A hard-coded static key in SolarWinds ARM can enable unauthenticated RCE.
CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.
CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.
Attackers are exploiting a critical Orkes Conductor RCE without authentication.
Nearly 7,000 attack attempts were blocked from Sept. 2–9, with attackers submitting crafted workflow definitions containing malicious JavaScript or Python expressions.
Nearly 7,000 attack attempts were blocked from Sept. 2–9, with attackers submitting crafted workflow definitions containing malicious JavaScript or Python expressions.
Three Linux kernel flaws are being exploited.
One can enable local privilege escalation. The others can expose memory, crash systems, or corrupt cryptographic results. All three are now in CISA’s KEV catalog.
One can enable local privilege escalation. The others can expose memory, crash systems, or corrupt cryptographic results. All three are now in CISA’s KEV catalog.
Nvidia CEO Jensen Huang: I’m not afraid of paying taxes. I’m just afraid of being poor.
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up.
IMF Report on AI Productivity in Europe — AI could boost European productivity by ~1% over five years, but risks include inequality, grid strain, and 60% of advanced-economy jobs being heavily affected.
Interpol Uses AI Against Terrorism — Operation "Shams 2" used AI to filter 108,000+ jihadi images, extracting 6,362 unique faces and identifying 126 suspected foreign terrorist fighters across 11 countries.
US Congress Seeks Cyber Command Support — Lawmakers propose $11 million for mental health and psychological support for Cyber Command personnel amid rising operational stress and recent suicides.
UAE Launches "Cyberani" Initiative — The UAE launched a national hands-on cybersecurity training program with 7 universities to prepare students across 6 domains including threat intelligence and digital forensics.
Google Confirms Gemini AI Hack — Google confirmed its Gemini AI model independently breached three companies' protected systems during a security test by guessing passwords and finding credentials in public repositories.
UN Chief Calls for Action on Hate Speech — Guterres urged international cooperation against digital hate speech, warning it can incite violence and normalize racism and xenophobia.
AI Error Nearly Triggered US-China Conflict — A chatbot incorrectly linked a Chinese ship's cargo to a nuclear weapons program, nearly prompting US military action before the error was caught.
Class-Action Lawsuit Against AI Companies — Four users sued Anthropic, OpenAI, xAI, and Google, alleging they coordinated to slow AI development in violation of US antitrust laws.
US Judge Rejects Part of TikTok Privacy Settlement — A federal judge rejected part of TikTok's $400M settlement with the DOJ over children's privacy violations, keeping monitoring obligations through 2029.
US Bolsters Panama's Border and Cyber Security — The US delivered $5M+ in maritime, border, and cybersecurity equipment to Panama, with total 2026 security cooperation potentially reaching ~$100 million.
Russia's Ruling Party Wins Parliamentary Elections — Elections proceeded amid widespread Ukrainian drone attacks and 1,000+ DDoS attacks on electoral infrastructure; United Russia leads with ~57.5% of counted votes.
Dark Web Cyberwar Escalates — ShinyHunters claims to have taken over rival group Cl0p's dark web site by exploiting a vulnerability, following disputes over an Oracle EBS zero-day used to steal data from 100+ companies.
Users Sue ChatGPT and Claude Developers — A group sued AI developers alleging collusion to slow technology development, impacting service quality for paying users; companies cite safety protocol reviews.