AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code sprawl is taking root, increasing risk, com...
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure.
The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.
Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The core problem CISA is attempting to address is that many organizat...
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound...
Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into...
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns.
The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.
The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek.
New government figures reveal a 20% annual increase in certifications
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.
Our view of good cyber adversary simulation – and how assured providers can deliver it.
Adversary simulation ('red teaming') tests your ability to prevent, detect and respond to cyber attacks.
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recommends ADK 2.1.0 or later. It is available in Pri...
A new CVE drops. Your scanner finds it. The severity score looks ugly.
But that still does not answer the question that matters: Can it actually be exploited in your environment?
Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still...
It was discovered that GStreamer Good Plugins did not limit the size of
reassembly buffers when processing fragmented RTP packets. A remote
attacker could possibly use this issue to cause GStreamer Good Plugins to
use excessive resources, leading to a denial of service.
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running “booter” operations in existence. The domain seizure notice (Source: US Department of Justice) “Booter services such as those named in this action allegedly facilitate attacks o...
It was discovered that GNU Bison incorrectly handled grammar-defined
configuration variables when generating HTML reports. An attacker could
possibly use this issue to execute arbitrary code.
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department j...