AI-Generated Code Creates Governance Crisis for Software Security
The rapid adoption of AI-generated code is outpacing traditional security practices, creating a significant governance challenge and accelerating the accumulation of security debt.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,725 stories synthesized.
The rapid adoption of AI-generated code is outpacing traditional security practices, creating a significant governance challenge and accelerating the accumulation of security debt.
APT-C-60's latest SpyGlace campaign leverages legitimate developer platforms like GitHub and GitLab, combined with a chain of trusted Windows tools, to deliver malware and evade network defenses.
A sophisticated phishing campaign, dubbed Operation Capsule Vault, is weaponizing genuine academic event materials to lure researchers into downloading a variant of the RokRAT malware.
Healthcare diagnostics provider Centers Laboratory has reported a data breach affecting over 540,000 individuals, with sensitive personal and health information exfiltrated by the WorldLeaks extortion group.
A forgotten Python HTTP server inadvertently exposed the operational materials for three active adversary-in-the-middle (AiTM) phishing campaigns, offering a rare glimpse into attacker methodologies.
Microsoft has released an emergency patch for a zero-day vulnerability in Microsoft Defender, CVE-2026-33331, which was actively exploited by the RoguePlanet malware to execute arbitrary code on affected systems.
Cynative is a new open-source security research agent designed to safely probe cloud environments by defaulting to read-only operations and implementing strict checks against unintended modifications.
A critical vulnerability in Motorola MR2600 Wi-Fi routers allows unauthenticated local attackers to execute arbitrary code by uploading a malicious firmware image, potentially leading to full network compromise.
Researchers at the University of Florida have developed VeriChat, an AI-powered conversational assistant designed to identify malicious circuitry and hidden backdoors in integrated circuit designs.
A new report from Orca Security reveals a critical gap in AI security, with nearly all fixable vulnerabilities in AI deployments left unaddressed, exposing organizations to significant risks.
Official SpaceX and Starlink X accounts were briefly compromised to promote a fraudulent cryptocurrency, leading to a 'rug-pull' scam that defrauded investors.
Researchers have detected a significant increase in internet-wide scanning activity specifically targeting Model Context Protocol (MCP) servers and AI assistant configuration files, posing a threat to sensitive internal systems.
Microsoft is testing a new Windows 11 Copilot feature called 'PC Insights' that uses AI to analyze system performance and identify hardware bottlenecks.
Key findings • CVE-2008-4128, a Cisco vulnerability, is now confirmed actively exploited in the wild. • CISA added this flaw to its Known Exploited Vulnerabilities catalog on July 13, 2026. …
The European Union has imposed sanctions on nine individuals and four entities linked to a Russian cyber-espionage network accused of targeting critical infrastructure and governments across at least nine countries since 2010.
Debian 13.6 (trixie) has been released, fixing an expired UEFI Secure Boot certificate issue and patching more than a hundred security advisories across various software packages.
A new open-source penetration testing framework, KittySploit, integrates local AI agents for autonomous attack path planning, featuring over 1,150 modules and a hybrid Python/Zig core.
This week's cybersecurity news features a 16-year-old Linux KVM escape vulnerability, numerous flaws in Ubiquiti's UniFi ecosystem, and innovative methods for data theft from air-gapped systems.
Apple has filed a federal lawsuit against OpenAI and former employees, accusing the AI company of orchestrating a systematic campaign to steal confidential hardware designs and trade secrets.
Version 8.14.0 of the jscrambler npm package was compromised, silently installing and executing a native infostealer on Windows, macOS, and Linux systems.
A bug in Microsoft Teams for macOS is causing blank screens or freezes during screen sharing, primarily impacting government cloud tenants.
Key findings • Ten ImageMagick vulnerabilities disclosed between July 9-11, 2026, with moderate to low severity. • Multiple vulnerabilities related to memory management, including use-after-f…
Researchers have developed 'Ghostcommit,' a novel technique that embeds malicious prompt injection instructions within PNG image metadata to bypass AI code reviewers and trick coding agents into exfiltrating sensitive repository secrets.
A critical vulnerability in Dell's BIOS password storage mechanism allows attackers with physical access to recover administrator and user passwords in mere milliseconds.