Latest stories — Page 80

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

AudiA6 Crypto Laundromat Pulled Offline After Washing €336M for Ransomware Crews
Europol says the takedown severs a major cash-out pipeline tied to ransomware payouts and underground markets.

Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift
NIST published its first three post-quantum standards in 2024. A year later, only 5% of security teams have a defined strategy. The clock is running whether they know it or not.

ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch
Mandiant ties a two-week extortion spree against Oracle PeopleSoft deployments to UNC6240, the cluster better known as ShinyHunters.

Langflow Path Traversal Flaw CVE-2026-5027 Hits CISA's Exploited List
An unauthenticated write-anywhere bug in the open-source AI builder is being abused in the wild, per VulnCheck telemetry, raising fresh questions for federal users bound by BOD 22-01 patch deadlines.

Researchers Turn OpenClaw Into a Confused Deputy With Hidden Prompts
Two teams show the self-hosted AI agent will execute attacker instructions smuggled inside contacts, location pins, and other benign-looking inputs.

GreatXML Bypasses BitLocker Through a Trusted Recovery Path
A researcher's four-hour weekend project shows how Windows' own offline scan plumbing can sidestep full-disk encryption.

The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents coughing up credentials — the criminal stack is industrialising.

The Gentlemen: A RaaS Affiliate That Grew Up and Wrote Its Own Worm
A double-extortion crew that started out renting LockBit, Qilin, and Medusa lockers has graduated to its own toolkit — including a payload with self-propagation.

ServiceNow's Unauthenticated API Endpoint Left Tenant Data Exposed for Months
An API resource shipped with authentication disabled by default. Now enterprises are asking whether the 'security researcher' explanation fully covers what got accessed.

The Week Identity Attacks Started Looking Like SaaS
Worm kits in public repos, a subscription RAT that clones live browser sessions, and AI agents that hand over credentials when asked nicely.

The 2026 Cybersecurity Stars Awards Land — 95 Categories, One Long Trophy Table
An industry awards program names winners across product, team, and company categories. The interesting question is what — if anything — the list tells us about where defenders are actually winning.

The Alert Queue Is Full. So Is the Graveyard of Missed Threats.
When every event screams critical, nothing is. AI and automation are being drafted to fix a triage problem that human analysts simply can't outrun anymore.

Oracle Patches PeopleSoft Flaw Tied to ShinyHunters Activity, Stays Quiet on Zero-Day Status
CVE-2026-35273 has a fix. Whether attackers got there first is a question Oracle isn't answering.

CISA's New Directive: Agencies Must Prioritize High-Risk Security Patches
Federal agencies get their marching orders: focus on Known Exploited Vulnerabilities.

OnyxC2 Stealer: $250/Month Buys You Encrypted Payloads and 200+ App Targets
A commodity infostealer is punching well above its price point. OnyxC2 brings DLL sideloading and in-memory execution to anyone with a credit card.

South Korea Fines Coupang ₩624.6 Billion Over 37M-Record Breach
The PIPC's record penalty under PIPA cites failures in access control and insider-threat monitoring tied to a 2024 intrusion attributed to a former contractor.

The Patch Window Is Closed: Why CISOs Are Quietly Reallocating to BAS
Vulnerability management was built around a buffer between disclosure and weaponization. Generative tooling is collapsing that buffer, and breach-and-attack simulation budgets are absorbing the panic.

FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel
The seized domains posed as consulting firms advertising jobs — a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.

OceanLotus Turns SPECTRALVIPER on Vietnamese Investors and a Construction Firm
Two campaigns, one toolset. The Vietnam-aligned crew spent eighteen months inside a state-linked infrastructure builder before pivoting to a supply chain hit on retail stock investors.

Six Things SRE Teams Demand Before Handing Anything to an AI Agent
Observability gaps, missing guardrails, and opaque reasoning are the real blockers — not the AI itself.