Firestarter malware targets a US federal agency, maintaining persistent access to compromised devices, posing risks to government and critical infrastructure.
Firestarter malware targets a US federal agency, maintaining persistent access to compromised devices, posing risks to government and critical infrastructure.
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
Microsoft acknowledged active exploitation of a high-severity security flaw in Windows Shell, now patched, allowing unauthorized access to sensitive information.
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
Microsoft acknowledged active exploitation of a high-severity security flaw in Windows Shell, now patched, allowing unauthorized access to sensitive information.
Why Cybersecurity Must Rethink Defense in the Age of Autonomous Agents
Agentic AI is transforming cybersecurity, presenting both opportunities for defenders and risks for attackers, necessitating a strategic response from the industry.
Why Cybersecurity Must Rethink Defense in the Age of Autonomous Agents
Agentic AI is transforming cybersecurity, presenting both opportunities for defenders and risks for attackers, necessitating a strategic response from the industry.
Zetachain Pauses Mainnet After GatewayZEVM Contract Exploit Targets Protocol Wallets
Zetachain paused its mainnet after a vulnerability in the GatewayZEVM smart contract was exploited, affecting internal team wallets but not user funds.
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
AI agents in Microsoft Entra ID can lead to privilege escalation and identity takeover attacks due to a security flaw in the Agent ID Administrator role.
Solana Readies Quantum Defense With 3-Step Roadmap and Falcon Implementation
Anza and Firedancer selected the Falcon post-quantum signature scheme for Solana, ensuring readiness against quantum threats without immediate migration needs.
The report revealed that 74% of the analyzed organizations either lacked a DMARC policy entirely or had it set to monitor-only mode, which does not block spoofed emails.
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
Telecommunications fraud campaign uses fake CAPTCHA to trick users into sending costly international text messages, generating illicit revenue for fraudsters.
China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks
GopherWhisper is a newly identified APT using legitimate services for command-and-control communication and data exfiltration, primarily targeting a Mongolian government entity.
The Bitwarden CLI NPM package was compromised, enabling credential theft through a malicious payload targeting various cloud services and GitHub repositories.