Latest stories — Page 99

Six Security Leaders Who Changed Jobs in Early 2026
From Air Force intelligence to frontier AI, the CISO hiring market is moving. Here is who landed where — and what the patterns suggest.

Clipper Crew Buys Sponsored Posts on News Sites to Push Trojanized Crypto Tools
An untracked actor is laundering credibility through paid press placements, a phishing-grade WordPress hub, and seeded GitHub and SourceForge repos to deliver clipboard hijackers.

Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works
CVE-2026-50656 is a privilege escalation bug in the Malware Protection Engine, the component sitting at the heart of every Defender install.

Fifteen Rogue JetBrains Plugins Posed as DeepSeek Assistants to Siphon AI Keys
A coordinated campaign on the JetBrains Marketplace dressed up credential stealers as LLM-powered coding helpers. The payload: your provider keys.

UK's Under-16 Social Media Ban Turns Every Signup Into an Identity Checkpoint
Spring 2027 rules will force ID uploads or face scans at account creation. The IAM bill comes due, and so does the breach surface.

UNC6508 Spent a Year Inside US and Canadian Research Networks via Trojanized REDCap
A China-linked espionage group hijacked REDCap's own upgrade process to plant persistent malware across academic, medical, and defense-adjacent research environments.

Security Executives Push Back on Anthropic Export Restrictions
A coalition of cybersecurity leaders argues that blocking foreign nationals from accessing Anthropic's latest models hands adversaries a strategic gift.

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse
CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

Contagious Interview Pivots to Dev-Review Lures in Two Fresh Campaigns
The North Korea-linked cluster is back with phishing pretexts aimed at developers: recruiter pitches and code-review requests that drop malware on engineers' workstations.

Behavioral AI Pitched as Triage Layer for Phishing and ATO Floods
A vendor webinar argues that pattern-learning models can cut investigation time on BEC and account takeover incidents. The harder question: what does that mean for breach-notification timelines?

Over 400 AUR Packages Backdoored With Rust-Based Credential Stealer
Attackers rewrote build scripts in Arch's community repo to drop a secret-harvesting binary, with an eBPF rootkit waiting if it gets root.

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds
Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome, agent completes task, attacker gets nothing, never appeared.

MDR's AI Reckoning: When the Old Service Model Stops Keeping Up
Managed detection and response solved a staffing problem. It is not, by itself, an answer to adversaries who automate reconnaissance and intrusion at machine speed.

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents handing over real credentials: the criminal stack is industrialising.

Oracle Patches PeopleSoft Flaw Tied to ShinyHunters Activity, Stays Quiet on Zero-Day Status
CVE-2026-35273 has a fix. Whether attackers got there first is a question Oracle isn't answering.

Tracing 'The Gentlemen' RaaS: OPSEC Trail Points to an Izhevsk Operator
A 90/10 affiliate split rocketed the crew to second place by victim count. The administrator's forum breadcrumbs are considerably less disciplined.

Twelve Controls That Actually Matter Once AI Ships to Production
Visibility into AI applications is a starting point, not a security posture. Here is what ongoing monitoring and defense of production AI systems looks like in practice.

protobuf.js Ships Six Bugs That Turn Schemas Into RCE Triggers
A single malicious descriptor is enough. Node.js services parsing untrusted Protobuf are the obvious blast radius.

Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated, and enterprises are deploying it despite knowing it carries unresolved flaws.

Cryptographic Invisibility: Atsign’s Approach to Securing AI Applications
Atsign's AI Architect aims to shield agentic software from attackers by rendering application identities invisible.