Ravie LakshmananJul 27, 2026Software Supply Chain / DevSecOps GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool […]
Category: Security
Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth
(Image credit: Getty Images) 2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California The vulnerability […]
It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files
(Image credit: Shutterstock/ gguy) Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331 Agent accessed […]
This Russian cybercrime campaign can infect a user just by viewing an email
(Image credit: Shutterstock) Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns “Half‑click exploit” let attackers compromise systems […]
Sakana AI Releases Fugu-Cyber: An Orchestration Model Reporting 86.9% on CyberGym and 72.1% on CTI-REALM
Sakana AI has released Fugu-Cyber (model ID is fugu-cyber-v1.0), a cybersecurity-specialized addition to its Fugu orchestration family. It is not […]
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime […]
Experts claim to have found more weaknesses in Apple’s Gatekeeper tool — but it doesn’t seem too bothered
(Image credit: Apple) Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware Attack […]
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in […]
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers […]
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Ravie LakshmananJul 25, 2026Vulnerability / Ransomware Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) […]
