Advertisement
OpenAI Disrups LLM-Powered Social Engineering Operations
OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.
Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets
Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.
DoD Refrigeration Outages: Hacking or Malfunction?
Multiple U.S. DoD commissaries report refrigeration outages, leading to speculation of cyberattack amidst a lack of official cause.
North Korean Job Fraud Expands Beyond IT: New Sectors Targeted
DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.
Nigeria Advances Sovereign Cloud for Cyber, National Security
Nigeria is implementing a sovereign cloud strategy with new policies to boost national cybersecurity, data control, and domestic technical capabilities.
AI Email Summarizers Vulnerable to Hidden HTML Prompts
Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.
Advertisement
Alice Secures $140M to Enhance AI Model Defenses and Guardrails
AI security firm Alice raised $140M to combat adversarial AI, prompt injection, and jailbreak attempts in generative AI systems.
U.S. Sanctions Iran-Linked Hackers Targeting Critical Infrastructure
U.S. Treasury sanctions Iran-linked cyber actors, including Mabna Institute members, for critical infrastructure breaches and cyber theft.
Mexico’s Cybersecurity Plan 2025-2030: Addressing Rising Threats
Mexico's National Cybersecurity Plan 2025-2030 aims to strengthen defenses against ransomware, state-sponsored espionage, and cybercrime.
Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata
Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.
Operational Sovereignty: Managing AI Guardrails in SOCs
Cloud-hosted AI guardrails can hinder SOC investigations, creating a "safety penalty." This article explores reclaiming operational sovereignty.
Black Hat 2026: The State of Security Vendors and AI's Influence
Analysis of Black Hat 2026 security vendor landscape, highlighting widespread AI integration and a market split between threat visibility and prevention tools.
Cybersecurity Affordability Crisis: Impact on Small Businesses
Rising breach costs and defense spending strain budgets, leaving small businesses dangerously exposed and elevating supply chain risks.
Linux Foundation to Govern TRACE: AI Runtime Attestation Standard
The Linux Foundation now governs TRACE, an open standard providing hardware-backed, verifiable evidence for AI agent runtime and confidential workloads.
Massive DDoS Disrupts Norway Government Digital Services
Norway's Digitalization Agency (Digdir) services, including e-IDs, face ongoing disruptions from a massive DDoS attack. No data breach reported.
ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing
ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.
AI Coding Accelerates Open Source Risk and Remediation Debt
AI coding tools introduce open-source dependencies faster than security teams can manage, creating "remediation debt" that impacts enterprise security.
Criminal Deception in Silicon Valley: The Façading Process
Research details entrepreneurial fraud in Silicon Valley, identifying 'façading' as a method where founders create illusory high-growth appearances.
Strategic Security: Aligning CISO Goals with Business Outcomes
CISOs face a double standard, hired for technical expertise but judged on business growth and customer trust.
AI-Powered PLC Attacks Target Critical Infrastructure
U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.
Anthropic Expands AI Security Access, Unveils $35M Open Source Fund
Anthropic is broadening access to its Mythos 5 AI security capabilities for defenders and launching a $35M fund for open-source project security.
Hardware Makers Integrate Post-Quantum Cryptography
Hardware manufacturers are proactively integrating post-quantum cryptography (PQC) to secure systems against future quantum computer-driven decryption threats.
Mabna Institute Espionage, BTR.sys Kernel Bypass, & Malware
Runtime Rebel details state-sponsored espionage by Mabna Institute, a kernel-level bypass using Microsoft Defender's BTR.sys, and new malware campaigns.