radar.cysentrix

Archive

Page 19 of 27 — 1565 stories total

← Back to radar
Help Net Security

Download: The High-Performance Team Playbook

Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built inten...

The Hacker News

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pa...

vulnerabilityzero day Actively exploitedCVE-2026-16812 · EPSS <1%
Help Net Security

Cybersecurity jobs available right now: July 28, 2026

Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain cloud security p...

microsoftcloud
BleepingComputer

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]

vulnerabilityzero day
CyberScoop

Microsoft debuts AI cybersecurity offerings as competition heats up

It includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop.

microsoft
Security Affairs

Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected

Reuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what ha...

data breach
BleepingComputer

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]

vulnerabilitymicrosoft
Help Net Security

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost

Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the company stat...

vulnerabilitymicrosoft
Dark Reading

Why Resetting Passwords No Longer Stops Attackers

As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.

The Hacker News

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI compani...

cloud
Security Affairs

MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data

MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user n...

malwaremicrosoft
The Record

UK court rejects Bahrain immunity claim in spyware case

The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court o...

data breach
Microsoft Security

Rethinking security for the age of AI

Why security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and complexity of wh...

Microsoft Security

Enhancing AI security through global AI red teaming

Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and s...

microsoft
Help Net Security

Tech giants form alliance to put open AI in cyber defenders’ hands

NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Open ...

The Hacker News

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Di...

zero day
SecurityWeek

New GitHub, PyPI Policies Boost Supply Chain Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek.

supply chain
BleepingComputer

Shadow AI agents are multiplying. Here's how to find and secure them.

Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]

Help Net Security

Zenity advances AI governance with Runtime Boundaries

Zenity has announced a major expansion of its platform, making it the AI security platform for autonomous AI built around a new security architecture designed to govern AI decisions before they become enterprise actions, including those made by long-horizon agents operating au...

Help Net Security

JetStream Security enables on-demand shutdown of compromised AI agents

JetStream Security has announced the release of an AI Kill Switch that allows organizations to shut down compromised AI agents on-demand without impacting other AI operations. This new control plane for AI agents solves the inability to stop a single agent that falters, begins...

Help Net Security

7AI expands platform with Federated SIEM and AI workflow builder

7AI has announced two major platform capabilities: 7AI Federated SIEM, which lets security teams query, investigate, and act on data wherever it lives, including within 7AI, and 7AI Build, which lets enterprises and partners define agentic workflows, skills, and AI-native secu...

Help Net Security

C1 adds shadow AI discovery to its identity governance platform

C1 has launched shadow AI discovery to eliminate the massive security blind spots created by unauthorized AI agents, tools, and credentials. By automatically discovering and folding every AI-adjacent identity into C1’s existing identity governance platform, organizations can f...

SecurityWeek

PTC Windchill Vulnerability Exploited in Ransomware Campaign

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek.

ransomwarevulnerability
Help Net Security

Google changes how it names cyber threat actors

Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over year...

Security Affairs

DentaQuest disclosed a data breach that impacted +23 million individuals

DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have expose...

data breach
The Hacker News

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for anoth...

vulnerability EPSS 9%
SecurityWeek

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityW...

malwaremicrosoft
CyberScoop

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech. The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

Help Net Security

Booz Allen expands Vellox Suite with AI-driven threat detection platform

Booz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identi...

The Hacker News

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft...

phishingmicrosoft
SecurityWeek

Nvidia and Tech Giants Launch AI Security Alliance

The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. The post Nvidia and Tech Giants Launch AI Security Alliance appeared first on SecurityWeek.

Help Net Security

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The ...

vulnerability EPSS 1%
CISA Alerts

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orche...

vulnerability Actively exploited · EPSS 1%
Security Affairs

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain

Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in ...

vulnerabilityzero day
Security Affairs

EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency

EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major s...

Help Net Security

ChatGPT joins the most impersonated brands in phishing attacks

Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, ...

phishingmicrosoft
SecurityWeek

Beelzebub Raises $3.4 Million for Hacker-Trapping Platform

The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platform appeared first on SecurityWeek.