radar.cysentrix

Archive

Page 23 of 27 — 1595 stories total

← Back to radar
CyberScoop

ANCHOR-CI could fix 20 years of broken government-industry collaboration

The government spent the past two decades learning what private sector partners have always known: cyber resilience requires everyone in the room. ANCHOR-CI is proof that the lessons may finally stick. The post ANCHOR-CI could fix 20 years of broken government-industry collabo...

The Hacker News

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone n...

SecurityWeek

Assaf Keren Appointed New CISO of Meta

He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.

Help Net Security

PyPI hardens package security with new upload restrictions

The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the...

supply chain
SecurityWeek

New Check Point Zero-Day Vulnerability Exploited in the Wild

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.

vulnerabilityzero day Actively exploitedCVE-2026-16232 · EPSS 73%
Help Net Security

GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous boun...

vulnerability
Security Affairs

Check Point patches actively exploited SmartConsole authentication bypass flaw

Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authent...

vulnerabilityzero day Actively exploitedCVE-2026-16232 · EPSS 73%
SOCRadar

WhatsApp Usernames Explained: Privacy Gains and Scam Risks

WhatsApp Usernames Explained: Privacy Gains and Scam Risks How WhatsApp's shift from phone numbers to usernames changes privacy for users, and the brand and executive impersonation surface it opens for security teams. Ke

Help Net Security

Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements

Axonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelli...

vulnerabilitycloud
The Hacker News

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 ...

vulnerabilityzero day Actively exploitedCVE-2026-16232 · EPSS 73%
Help Net Security

Shadow AI is becoming enterprise security’s biggest blind spot

Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly...

Help Net Security

Product Showcase: AppViewX Agent Identity Security

AI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agen...

Help Net Security

Multi-patch vulnerability fixes can leave open source exposed

Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the ...

vulnerability
Help Net Security

The AI code vulnerabilities that grow with your app

Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. T...

vulnerability
Help Net Security

Building a defense in depth strategy for sensitive data

In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or turning on DLP, leaves gaps t...

Security Affairs

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), aff...

vulnerability
Security Affairs

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension tha...

vulnerability EPSS 2%
BleepingComputer

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]

data breach
The Record

Federal agencies broaden alert on Iran-linked OT attacks

The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.

The Hacker News

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date,...

The Hacker News

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8...

vulnerability
CyberScoop

Malware is targeting AI tools in software development environments

The worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development environments appeared first on CyberScoop.

malware
CyberScoop

White House accuses Chinese company of distilling Anthropic’s Fable

While distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on Cyb...

Microsoft Security

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resi...

microsoft
BleepingComputer

How enterprise GenAI can amplify ransomware risk — and how to contain it

Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure ...

ransomware
SecurityWeek

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek.

data breach
The Hacker News

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed Herm...

vulnerability
Help Net Security

OpenAI: Our models breached Hugging Face during a cyber capability test

The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its inter...

data breach
SOCRadar

CVE-2026-50522 PoC Fuels SharePoint Attacks

CVE-2026-50522 PoC Fuels SharePoint Attacks Attackers are exploiting CVE-2026-50522, a critical Microsoft SharePoint Server vulnerability, after public proof-of-concept (PoC) exploit code became available. The activity t

vulnerabilitymicrosoft Actively exploitedCVE-2026-50522 · EPSS 77%
Help Net Security

Astelia extends reachability analysis with agentic AI for vulnerability management

Astelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vulner...

vulnerabilitymicrosoft
Help Net Security

ThreatDown expands security visibility to AI tools and machine identities

ThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools...

Help Net Security

Swimlane AI SOC automates security operations for MSSPs

Swimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers. Some AI SOC providers are moving into managed services, turni...