Quebec water treatment plant attack gains access to control pumps and chlorine dosing.
Norway plans to restrict AI use for students aged 6–13, shifting focus back to traditional learning tools amid concerns about developmental impact.
Poland warns Russia may be influencing AI outputs by flooding the internet with disinformation, highlighting a new front in hybrid warfare.
Reports suggest Claude Code may use hidden markers to identify certain users, raising new transparency and privacy concerns in AI tooling.
The U.S. lifts export restrictions on Anthropic’s advanced AI models after new security measures, restoring access for global users.
OECD releases a roadmap for AI in public governance, emphasizing citizen engagement and efficiency—but warns AI is not a standalone solution to democratic challenges.
The U.S. offers up to $10M for intel on hackers tied to Russian groups UNC5792 and UNC4221, linked to phishing attacks targeting Signal and WhatsApp users, including officials.
A former NSO executive is reportedly behind a new cyber project, signaling the next wave of offensive cyber tools as geopolitical tensions increasingly shift into digital battlegrounds.
90+ spoofed software domains are pushing AsyncRAT through ScreenConnect.
Kaspersky says the sites mimic OBS Studio, Bandicam, DNS Jumper, and DS4Windows, then use SEO to surface in Google and Bing.
Kaspersky says the sites mimic OBS Studio, Bandicam, DNS Jumper, and DS4Windows, then use SEO to surface in Google and Bing.
PureLogs Stealer now hides behind Blogger pages and a fake PDF JavaScript file.
Experts say VEIL#DROP uses PowerShell, dynamic Blogspot URLs, fileless .NET loading, and Microsoft-signed LOLBins to evade detection.
Experts say VEIL#DROP uses PowerShell, dynamic Blogspot URLs, fileless .NET loading, and Microsoft-signed LOLBins to evade detection.
Two Cursor vulnerabilities could let hidden prompt-injection instructions escape the editor’s terminal sandbox and run commands on a developer’s machine.
Tracked as CVE-2026-50548 and CVE-2026-50549, they affect versions before 3.0.
Tracked as CVE-2026-50548 and CVE-2026-50549, they affect versions before 3.0.
Attackers are trying to exploit CVE-2026-8037 in Progress Kemp LoadMaster.
The CVSS 9.6 flaw enables unauthenticated OS command injection and arbitrary code execution on vulnerable appliances.
The CVSS 9.6 flaw enables unauthenticated OS command injection and arbitrary code execution on vulnerable appliances.
Ousaban hides a ZIP payload inside an image after a fake “corrupted” PDF screens victims in Spain and Portugal.
The Windows banking trojan watches 24+ banks and can log keys, grab screenshots, tamper with the clipboard, and enable remote control.
The Windows banking trojan watches 24+ banks and can log keys, grab screenshots, tamper with the clipboard, and enable remote control.
Adobe patched 9 flaws in ColdFusion and Campaign Classic, 7 rated CVSS 10.0.
ColdFusion issues enable RCE, privilege escalation, file read, and bypass.
Campaign Classic CVE-2026-48286 impacts on-prem ACC v7 only.
ColdFusion issues enable RCE, privilege escalation, file read, and bypass.
Campaign Classic CVE-2026-48286 impacts on-prem ACC v7 only.
Adobe patches 7 critical vulnerabilities, including multiple RCE flaws in ColdFusion. No active exploitation yet—but risk level is high. Immediate updates recommended.
Cyber defense alone is no longer enough. Experts emphasize integrating offensive capabilities, AI-driven monitoring, and proactive response for modern cyber warfare.
Nvidia and Palantir unveil a secure AI platform built on open Nemotron models, designed for U.S. government and critical infrastructure use. Focus: full data control, isolated deployment, and high-stakes environments.
The EU adopts “Omnibus 7” reforms, delaying some AI regulations while simplifying compliance and banning non-consensual AI-generated explicit content.
Scattered Spider investigation expands: 19-year-old Peter Stokes extradited from Finland to the U.S., accused of operating as “Bouquet.” Prosecutors link him to at least four intrusions, including one involving an $8M crypto ransom demand.