Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply…
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.…
Silent Patches Don’t Stop Attackers – They Blind Defenders
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how…
Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts
Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any…
Teaching AI to Reason Through Detection Triage
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Teaching AI to Reason Through Detection Triage
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a “safety penalty” that hampers real-time incident response. Discover how…
ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.
Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary…
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that…
CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the…
IT Security News Hourly Summary 2026-08-25 12h : 8 posts
8 posts published in the last hour 09:31Crooks push Mac malware through fake OpenAI Codex ads 09:31ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 09:31US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks 09:02Anthropic Expands Claude MCP…
Crooks push Mac malware through fake OpenAI Codex ads
Sponsored search results lead developers straight into a ClickFix malware trap
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a…
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing…
Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors
Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that…
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers…
Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions
A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access. The campaign turns…
IT Security News Hourly Summary 2026-08-25 11h : 7 posts
7 posts published in the last hour 08:31Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover 08:31TikTok phishing: How to spot fake login and verification pages 08:31Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac…
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard…