Latest stories — Page 98

Illustration: a large corporate boardroom table with scattered financial documents, a risk matrix printout
Opinion

CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready.

Security chiefs at Appfire, JumpCloud, and BECU describe how they're learning to own risks that finance and operations used to call their own.

3 min read
Illustration: a dimly lit operations center with multiple monitors showing abstract network maps of the Asia-Pacific region
Threat Intelligence

INTERPOL Flags Sharp Rise in Phishing, Ransomware and AI Scams Across Asia-Pacific

A new INTERPOL assessment maps a region where cybercrime is outpacing defensive capacity, with phishing leading the volume charts and ransomware crews exploiting the gap.

3 min read
Illustration: a vast illuminated data-center floor at night
AI Security

Zero Trust as the AI Control Plane: What Zscaler's Vienna Pitch Means for APAC CISOs

AI agents are joining the workforce whether security teams are ready or not. At Zenith Live 2026, Zscaler made its case for why zero trust should govern them the same way it governs humans.

3 min read
Illustration: a dimly lit server rack with a single envelope-shaped indicator light glowing amber
Vulnerabilities

Gravity SMTP Flaw Under Active Exploitation, Leaks API Keys and OAuth Tokens

CVE-2026-4020 lets unauthenticated attackers pull secrets from roughly 100,000 WordPress installs running the mail plugin.

3 min read
Illustration: A long polished conference table in a modern governmental chamber
Policy & Regulation

Macron Pushes Wealthy Democracies Toward a Unified AI Regulatory Front

The French president wants the G7 crowd to stop freelancing on AI governance and start coordinating. Whether that translates into anything enforceable is a different question entirely.

3 min read
Illustration: a disassembled smartphone logic board under cool blue lab
Vulnerabilities

usbliter8 Burns a Permanent Hole in A12 and A13 SecureROM

Paradigm Shift's tethered exploit reaches code burned into the silicon, putting a years-long tail on iPhone XS through SE2 boot-chain trust.

3 min read
Illustration: a darkened server rack with one indicator LED glowing amber while neighboring LEDs are dark
Ransomware

The Gentlemen RaaS Ships an In-House EDR Killer to Affiliates

GentleKiller bundles signed-driver abuse with third-party utilities and a kill list of roughly 400 security processes, handed out as part of the affiliate package.

3 min read
Illustration: a darkened developer workstation at night
AI Security

AutoJack: When the AI Browser Becomes the Initial Access Broker

Microsoft researchers describe an exploit chain that turns an agentic browser into a one-click path from web page to host process execution.

3 min read
Illustration: A darkened server room with rows of rack-mounted equipment
Policy & Regulation

Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure

Dutch-led coalition disrupts servers and remediates 14,971 compromised WordPress sites, in the latest tranche of the multinational takedown effort.

3 min read
Illustration: tangled ethernet cables and server rack indicator lights glowing amber and green in a darkened data center
Vulnerabilities

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows

A Bluetooth eavesdropping patch, a quietly dangerous GCP authorization flaw, and a threat actor that spent ten years undetected, here is what you may have missed.

3 min read
Illustration: a rack-mounted network security appliance in a dim data center aisle, status LEDs glowing amber and red
Threat Intelligence

FortiBleed Campaign Hits 86,644 FortiGate Boxes; CISA Pushes Customers to Lock Down

Russian-speaking operators are working through internet-exposed Fortinet appliances at scale. CISA wants admins moving now.

2 min read
Illustration: a modern office desk with a monitor displaying a completely blank white application window
Vulnerabilities

June Patch Tuesday Breaks OLE Automation, Leaves Word and Excel Silent on Failure

A Windows update shipped June 9 quietly severed the OLE bridge between Office apps and dozens of third-party tools. No error message. Just nothing.

3 min read
Illustration: a vast server room at night, rows of glowing rack-mounted hardware receding into darkness
AI Security

The SOC Triangle Was Always a Lie We Accepted. AI Is Changing the Math.

Security operations have run on a structural compromise for decades, quality, consistency, or cost: pick two. That constraint is finally starting to bend.

3 min read
Illustration: A digital visualization of interconnected AI agents interacting with a central computer system
AI Security

AutoJack Exploit in Web-Enabled AI Agents: Bypassing Localhost Security

Microsoft researchers chain three weaknesses in AutoGen Studio's MCP WebSocket layer to achieve host-level remote code execution through a browsing agent.

3 min read
Illustration: a dimly lit modern security operations center, rows of monitors displaying abstract graph data and dashboards
AI Security

Tool Sprawl Meets Agentic AI: Why SOCs Are Rethinking the Triage Stack

Forty tools, forty-three day dwell times. Vendors are pitching agentic AI as the fix. Analysts have questions.

3 min read
Illustration: A dimly lit corporate office at night
Identity & Access

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.

Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.

3 min read
Illustration: a tangled bundle of glowing fiber-optic cables converging into a single dark server rack port
Identity & Access

Shadow AI Is an IAM Problem Now, Not a DLP Problem

The risk isn't what employees paste into ChatGPT. It's what tokens, scopes, and service accounts the AI agents they spin up are quietly holding.

3 min read
Illustration: a glowing blue cloud server rack with a single severed fiber-optic cable sparking
Cloud Security

Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise

The CRM giant pulled the competitive-intelligence app's integration on June 11, 2026 following a security incident that exposed connected customer data.

3 min read
Illustration: A high-tech server room with glowing server racks, representing AI and security in a corporate environment
AI Security

Security Protocols for SMBs Adopting Claude

What security leaders at small and medium-sized businesses actually need to know before they hand anyone a Claude license.

3 min read
Illustration: a dense network of glowing fiber-optic threads converging into a central illuminated node
Identity & Access

Cisco Acquires WideField Security to Wire Identity Intelligence Into Splunk's Agentic SOC

The deal adds credential and session visibility to Splunk's autonomous detection pipeline, filling a gap that pure log-correlation has always struggled with.

3 min read
Illustration: Macro close-up of a glowing blue search bar interface on a dark enterprise dashboard screen
AI Security

SearchLeak Shows How a Single Crafted URL Can Drain Your M365 Tenant

Varonis researchers chained three weaknesses in Copilot Enterprise Search into a full data-exfiltration path. Microsoft patched it. The attack class isn't going anywhere.

3 min read
© 2026 Threat Vectr