-
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the Rancher management plane and every downstream Kubernetes cluster it manages. This issue is tracked as CV…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have disclosed “GhostJacking,” a new class of attacks that exploits trusted observability and security platforms to manipulate AI agents into making unauthorized infrastructure changes, executing attacker-controlled commands, and e…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors used a private cellular access-point-name (APN) network to pivot from a compromised wind farm into the operational technology environment. A Polish combined heat and power plant, where they disrupted Siemens programmable logic controllers…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco has disclosed seven high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning by submitting specially crafted files. These vulnerabilities are tracked as CVE-2026-20337, CVE-2026-20338…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has launched a machine-readable content-marking initiative for materials generated by its Claude models. This initiative combines invisible text watermarks with digitally signed provenance metadata for supported files. This move follows Anthr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and advanced security testing. Built on the foundati…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encryp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


