“The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory.
“JFrog Artifactory contains an authentication weakness that, under default
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a “highly capable
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
“We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates.
“The authentication
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
“Greatness supports AiTM [adversary-in-the-middle] credential and
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
These targeted organizations operate across several sectors, such as healthcare, research, government offices,
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.
Adam Kues at Assetnote, Searchlight Cyber’s attack surface management arm, found the flaw and reported
