Cyber News

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

This is not just another catalog update. CISA is effectively telling defenders that these flaws have crossed from known problem…

Why metaphor may dictate your security strategy

Why metaphor may dictate your security strategy

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

This moved from important to urgent fast. CrowdStrike is pointing to a live exploitation or incident path that should be…

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

The latest LiteLLM fallout matters because the issue is no longer just a package-security anecdote: teams may still have long-lived…

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock is an emerging ransomware operation that pairs double extortion with decentralized recovery and leak infrastructure, giving the actor a…

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal flaw in VMware vCenter, and incident responders are seeing successful compromise…

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit CVE-2026-71362 in Adobe Commerce and Magento have already been detected, and the flaw appears to let attackers…

Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation…

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Atlassian Rovo is showing exactly why AI assistants deserve the same trust-boundary thinking as connectors and privileged apps: attacker-controlled content…

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

CISA added Progress Kemp LoadMaster flaw CVE-2026-8037 to the KEV catalog after repeated exploitation attempts, turning a load balancer bug…

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited…

Why metaphor may dictate your security strategy

Why metaphor may dictate your security strategy

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…