It was discovered that kitty incorrectly handled certain image data. An
attacker able to write to the terminal's input could possibly use this
issue to cause kitty to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-33633)
It was discovered that kitty incorrect...
Read the latest DFIR news – CCTV chain of custody, UEFI bootkit detection, Android intrusion log analysis, new LEAPP reporting, macOS Tahoe artifacts, and more.
Researchers have uncovered an Android banking Trojan that targets more than 200 banking and cryptocurrency apps and can take over infected devices.
What we believe We’ve been thinking deeply about enterprise security. The operating model that served us for the past decade (collect telemetry, store it, query it, build dashboards to watch it) is no longer keeping pace. We need to shift to the new world: telemetry, context, reasoning, and actions....
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Widget Factory Joomla Content Editor (JCE) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added Widget Factory Joomla Content Editor (JCE) flaw, tracked as CVE-202...
Europe is moving to tackle its massive structural reliance on foreign technology. Here’s what it means for European businesses.
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. [...]
Several security issues were fixed in GStreamer Bad Plugins.
Nisos infiltrated a North Korean IT-worker fraud cell running on AI interviews and a US laptop farm
PARTNER CONTENT Europe wants control over its own technology, but what does that look like?
There’s no shortage of agentic AI tools out there that offer to perform online tasks on your behalf, if only you’ll give them all your passwords and credit card details. The trouble starts when those agents don’t know when to stop — or when others don’t know to stop them.
I...
Medical technology company iRhythm Holdings disclosed a cyberattack involving certain third-party-hosted business applications that resulted in the theft of patient protected health information, proprietary data, and other personal data. The company discovered unauthorized activity on June 8, 2026,...
Attendees will learn how attackers evade conventional detection methods, why legacy MFA alone is no longer sufficient, and how organizations can strengthen their defenses.
The post Webinar Today: How Modern Breaches Bypass MFA and Evade Detection appeared first on SecurityWeek.
WitnessAI has announced extended agentic security capabilities that govern how AI agents interact with enterprise systems, tools, and Model Context Protocol (MCP) servers. With the launch of Agentic Control, enterprises have greater visibility and control over their AI agents with a single control p...
Account takeovers are rising as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue. Specops Software explores how device trust and continuous verification help reduce account takeover risk. [...]
GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials
Tigera has announced the general availability of Tigera Lynx, a unified control plane for Kubernetes-native AI agents. Lynx gives enterprises a single place to find every agent in their Kubernetes estate, tighten security posture, assign sandboxes, provide each agent with a cryptographic identity, e...
Updated at the time? No sweat. Check those logs, though
graphite2 could be made to crash or run programs if it opened a specially crafted file.
Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solutions” and “tools” that claim to give users an unfair advantage. These offers include Solana and Pump.fun sniper bots (automated tools that try to buy new tokens or meme coin...