Latest Articles
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more thanΒ 1,300 packages with a combined 2 billion monthly downloadsΒ on the Node Package Manager (n...
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls....
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind....
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access....
New Tool Traces AI Videos Back to Their Source
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures....
Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues
Last month's incidents in which the AI model breached real-world systems derived from over-permissioning, especially with Internet access....
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks....
Is There Really a Fix for CISO Fatigue?
Accountability without any real authority is driving CISO burnout, and organizations need to take notice....
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements....
The Morning After We Pull a Root of Trust, Nobody Owns It
The most valuable move any security team can make is building a certificate and key inventory....