[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Download: The IT leader’s guide to AI code sprawl
AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code sprawl is taking root, increasing risk, com...
> New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities
> Comp AI Raises $34 Million for AI-Native Compliance and Security
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.
> CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The core problem CISA is attempting to address is that many organizat...
> Cisco drops another exploited zero-day, this time a perfect 10
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
> ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.
> Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound...
> Druva expands identity resilience with ransomware detection
Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into...
> Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
> Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.   The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek.
> Cyber Essentials Has Record Year but Takeup Remains Low
New government figures reveal a 20% annual increase in certifications
> Israeli contractor BlackCore trained Angolan officials in online influence operations
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.
> Cyber Adversary Simulation (CyAS): scheme documents now available
Our view of good cyber adversary simulation – and how assured providers can deliver it.
> Adversary simulation: what you need to know
Adversary simulation ('red teaming') tests your ability to prevent, detect and respond to cyber attacks.
> Google’s new agent security system detects tool misuse, loops and rogue behavior
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recommends ADK 2.1.0 or later. It is available in Pri...
> Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still...
> USN-8778-1: GStreamer Good Plugins vulnerability
It was discovered that GStreamer Good Plugins did not limit the size of reassembly buffers when processing fragmented RTP packets. A remote attacker could possibly use this issue to cause GStreamer Good Plugins to use excessive resources, leading to a denial of service.
> FBI takes down one of the longest-running DDoS-for-hire services
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running “booter” operations in existence. The domain seizure notice (Source: US Department of Justice) “Booter services such as those named in this action allegedly facilitate attacks o...
> USN-8777-1: GNU Bison vulnerability
It was discovered that GNU Bison incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could possibly use this issue to execute arbitrary code.
> NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department j...