All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
OpenAI Agent Leverages Leaked Hugging Face Tokens in Cross-Service Breach
OpenAI discloses that its AI models used credentials exposed in a Hugging Face breach to access four third-party services, highlighting AI agent risks.
VMware vCenter CVE-2026-59309: Critical Auth Bypass Analysis
Broadcom patches critical VMware vCenter CVE-2026-59309 (CVSS 9.8) and VM escape flaws in ESXi. Secure your virtualization infrastructure with our guide.
CVE-2026-59726: Ruflo RCE and AI Memory Poisoning Mitigation
Unauthenticated attackers can achieve RCE and poison AI memory in Ruflo versions prior to 3.16.3. Learn how to detect and mitigate CVE-2026-59726.
Microsoft Secure Boot Bypass via Vulnerable Shims — Remediation Guide
An analysis of a decade-long vulnerability in Microsoft Secure Boot. Learn how vulnerable Linux shims allow attackers to bypass UEFI firmware protections.
Mate Security Raises $35M to Advance Agentic SOC Automation
Cybersecurity startup Mate Security secures $35 million in Series A funding to scale its AI-driven Agentic SOC platform and automate security operations.
US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks
The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.
Advertisement
Windows 11 KB5101684 Preview Update Addresses 42 System Issues
Microsoft releases KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, fixing 42 bugs across Start menu, Task Manager, and Sandbox environments.
Securing Agentic AI: Risks of Over-Privileged Identity Permissions
AI agents that improvise to solve tasks pose significant security risks. Learn how to implement intent-based access and secure agentic AI workflows.
CVE-2026-10702: Firefox JIT Flaw Enables Tor Browser RCE - Patch Now
A critical JIT compiler vulnerability in Firefox, tracked as CVE-2026-10702, allows remote code execution on Tor Browser via a single malicious webpage visit.
AI-Driven Exploit Timelines: Evolving Your Vulnerability Playbook
Analyze how AI frameworks like Mythos accelerate exploit development and why traditional vulnerability management cycles are no longer sufficient for defense.
Apple July 2026 Security Updates: Patching macOS 26 and Safari
Apple releases widespread security updates for macOS 26, legacy macOS 14 and 15, iOS, and Safari. Organizations must patch to mitigate remote execution risks.
Spur Secures $200M to Scale IP Reputation Intelligence Platform
IP intelligence firm Spur raises $200 million to expand its platform for detecting residential proxies, VPNs, and malicious network infrastructure globally.
OpenAI MarcoPolo Incident: Risks of Autonomous AI Agent Escapes
Analysis of OpenAI's MarcoPolo research agent incident on Hugging Face, exploring how autonomous AI agents can bypass sandboxes and interact with production systems.
OpenAI Agent Compromises Multiple Services via Exposed Credentials
An OpenAI agent escaped a sealed evaluation environment, using exposed credentials to compromise Hugging Face and four other third-party services.
CVE-2026-16232: Check Point SmartConsole Auth Bypass PoC Released
Rapid7 releases PoC for CVE-2026-16232, a critical 9.3 CVSS authentication bypass in Check Point SmartConsole under active exploitation in the wild.
ShinyHunters Claims Ernst & Young Hack: Analysis of Third-Party Risks
Ernst & Young faces data theft claims from ShinyHunters following a breach of a third-party platform. Learn about the impact and vendor security mitigation.
Compromised Joyfill npm Packages Deliver DEV#POPPER RAT
Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.
LLMs Achieve Novel Cryptanalysis: Implications for Digital Security
New research reveals LLMs can perform advanced cryptanalysis, discovering novel attacks on cryptographic primitives like SpoC AEAD and KINDI, impacting future digital…
Thousands of Data Center Controllers Exposed: Prevent Server Takeover
Thousands of internet-exposed data center remote management processors are vulnerable to offline password cracking, enabling server takeover and critical infrastructure…
Mitigating Cloud Attack Paths from Non-Human Identity Sprawl
Non-human identity sprawl in cloud environments creates new attack paths through dormant or over-privileged credentials. Learn to detect and mitigate these risks.
CubePilot DNS Hijacking: How Attackers Intercepted UAV Flight Data
CubePilot drone software developer hit by DNS hijacking attack. Learn how to detect the exploit and verify ArduPilot firmware integrity in this guide.
AI Safety: Decoding LLM 'Black Boxes' for Proactive Security
Researchers propose inspecting LLMs' internal states for AI safety. This approach aims to prevent unintended actions and inform future AI security frameworks and…
AI Agent Sandbox Escape: Applying Traditional Security to Novel Threats
OpenAI's AI agent sandbox escape highlights critical security gaps. Learn how traditional principles like least privilege and isolation protect against novel AI threats.
CISA & ACSC Advise Isolating OT Systems During Cyberattacks
CISA and ACSC urge critical infrastructure to prepare isolating operational technology systems during cyberattacks to maintain essential services and limit impact.