Latest stories — Page 81

JDY Botnet Turns 1,500 Compromised SOHO Devices Into a Nation-State Targeting Engine
Lumen's Black Lotus Labs links the scanning network to Volt Typhoon. The threat isn't the botnet itself — it's the reconnaissance data it harvests before you've even read the CVE advisory.

Frontier AI Models Transform Vulnerability Discovery
AI capabilities reshape cyber defense strategies, prompting new approaches to vulnerability management.

npm 12 Pulls the Plug on Install Scripts by Default
GitHub is finally turning off the lifecycle hook that's been quietly powering half a decade of supply chain attacks.

GitHub's npm Overhaul: No More Automatic Install Scripts
GitHub reshapes npm with default script blocking, aiming to tighten software supply chain security.

CISA's New Patching Directive Drops CVSS as the North Star
BOD 26-04 introduces a four-factor framework that prioritizes internet exposure, active exploitation, and attacker automation over raw severity scores — and gives agencies three days to act on the worst cases.

Ivanti Sentry Carries Two Critical Bugs — One a Perfect 10 — Enabling Full Appliance Takeover
A pair of unauthenticated flaws in the mobile gateway give attackers a clear path to root. Exploit code is already public.

JDY Botnet's Quiet Comeback: 1,500 SOHO and IoT Nodes Now Mapping the Internet
Researchers tie the reconstituted scanner network to China-nexus operators conducting persistent, large-scale reconnaissance against exposed services.

CISA Triggers Federal Patch Clock on Cisco, Chrome and Arista Bugs Under KEV
Three vulnerabilities added to the Known Exploited Vulnerabilities catalog activate BOD 22-01 remediation deadlines for civilian agencies.

Langflow Path Traversal Under Active Exploitation, No Patch Available
CVE-2026-5027 lets unauthenticated attackers write arbitrary files on Langflow servers. In-the-wild exploitation is being tracked now.

Patch Tuesday-Adjacent: FortiSandbox, Ivanti, and SAP Ship Fixes for Critical Bugs
A 9.1-rated command injection in FortiSandbox headlines a busy week of vendor advisories. Most of these land squarely on platform teams.

210 CVEs, Three Zero-Days, and a Microsoft Warning That This Is Just the Beginning
June Patch Tuesday sets a volume record. Microsoft says AI-assisted discovery is why, and that you should get used to it.

Tracing 'The Gentlemen' RaaS: OPSEC Trail Points to an Izhevsk Operator
A 90/10 affiliate split rocketed the crew to second place by victim count. The administrator's forum breadcrumbs are less impressive.

Infostealers Are Now the Front Door for Ransomware Gangs
Credential theft at industrial scale has made exploit-based initial access look quaint. Here's why stolen session tokens are reshaping the attack chain.

AI Agents in Phishing Tests: Risks and Failures Exposed
Autonomous AI agents can be tricked into leaking sensitive data, highlighting configuration issues in security frameworks.

RoguePlanet Zero-Day Drops as Nightmare Eclipse–Microsoft Feud Reaches New Low
A race-condition bug in Microsoft Defender can yield a SYSTEM shell on fully patched Windows 11 and 10. No patch exists. The researcher dropped it the day after June Patch Tuesday.

Shadow AI Is the Governance Gap Nobody Wants to Admit
A mid-year security forum puts unmonitored generative AI use front and center. The problem is older than the hype.

Twelve Controls That Actually Matter Once AI Ships to Production
Visibility into AI applications is a starting point, not a security posture. Here is what ongoing monitoring and defense of production AI systems looks like in practice.

Microsoft's October Dump: 206 CVEs, Three Already Public
A record Patch Tuesday hauls in 39 Critical bugs and a trio of zero-days that were knocking around before the fix shipped.

When the Pentest Report Goes Quiet, Start Worrying
Stable findings aren't the same as a stable attack surface — and identity paths are usually what the scanners stop seeing first.

AI Red Teaming Grew Up. The Job Description Is Still Being Written.
The tools broke when LLMs arrived. Now the discipline is rebuilding itself in real time — and the threat model includes teenagers with too much free time.

Anthropic Ships Claude Fable 5 as Two Products, One With the Cyber Guardrails Off
The public gets Fable 5. A vetted cyber cohort gets Mythos 5 — the same model with safety classifiers lifted.