AIChaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day bypassing the CVE-2026-50656 patch to achieve SYSTEM-level code execution. The vulnerability highlights an incomplete fix in Defender for Windows.
AIChina-linked threat actor Storm-1175, a former Medusa affiliate, deployed new StormEncryptor ransomware, likely exploiting an N-central flaw, according to Microsoft and BleepingComputer reports.
AILiteLLM's PyPI packages v1.82.7 and v1.82.8 were compromised with credential-stealing code, impacting over 2,500 organizations in a supply chain attack linked to the Trivy breach.
AICisco warns CVE-2026-20349, a high-severity unauthenticated DoS flaw in ASA and FTD firewall software, is being actively exploited to remotely crash devices. Patches are available.
AINorth Korea's Lazarus group exploited Windows zero-day CVE-2026-68820 in fake job offers targeting defense firms. Microsoft's August 2026 Patch Tuesday fixed the flaw among 400+ vulnerabilities, including other disclosed zero-days.
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decis...
DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-laye...
Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to...
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, ...
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activ...
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" ha...
AIA cyberattack on logistics firm CEVA disrupted operations at eight European warehouses, affecting retailers and Steam hardware deliveries. The incident may have exposed delivery and order data belonging to some Steam customers.
AI737 malicious Chrome VPN extensions impersonating known services routed users' browser traffic through a single provider's SOCKS5 proxies, mainly targeting Russian-speaking users seeking blocked content. Users should check installed extensions and remove any matching these fake add-ons.
China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against...
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, ...
Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.