First Recon AI Launches Security Runtime to Govern Enterprise AI Usage
First Recon AI introduces its AI Security Runtime platform, offering enterprises a way to govern and secure AI interactions with audit-ready evidence.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,727 stories synthesized.
First Recon AI introduces its AI Security Runtime platform, offering enterprises a way to govern and secure AI interactions with audit-ready evidence.
Cloudflare's Research team has developed Meerkat, an experimental global consensus service utilizing the QuePaxa algorithm to manage control-plane state across its data centers.
A novel 'ghost phishing' campaign by EvilTokens uses browser-side decryption to hide malicious content, bypassing traditional email security checks and targeting Microsoft 365 accounts.
A new offensive cybersecurity startup, IRIS C2, which claims to acquire zero-day exploits for millions, is reportedly run by convicted felons Jack Burkman and Jacob Wohl, known for past disinformation campaigns.
Threat actors are leveraging agentic AI to reduce complex cloud compromise campaigns from weeks to mere days, according to a new Sygnia report.
Proof-of-concept exploit code is now available for CVE-2025-53770, a critical RCE vulnerability in on-premises Microsoft SharePoint Server, increasing the risk of widespread exploitation.
Mandatory driver-monitoring systems in new EU cars, set to expand globally, are raising significant privacy and security concerns among experts.
A newly discovered vulnerability allows attackers to rewrite signed Git commits, altering their hashes while maintaining valid signatures and GitHub's 'Verified' status, potentially deceiving reviewers.
A novel exploit chain named IonStack demonstrates a critical vulnerability in Android 17, allowing full device control with a single URL click by chaining two zero-day exploits.
As passkeys become the norm, cybercriminals are shifting from credential stuffing to compromising identity verification and recovery processes for account takeovers.
Japanese telecom giant KDDI has disclosed a significant data breach impacting over 12 million individuals, with attackers accessing an email platform and exposing email addresses and passwords.
Researchers discovered that GitHub Copilot can be tricked into generating malicious code by breaking down requests into seemingly innocuous steps within its code editor interface, bypassing chat-based safety filters.
A joint Five Eyes intelligence alliance statement highlights the growing threat of AI in cybersecurity, warning that advanced AI models are rapidly diminishing the need for deep technical skill to launch sophisticated attacks.
Trail of Bits' open-source mutation testing engine, Mewt, now supports DAML, improving the assessment of test suite effectiveness for Canton Network applications.
Key findings • Seven vulnerabilities disclosed across multiple Perl modules including DBI, String::Util, and Mojo::JSON. • Issues range from denial-of-service and code injection to heap overf…
A significant majority of WordPress websites are running outdated PHP versions, leaving them vulnerable to known exploits and cyberattacks.
Automox MCP Server 2.2 introduces visual review capabilities and AI-driven patch policy creation, offering IT teams more contextual and trustworthy control over endpoint operations.
ESET's latest report reveals over 25,000 malicious AI skills designed to steal data, execute malware, and manipulate AI agents, significantly expanding the AI attack surface.
A new AI cybersecurity clearinghouse, mandated by executive order, aims to coordinate vulnerability discovery and patching in critical infrastructure, but faces challenges in accelerating the slow process of fixing and deploying patches.
ESET's H1 2026 threat report highlights the rapid growth of AI skills, the emergence of AI-powered Android malware like PromptSpy, and evolving phishing tactics including record quishing levels.
Ubiquiti has released urgent security updates for its UniFi OS, patching seven critical vulnerabilities, including a maximum-severity flaw that allows for command injection attacks.
A newly released stack simulator tool from SANS instructor Xavier Mertens aims to demystify stack memory operations crucial for malware analysis and reverse engineering.
A 15-year-old Linux kernel vulnerability, dubbed GhostLock, has been disclosed, allowing any logged-in user to achieve root privileges and escape containerized environments on unpatched systems.
A wave of new open-source cybersecurity tools is emerging, addressing critical areas from AI security and vulnerability research to container security and penetration testing.