radar.cysentrix

Security Radar

Page 8 of 10 · 1555 stories from the last 30 days across 19 trusted sources.

The Hacker News

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments...

The Hacker News · SecurityWeek2 stories

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

AIAdobe patched critical ColdFusion, Commerce, and Campaign Classic flaws, including three CVSS 10.0 issues, that could enable arbitrary code execution, privilege escalation, and denial-of-service; immediate patching is urged.

Open narrative →
vulnerability
Show all coverage
Schneier on Security

Prompt Injections for Defense

This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompt...

Help Net Security

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, supp...

microsoft
Help Net Security

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud env...

cloud
SecurityWeek

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek.

zero daymicrosoft
Help Net Security

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrup...

Help Net Security · BleepingComputer2 stories

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

AIGoogle's Chrome anti-abuse systems now block over 7 billion unwanted Android notifications daily by revoking permissions for inactive or suspicious sites, curbing scams and phishing.

Open narrative →
phishing
Show all coverage
Security Affairs · The Hacker News · Unit 423 stories

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

AIResearchers detailed Kimwolf v7, an Android/IoT botnet upgrade that disguises HTTP/2 DDoS traffic as legitimate browsing, adds Ethereum ENS-based C2 resolution, and Tor backup routing for stronger resilience.

Open narrative →
malware
Show all coverage
SecurityWeek

Ivanti EPM Update Patches Remotely Exploitable Flaws

The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.

vulnerability
Help Net Security

Split-second deepfake glitch blows digital certificate fraudster’s cover

Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made 38 attempts using this met...

Help Net Security

Post-quantum migration gets harder when every user holds a key

In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size a...

Help Net Security

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discove...

Help Net Security

338 million attack simulations reveal the state of enterprise defense

First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from...

Help Net Security

Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found. Researchers discovered the scam project...