JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating…
News
After OpenAI, Anthropic finds Claude breached three organizations during cyber tests
Less than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed…
5 key priorities for your Black Hat agenda — and what to avoid
Two major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat. RSA was launched in 1991…
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including…
A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?
A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread…
AI agents gain access to financial workflows amid growing governance gaps
AI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most…
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by…
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened…
A Scattered Spider member was indicted. Microsoft’s GDID went to trial.
A recently released criminal complaint against Peter Stokes, an alleged member of the Scattered Spider cybercrime group, reveals previously unpublicized details about…
CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
Most IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in…