Aggregator
The AI Trust Gap: Governing Autonomous AI Without Losing Visibility or Control
1 month ago
AI Resilience: Preparing Infrastructure and Operations Teams for Autonomous AI
1 month ago
Securing Autonomous AI: New Security Strategies for AI Agents and Machine-Speed Risk
1 month ago
Go-Ahead for AI Chip Sales to 10 Chinese Firms Raise Alarms
1 month ago
Reports: Trump Administration Approval of Nvidia H200 Sales Poses Frontier AI Risks
Trump administration discussions on AI governance with China are colliding with reports that Washington may permit expanded Nvidia H200 chip sales to Chinese firms, fueling concerns that U.S. technology access could accelerate Beijing's frontier AI and military-linked ambitions.
Trump administration discussions on AI governance with China are colliding with reports that Washington may permit expanded Nvidia H200 chip sales to Chinese firms, fueling concerns that U.S. technology access could accelerate Beijing's frontier AI and military-linked ambitions.
Wave of ShinyHunters Extortion Drives Surge in Data Leaks
1 month ago
'Have I Been Pwned' Founder Troy Hunt Reviews Impact on People and Organizations
The volume of data breaches that result in stolen personal data being leaked online has been surging, "courtesy of the ShinyHunters," and while it affects individuals, the organizations being extorted are bearing the brunt of such attacks, said Troy Hunt, founder and CEO of Have I Been Pwned.
The volume of data breaches that result in stolen personal data being leaked online has been surging, "courtesy of the ShinyHunters," and while it affects individuals, the organizations being extorted are bearing the brunt of such attacks, said Troy Hunt, founder and CEO of Have I Been Pwned.
Microsoft Debuts Bug Hunting 100-Agent AI System
1 month ago
Computing Giant Touts Multi-Agentic 'MDASH' Approach as Superior to Single Models
Microsoft says its new approach to finding vulnerabilities with artificial intelligence agents outclasses the single models touted by Anthropic and OpenAI. MDASH is only being utilized internally by Microsoft engineers and tested by a "small set of customers as part of a limited private preview."
Microsoft says its new approach to finding vulnerabilities with artificial intelligence agents outclasses the single models touted by Anthropic and OpenAI. MDASH is only being utilized internally by Microsoft engineers and tested by a "small set of customers as part of a limited private preview."
ISMG Editors: Should We Trust Ransomware Gangs?
1 month ago
Ransomware Payouts, AI-Driven Threats and Reshaping Payment Fraud
In this week's panel, four ISMG editors discussed a ransomware case that once again raises questions about paying extortionists, why security leaders fear AI is accelerating attacks faster than humans can respond and how the rise of instant payments is reshaping fraud programs at banks.
In this week's panel, four ISMG editors discussed a ransomware case that once again raises questions about paying extortionists, why security leaders fear AI is accelerating attacks faster than humans can respond and how the rise of instant payments is reshaping fraud programs at banks.
The Next Cybersecurity Challenge May Be Verifying AI Agents
1 month ago
AI agents are reshaping cybersecurity. Learn why verification, trusted identity standards, and runtime controls are now essential.
Waqas
Congress Puts Heat on Instructure After Canvas Outage
1 month ago
The House Committee on Homeland Security sent a letter about the Canvas cyberattack, the same day that the edtech company said it reached an "agreement" with the ShinyHunters cybercriminals.
Rob Wright
Here’s how the FTC plans to enforce the Take It Down Act
1 month ago
The commission will dole out hefty fines and promises investigations for Take It Down Act violators. Experts say questions remain around the agency’s resources and priorities.
The post Here’s how the FTC plans to enforce the Take It Down Act appeared first on CyberScoop.
djohnson
More than $10 million stolen from crypto platform THORChain
1 month ago
THORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million.
Funnel Builder WordPress plugin bug exploited to steal credit cards
1 month ago
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]
Bill Toulas
CVE-2026-8525 | Google Chrome up to 148.0.7778.96 on macOS ANGLE heap-based overflow (ID 497928 / Nessus ID 314855)
1 month ago
A vulnerability was found in Google Chrome on macOS. It has been rated as critical. This impacts an unknown function of the component ANGLE. This manipulation causes heap-based buffer overflow.
This vulnerability is handled as CVE-2026-8525. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-8541 | Google Chrome up to 148.0.7778.96 UI out-of-bounds (ID 496645 / Nessus ID 314857)
1 month ago
A vulnerability classified as problematic has been found in Google Chrome. Affected is an unknown function of the component UI. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-8541. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-40374 | Microsoft Power Automate for Desktop prior 2.67 information disclosure (Nessus ID 314904)
1 month ago
A vulnerability labeled as problematic has been found in Microsoft Power Automate for Desktop. This affects an unknown function. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2026-40374. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-42861 | FlowiseAI Flowise up to 3.0.12 API Endpoint createLead dynamically-determined object attributes (WID-SEC-2026-1554)
1 month ago
A vulnerability was found in FlowiseAI Flowise up to 3.0.12 and classified as critical. Affected by this issue is the function createLead of the component API Endpoint. Such manipulation leads to dynamically-determined object attributes.
This vulnerability is traded as CVE-2026-42861. The attack may be launched remotely. Furthermore, there is an exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-43490 | Linux Kernel up to 6.12.87/6.18.29/7.0.6/7.1-rc2 ksmbd smb_inherit_dacl buffer overflow (WID-SEC-2026-1555)
1 month ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.87/6.18.29/7.0.6/7.1-rc2. This impacts the function smb_inherit_dacl of the component ksmbd. Such manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2026-43490. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
FreePBX security advisory (AV26–474)
1 month ago
Canadian Centre for Cyber Security
Марс наконец получит нормальный интернет. НАСА ищет подрядчика — дедлайн 2030 год, опоздания не принимаются
1 month ago
Новая сеть станет частью архитектуры, которая соединит Землю, Луну и Марс постоянными каналами.