It’s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. […]
Category: Security
AI Broke Vulnerability Management. That’s Why CISOs Are Moving Budget to BAS.
For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone […]
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock […]
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
Ravie LakshmananJun 11, 2026Developer Security / Software Supply Chain GitHub has announced what it said are “breaking changes” coming to […]
This Microsoft Defender zero-day could give hackers unprecedented access to your system
(Image credit: iStock) Chaotic Eclipse drops seventh Windows zero‑day, “RoguePlanet,” hours after Patch Tuesday Race‑condition exploit grants SYSTEM privileges; PoC […]
OpenClaw AI agent tricked into phishing attacks, with user data compromised
(Image credit: Getty Images) Varonis’ “Pinchy” OpenClaw agent fell for identity‑based phishing despite strict settings Models blocked malicious links/OAuth apps […]
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Cybersecurity researchers have warned of a “resurgence and expansion” of JDY, a covert network associated with China-nexus state-sponsored threat actors. […]
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Ravie LakshmananJun 10, 2026Vulnerability / Patch Management Fortinet, Ivanti, and SAP have released security updates to address multiple critical security […]
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
Ravie LakshmananJun 10, 2026Vulnerability / Open Source A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build […]
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Ravie LakshmananJun 10, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new […]
