Latest stories — Page 83

Anthropic Pushes for Verified AI Pause Mechanism Among Leading Labs
The company wants coordinated verification protocols that could let frontier AI developers confirm rivals have genuinely halted or slowed development if safety risks cross certain thresholds.

VerdantBamboo Ports BRICKSTORM to BSD, Goes Hunting for Linux Appliances
A China-nexus crew is rewriting its toolkit to live on the boxes most EDR vendors forgot about.

Corporate Cyber Readiness Is a Compliance Exercise. The Military Treats It as Combat.
Enterprise incident response still runs on annual tabletops and audit checkboxes. That gap between posture and practice is exactly what attackers count on.

12 Questions That Expose Whether Your Security Program Is Actually Working
A roundup of hard questions CISOs should already be asking — about blast radius, nonhuman identities, and whether 'vibe coding' has eaten your attack surface.

UNC3753 Hit U.S. Professional Services Firms With Vishing and Walk-In Intrusions
Dozens of legal, financial, and consulting firms were hit between January and May 2026 in a data-theft extortion run that blended phone-based social engineering with physical site visits.

How Ukraine Turned a Nation-State Cyberwar Into a Masterclass in Operational Resilience
Former foreign minister Dmytro Kuleba details how pre-planned contingencies — not ad-hoc crisis management — kept Ukrainian government and business functions alive under sustained Russian attack.

Microsoft Bakes a Two-Hour Quarantine Into VS Code Extension Auto-Updates
The delay is a soft tripwire against marketplace supply chain attacks — buying defenders a window to flag malicious updates before they propagate.

Silent Ransom Group Escalates Vishing Campaign Against U.S. Law Firms
Mandiant tracks rapid data theft following fake IT-support calls, raising fresh questions about Form 8-K Item 1.05 disclosure timing for affected firms.

OpenAI Ships ChatGPT 'Lockdown Mode' to Blunt Prompt-Injection Data Theft
The opt-in setting strips connectors and browsing tools that attackers have used to siphon data from logged-in sessions.

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft
A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

Bright Data's iOS SDK Quietly Conscripts Smart TVs Into a Scraping Proxy Network
A reverse-engineering of the SDK shows how consumer apps — including always-on televisions — relay traffic for the proxy giant now courting AI customers.

CISA Flags SolarWinds Serv-U DoS Bug as Actively Exploited
CVE-2026-28318 crashes the file transfer service. Federal agencies get the usual three-week patch window.

FFmpeg Gets 21 New Bugs from an AI Fuzzer; Chrome 149 Ships a Record 429 Fixes
An autonomous agent dug up zero-days in the codec library that ships in everything. Google's browser shipped its largest single security release on record. Same week.

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected
The campaign — tracked publicly as Miasma — propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

Cisco SD-WAN Manager Bug Under Active Exploit, No Fix Yet
CVE-2026-20245 affects on-prem and FedRAMP deployments. Cisco confirms exploitation in the wild while customers wait on a patch.

npm Hit by Dual Supply-Chain Campaigns: Rust Stealer With eBPF Rootkit, Self-Spreading Worm
Researchers flagged two parallel intrusions into the npm registry. One delivers a kernel-level credential scraper. The other propagates through more than 50 poisoned packages.

Microsoft Expands Its Agentic AI Failure Taxonomy With Seven New Attack Classes
From inter-agent trust escalation to MCP plugin abuse, the updated taxonomy surfaces threat categories that didn't exist — or weren't well-understood — when Microsoft published its first version.

RubyGems Adds Installation Cooldown to Bundler as Supply Chain Defense
A configurable delay before newly published gems install gives the community time to spot malicious code before it reaches developer machines.

Asin Android Spyware Surfaces in Arabic-Language Lures, ESET Says
ESET ties early-2025 campaigns to decoy sites posing as utilities, war-tracking tools and a fake government news portal.

OWASP's CVE Lite CLI Puts Dependency Scanning in the Terminal
A new OWASP Incubator project lets developers scan project dependencies for known vulnerabilities from the command line — no dashboard, no subscription, no delay.

Fuel, Chemicals, Food: CISA Warns ATG Attacks Can Drain Tanks Silently
Hardcoded credentials and unauthenticated command execution leave automated tank gauges wide open. The fix list is embarrassingly short.