New Relic Launches Knowledge Layer to Accelerate AI-Driven Troubleshooting
New Relic has introduced a new intelligence layer designed to enhance AI-driven observability by correlating real-time telemetry with historical operational data.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,727 stories synthesized.
New Relic has introduced a new intelligence layer designed to enhance AI-driven observability by correlating real-time telemetry with historical operational data.
A sophisticated Linux-based Remote Access Trojan dubbed Quasar Linux (QLNX) has been identified targeting software developers to steal cloud, repository, and package-publishing credentials.
Observability platform groundcover has launched a suite of new features for Synthetic Monitoring and Real User Monitoring, including a privacy-focused Session Replay tool designed to keep telemetry data within customer-controlled cloud environments.
ServiceNow has introduced its Autonomous Security & Risk platform, integrating technology from Veza and Armis to provide centralized governance for AI agents, identities, and connected assets.
Google has introduced an expanded Binary Transparency initiative for Android that uses a public, cryptographic ledger to verify the authenticity of its production applications and prevent supply chain attacks.
Megaport has introduced a new fabric-native DDoS protection service that filters malicious traffic directly within its network to reduce latency and eliminate the need for external scrubbing centers.
Threat actors are leveraging a custom plugin called Pheno to hijack the Microsoft Phone Link application, allowing them to steal SMS messages and OTPs directly from Windows PCs without compromising the user's mobile device.
CrowdStrike has expanded its real-time cloud detection and response to Google Cloud and introduced new services to monitor shadow AI and enhance threat hunting within Microsoft Defender environments.
Oracle is moving to a monthly security update cadence to address high-priority vulnerabilities faster, leveraging AI-driven detection to speed up the remediation lifecycle.
The United Arab Emirates is facing a massive surge in cyberattacks, with daily breach attempts reaching up to 800,000 as regional geopolitical tensions escalate.
CISA has mandated that federal agencies urgently patch a critical cPanel zero-day vulnerability that was exploited by attackers for months before a fix was released.
Palo Alto Networks is addressing a critical, actively exploited zero-day vulnerability in its PAN-OS software that allows unauthenticated attackers to gain root-level remote code execution on firewall appliances.
India’s securities regulator has ordered financial market participants to urgently harden their systems against the threat of AI-accelerated cyberattacks, specifically citing risks posed by Anthropic’s Mythos vulnerability-finding tool.
The SANS Internet Storm Center has issued an urgent alert regarding a new NGINX vulnerability and a zero-day exploit targeting Cisco systems, prompting calls for heightened vigilance across enterprise networks.
ABB has patched a medium-severity vulnerability in its B&R PVI software that could allow local attackers to harvest sensitive credentials from application log files.
Johnson Controls has released patches for a high-severity DLL hijacking vulnerability in its CEM AC2000 access control system that could allow local attackers to escalate privileges.
Hitachi Energy has disclosed a path traversal vulnerability in its PCM600 software caused by an outdated third-party library, potentially allowing attackers to overwrite arbitrary files.
ABB has issued patches for a resource allocation vulnerability in its B&R Automation Runtime that could allow remote, unauthenticated attackers to cause a permanent denial-of-service condition.
ABB has patched a high-severity certificate validation vulnerability in its B&R Automation Studio software that could allow attackers to intercept and spoof secure industrial communications.
A deterministic local privilege escalation vulnerability in the Linux kernel's AF_ALG cryptographic interface, dubbed Copy Fail, allows unprivileged attackers to gain root access on virtually all major distributions released since 2017.
A newly discovered Linux malware strain called Quasar Linux (QLNX) is targeting software developers with a sophisticated suite of rootkit, backdoor, and credential-stealing tools designed for long-term, stealthy persistence.
The ShinyHunters extortion group claims to have stolen 280 million records from Instructure, the provider of the Canvas learning management system, affecting thousands of educational institutions worldwide.
Cybersecurity firm Trellix has confirmed that an unauthorized party accessed a portion of its source code repository, prompting an ongoing forensic investigation.
Chinese-speaking threat actors have compromised the official Daemon Tools website to distribute a multi-stage backdoor through trojanized software installers.