Latest stories — Page 76

Threat Intelligence

Anonymized Infrastructure Now Touches 94% of Incidents, and Most SOCs Are Still Playing Catch-Up

Survey data points to a persistent gap between IP enrichment volume and the analyst's ability to answer a simple question: who's actually on the other end?

2 min read
Policy & Regulation

CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw

CVE-2026-54420 lands on the KEV catalog, triggering a BOD 22-01 remediation clock for federal civilian agencies.

2 min read
Threat Intelligence

SprySOCKS Crosses Over: Windows Variants Surface With Driver-Level Hiding

Two undocumented Windows builds of the China-linked backdoor — tagged WIN_DRV and WIN_PLUS — extend a toolset previously seen only on Linux.

2 min read
Vulnerabilities

Three FortiSandbox Bugs Under Active Exploitation, Including a 9.1 Path Traversal

Threat intel firm flags in-the-wild abuse of CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089 within a 24-hour window.

2 min read
Vulnerabilities

Cisco's SD-WAN Manager Has a Write-to-Root Problem — and Attackers Found It First

CVE-2026-20262 lets an authenticated attacker overwrite arbitrary files on Cisco Catalyst SD-WAN Manager, with a clear path to root. No workaround exists. Exploitation is already underway.

2 min read
Policy & Regulation

Security Executives Push Back on Anthropic Export Restrictions

A coalition of cybersecurity leaders argues that blocking foreign nationals from accessing Anthropic's latest models hands adversaries a strategic gift.

2 min read
Vulnerabilities

Twenty-Five Orgs Are Quietly Triaging Open-Source Vulns Before You Hear About Them

A coalition called Athena is building shared infrastructure to find, fix, and harden OSS projects in the window between discovery and public disclosure.

2 min read
Identity & Access

Zero Trust Turns 15 and Still Can't Get Out of Its Own Way

The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.

3 min read
Threat Intelligence

ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert

APT37's spear-phish leans on the oldest trick in the identity playbook: tell the user their account is at risk, then hand them the payload.

2 min read
Vulnerabilities

CISA Adds LiteSpeed cPanel Plugin Bug to KEV After In-the-Wild Exploitation

CVE-2026-54420 (CVSS 8.5) lets attackers escalate to root on hosts running the LiteSpeed cPanel plugin. Federal agencies have until June 18, 2026 to patch.

3 min read
Vulnerabilities

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse

CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

2 min read
Policy & Regulation

Feds Pull the Plug on CFAKE and SOCFAKE in First TAKE IT DOWN Act Domain Grab

DOJ seizes two deepfake nude sites that pulled tens of millions of visits a month, marking the first public test of the new federal statute.

2 min read
Threat Intelligence

China-Nexus Crew Burrowed Into REDCap, Turned Google Workspace Rules Into an Exfil Pipe

A 13-plus-month intrusion across medical, academic, and defense research networks abused victim-side mail forwarding instead of dropping noisy C2.

2 min read
Threat Intelligence

Contagious Interview Pivots to Dev-Review Lures in Two Fresh Campaigns

The North Korea-linked cluster is back with phishing pretexts aimed at developers — recruiter pitches and code-review requests that drop malware on engineers' workstations.

3 min read
AI Security

Three-Bug Chain Turns Any LiteLLM User Into Root on the AI Gateway

A default low-privilege account on the popular open-source LLM proxy can escalate to admin and execute code, exposing every provider key the gateway holds.

2 min read
AI Security

SearchLeak: How a microsoft.com Link Could Have Drained a Copilot Tenant

Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfil path that lived behind a trusted Microsoft URL.

2 min read
Vulnerabilities

Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass

Another seven days of rented phishing kits, AI-themed lures, and forgotten software paying out as initial access.

3 min read
AI Security

Langflow's Unauthenticated File-Write Flaw Is Being Exploited — Patch Dropped 73 Days Ago

CVE-2026-5027 lets attackers write files to arbitrary paths on exposed servers, and because Langflow ships with login disabled by default, exploitation requires exactly zero credentials.

3 min read
AI Security

Poisoned Documents Can Freeze AI Agent Guardrails Dead in Their Tracks

Researchers found that a single malicious input can trap reasoning-based safety systems in extended thinking loops, slowing LangGraph deployments by 148x and starving co-located agents of resources.

2 min read
Identity & Access

Behavioral AI Pitched as Triage Layer for Phishing and ATO Floods

A vendor webinar argues that pattern-learning models can cut investigation time on BEC and account takeover incidents. The harder question: what does that mean for breach-notification timelines?

3 min read
Identity & Access

First-Day Passwords Are Still IAM's Soft Underbelly

Temporary onboarding credentials keep showing up in breach forensics. The problem isn't laziness — it's that most IT teams never actually defined what 'temporary' means.

2 min read
© 2026 Threat Vectr