radar.cysentrix

Archive

Page 11 of 26 — 1559 stories total

← Back to radar
CyberScoop

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on Cyber...

ransomwarevulnerabilityzero day
SecurityWeek

Oligo Raises $60 Million for Runtime Security

The company will use the investment to accelerate product innovation and expand go-to-market operations. The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek.

SecurityWeek

CISO Conversation: Russ Kirby – Passion Is the Antidote to Burnout

Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night. The post CISO Conversation: Russ Kirby – Passion Is the Antidote to Burnout appeared first on SecurityWeek.

Help Net Security

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in ...

malwaremicrosoft
BleepingComputer

Varonis Agent IBAC keeps AI agents within their intended boundaries

AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]

SecurityWeek

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared fir...

Help Net Security

Sevii APS Module preempts attacks with autonomous cyber defens

Sevii has announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module complements ADRs autonomous defense against threats, extending the platform to con...

SecurityWeek

Zenity Raises $125 Million in Series C Funding

The AI security company will invest in product innovation, global expansion, and customer experience. The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek.

Help Net Security

ServiceNow organizes autonomous security around six solution areas

ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and acces...

vulnerability
Help Net Security

Snyk unveils continuous AI pentesting and agent red teaming

Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually ex...

The Hacker News

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Manage...

phishing
SOCRadar

Dark Web Market: Vortex Market

Dark Web Market: Vortex Market Slug: /blog/dark-web-market-vortex-market/ SEO title: Dark Web Market: Vortex Market (2026 Analysis) Meta description: Vortex Market is a classic wallet escrow Dark Web marketplace with rou

Help Net Security

RapidFort Runtime brings continuous CVE monitoring and tamper detection

RapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source softwar...

vulnerabilitymalware
Unit 42

Almost Half of Malware Samples Communicate Direct to IP

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

malware
Security Affairs

CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access

A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CVE-2...

vulnerability
CISA Alerts

Thermo Fisher Applied Biosystems Genetic Analyzers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected...

vulnerability
CISA Alerts

Acrisure KARR BT and DR-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026 DR-100 firmware <July_20_2026 CVSS Ven...

vulnerability
CISA Alerts

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Cha...

vulnerability Actively exploited · EPSS 17%
Security Affairs

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8....

vulnerability Actively exploitedCVE-2026-18577 · EPSS 4%
Schneier on Security

Some Claude Chats Are Searchable on Google

And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cry...

Help Net Security

ESET introduces new AI capabilities for autonomous agent security

ESET is expanding its AI capabilities across threat detection, investigations, threat protection, and security operations, delivering added value to customers through built-in innovations rather than separate add-on solutions. “AI is a new class of actor inside the company – r...

CyberScoop

How companies could share cyber risks without exposing their secrets

A cryptographic technique could let companies prove they're vulnerable to critical flaws without revealing the sensitive data that attackers could exploit. The post How companies could share cyber risks without exposing their secrets appeared first on CyberScoop.

Help Net Security

Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package

Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one stops. The self-hosted monitoring tool is MIT licensed, runs in a container or on Node.js, and has 89,8...

supply chain
Help Net Security

Tanium expands autonomous security across AI, exposure management and SecOps

Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landsc...

Graham Cluley

Fake IRS letters target cryptocurrency holders

Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Securi...

SOCRadar

Why Was Telegram Removed From the App Store?

Why Was Telegram Removed From the App Store? Telegram briefly disappeared from the App Store worldwide on Monday night – no warning, no explanation, and no way for new users to download it. Why did it disappear? Is it ba

SecurityWeek

150,000 Impacted by Madera Community Hospital Data Breach

An extortion group stole personal, financial, and medical information from the hospital’s network. The post 150,000 Impacted by Madera Community Hospital Data Breach appeared first on SecurityWeek.

data breach
Help Net Security

Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for .NET developers. API keys created before August 17 will remain valid until November 1, after which devel...

microsoftsupply chain
The Hacker News

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CV...

vulnerabilityzero day
Help Net Security

EU begins enforcing AI Act, putting AI models under the microscope

Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell users wh...

Help Net Security

Digital executive protection is a strategic imperative for CEOs

In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor ...

Help Net Security

OWASP’s subtractive security project measures the attack paths you erased

An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz wants those capabilities deleted...