SonicWall reports two major security holes under active exploit
SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…
Consultants called the holes, one of which permits remote attacks that…
In its security alert, SonicWall described the first hole, tracked as …
A remote unauthenticated attacker could potentially exploit this vulne…
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Anthropic introduces zero-retention AI safety monitoring for enterprises
Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements.…
The company announced a new solution called Enterprise Frontier Safegu…
Under the approach, activity data used for monitoring will be stored i…
The feature will be rolled out in phases later this fall and will be o…
Exploited JFrog Artifactory bug puts software supply chain on alert
A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.…
The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August …
By September 1, watchTowr said its Attacker Eye honeypot was already s…
The activity included attackers minting administrator tokens and enume…
Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer.…
It has different settings for when people are home, asleep, or away.
The Xfinity app also lets users see live motion activity and a feed of…
Comcast acknowledges that the system has some limitations.
How China industrialized the infrastructure behind state hacking
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…
A People’s Republic of China (PRC) state-sponsored group known as “QTF…
Among the targets of QTFY are the National Aeronautics and Space Admin…
The law enforcement agencies said QTFY offers computer hacking service…
Anthropic makes changes to stop AI agents running amok again
Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.…
The company has established controls that flag when a model attempts t…
” Anthropic conceded that three recent security incidents involving Cl…
” Recent events “stressed that the urgency of improving our cybersecur…
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.…
Based on interviews with individuals whose licenses are available for …
KrebsOnSecurity also has learned that the New Orleans field office of …
A record available at this identity theft service that includes the dr…
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
CrowdStrike launches cyber frontier AI models, agentic security system
CrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.…
Con conference in Las Vegas.
At the heart of SafeMind are two purpose-built cybersecurity models, t…
Both models have been trained on CrowdStrike’s Falcon sensor telemetry…
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.…
[…] The reporting also linked a 2024 Department No.
4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known a…
That unit has been associated with destructive cyber activity against …
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.