Cyber News

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Atlassian Rovo is showing exactly why AI assistants deserve the same trust-boundary thinking as connectors and privileged apps: attacker-controlled content…

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

CISA added Progress Kemp LoadMaster flaw CVE-2026-8037 to the KEV catalog after repeated exploitation attempts, turning a load balancer bug…

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited…

Why metaphor may dictate your security strategy

Why metaphor may dictate your security strategy

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including…

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively…

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft's August 2026 Patch Tuesday is not just a volume story. Teams should start with the actively exploited AFD.sys zero-day,…

ChainDrop: Inside a Self-Propagating npm Worm

ChainDrop: Inside a Self-Propagating npm Worm

Unit 42 and Siemens detailed a three-CVE exploit chain in Siemens ROX II OT switches that can move an attacker…

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

Atlassian Rovo is showing exactly why AI assistants deserve the same trust-boundary thinking as connectors and privileged apps: attacker-controlled content…

CISA Adds One Known Exploited Vulnerability to Catalog

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog after active exploitation. The flaw affects Cisco Secure Firewall Management Center…

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA is telling federal agencies to move within three days on actively exploited flaws in IBM Langflow, N-able N-central, and…

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage…

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates.…