When license plate readers become stalking tools ExfilSquad dumps UK police contact data China-linked hackers shrink the patch window Get the show notes…
4,400+ Internet-Exposed Rockwell PLCs Expose Water Systems to Cyberattacks
A wave of cyberattacks against U.S. water and wastewater utilities has renewed alarm over how many industrial controllers remain directly reachable from…
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a…
Top 10 Best Intrusion Detection & Prevention (IDS/IPS) Tools in 2026
An IDS detects malicious activity and alerts; an IPS sits inline and blocks it. Cisco Secure IPS is our top pick for 2026 on the strength of Snort 3 and…
Black Hat 2026: Barracuda Details AI-Powered BEC Attack
Barracuda’s Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks.
Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed…
Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
Recently, I read a great post by Melvin Tan Zhi Xian sharing his thoughts halfway through the OffSec OSAI+ course. He touched on something crucial that…
Vanta Stealer Empties Browser Vaults, Crypto Wallets and Gaming Accounts in Minutes
Vanta Stealer is a newly analyzed information-stealing malware built to strip valuable data from an infected computer quickly. It reaches far beyond saved…
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation…
Critical Flaws in Anthropic, Google, and OpenAI’s Coding Agents Enable RCE and Supply Chain Attacks
A repeatable vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI that allows attackers to achieve remote code execution,…
Photos: Black Hat USA 2026, part two
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured…
The risk awareness radar. A superpower every MSP needs to train
Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most…
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and…
Why metaphor may dictate your security strategy
In this week’s newsletter, Martin looks at how the metaphors we use to describe AI “escaping” its sandbox can completely change how we react to the threat.
Accelerating Enterprise AI from Proof of Concept to Production
Discover how Akamai AI Professional Services helps enterprises bridge the gap from proof of concept to secure, scalable, and manageable production AI.
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls…
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using…
Ransomware Attacks Become More Sophisticated as Experts Debate Effectiveness of Payment Bans
iNearly half of organizations hit by ransomware attacks end up paying cybercriminals to regain access to their data or systems, while the average ransom…
Hacker pleads guilty to stealing data from more than 165 Snowflake customers
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in…
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Automates bug bounty triage with Sonnet for $58 a month, CSO says Mythos would cost $200k
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher…
Humans in the loop miss a third of dangerous AI coding agent requests
You wouldn’t let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
Apple Photos Privacy Case Advances, With Up to $32.5 Billion Alleged Exposure
Apple’s Photos biometric privacy case will proceed after an appeals court declined to review class certification. Here’s what remains unresolved.
South Korea Probes Major Cyberattack on Diplomatic Academy Amid Data Leak Concerns
South Korea’s Ministry of Foreign Affairs has revealed that a cyberattack targeting the Korea National Diplomatic Academy (KNDA) may have resulted in the…