoor named Mistic has been active since April, and the threat actor behind it has reportedly funneled access to Qilin, Akira, Black Basta, and others.

2 min read
Opinion

RSnake's Case for a CISO Code of Ethics

Robert Hansen argues that kickbacks, no-show jobs, and shelfware deals aren't just embarrassing — they're a national security problem.

2 min read
Vulnerabilities

CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug

CVE-2025-67038 carries a 9.8 CVSS. Federal agencies have until June 26, 2026 to patch — but if it's already being hit in the wild, that runway looks generous.

2 min read
AI Security

AI Agents Are Being Manipulated Through the Data They Trust

Hidden content injections and context poisoning are turning autonomous AI pipelines into attack surfaces. Here's what defenders need to understand before deploying agents at scale.

2 min read
Threat Intelligence

Operation Endgame Hits Amadey and StealC, Pulls 27M Credentials From Loader Infrastructure

Europol-led takedown dismantled command servers behind two of the most prolific malware-as-a-service loaders, with Microsoft, ESET, Bitdefender, and Bitsight providing technical support.

3 min read
Threat Intelligence

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC

Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

2 min read
AI Security

AIVEX Triage Model Targets Software Supply Chain Risk in AI Environments

A new framework aims to help security teams prioritize which supply chain vulnerabilities carry the highest operational, safety, and business risk where AI systems are in play.

2 min read
Identity & Access

The Service Desk Is the New Phishing Inbox

Help desks keep getting talked out of MFA resets. The fix is less about training and more about treating identity verification like an auth protocol.

3 min read
Vulnerabilities

Non-Admin macOS Accounts Can Chain Native OS Features to Blind Endpoint Security Tools

No exploit required. Researchers found that standard user privileges are enough to chain macOS weaknesses and silently kill endpoint security agents — no vulnerability needed.

2 min read
Vulnerabilities

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos

A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, researchers say.

2 min read
AI Security

Fake AI Agent Skill Exploits Security Gaps, Reaches 26,000 Users

A malicious AI agent skill bypassed security checks, exposing potential risks in enterprise environments.

2 min read
Opinion

The Patch Cycle Won't Survive Machine-Speed Adversaries

Defenders measured dwell time in days. Agentic attack pipelines are about to measure it in minutes.

3 min read
Identity & Access

Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months

Nathan Austad gets a year and a half in federal prison, plus $1.8 million in forfeiture and restitution, closing out the last of the DraftKings account-takeover prosecutions.

2 min read
AI Security

Agentic AI Runs on Context. Feed It the Wrong Kind and Decisions Go Sideways Fast.

The core vulnerability in agentic AI systems isn't the model — it's the context window. Bad inputs, machine-speed outputs.

2 min read
Vulnerabilities

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop

A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

2 min read
Policy & Regulation

DOJ Seizes HuiOne Cloud Account, Treasury Sanctions Prince Group Network

Cambodia-based conglomerates accused of laundering proceeds from pig-butchering and cyber-enabled fraud face coordinated U.S. action.

2 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

2 min read
© 2026 Threat Vectr