Jamf AI Governance for Mac Addresses Shadow AI and Policy Enforcement
Jamf has launched AI Governance for Mac, a new feature enabling organizations to discover, manage, and control the use of AI tools on their macOS devices.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,736 stories synthesized.
Jamf has launched AI Governance for Mac, a new feature enabling organizations to discover, manage, and control the use of AI tools on their macOS devices.
CISA's Binding Operational Directive 26-04 mandates federal agencies move from technical patch metrics to risk-based vulnerability prioritization and reporting, impacting federal contractors and influencing private sector standards.
SystemBC, a versatile malware known as Coroxy, is increasingly used by ransomware gangs to establish hidden persistence and proxy malicious traffic, now leveraging Tor for stealthier command-and-control.
A sophisticated 'Boss Scam' campaign is targeting Indian enterprises, combining social engineering with DLL sideloading to hijack WhatsApp Web sessions for CEO fraud and large-scale financial theft.
New AI capabilities allow intelligence agencies to query vast video archives using natural language, enabling behavioral analysis and unprecedented mass surveillance possibilities.
Threat actors pre-planned and deployed extensive fraud infrastructure targeting the FIFA World Cup 2026 months in advance, spanning multiple sectors and languages, according to Check Point Research.
A proof-of-concept exploit for CVE-2026-24294 demonstrates a new NTLM reflection bypass flaw affecting Windows Server 2025 and Windows 11 24H2, allowing SYSTEM-level access.
Insurance giant Aflac disclosed a data breach impacting its Japanese subsidiary, where attackers accessed systems and stole sensitive personal and financial data.
A suite of critical vulnerabilities in the wolfSSL embedded TLS library could allow attackers to forge certificates, execute remote code, and launch denial-of-service attacks across billions of devices.
Trail of Bits integrates NIST-standard post-quantum cryptography into the widely-used pyca/cryptography library, enabling Python applications to prepare for the quantum computing threat.
X has introduced hosted Model Context Protocol (MCP) servers, simplifying API access for AI tools like Cursor and Claude, while raising questions about write operation security.
The ToddyCat APT group has developed a new tool, Umbrij, to steal cloud email credentials by exploiting the OAuth 2.0 protocol through Google's API, employing a novel technique dubbed Shadow Token via Remote Debug (STRD).
Key findings • Three vulnerabilities in GPAC disclosed between June 28 and June 30, 2026. • Two use-after-free vulnerabilities (CVE-2025-60464, CVE-2025-60465) leading to Denial of Service. …
The Blackfield ransomware group is extorting Nidec Corporation for $2 million following a breach that impacted its Taiwanese subsidiary.
The UK's healthcare sector has experienced a dramatic tenfold increase in cyber-attacks during the first five months of 2026, with SonicWall reporting 264,000 security events.
Ransomware groups like Black Basta have evolved into sophisticated, corporate-style organizations, leveraging specialized teams and outsourcing to maximize profits through advanced extortion tactics.
CISA has confirmed that ransomware gangs are actively exploiting the BlueHammer vulnerability in Microsoft Defender, a privilege escalation flaw previously used in zero-day attacks.
Apple has released security updates for iOS, macOS, and Safari, addressing more than 30 vulnerabilities, with four in WebKit identified using AI tools.
Kali Linux 2026.2 has been released, featuring significant improvements to virtual machine boot times, the addition of nine new security tools including AI-powered options, and modernization of its package management system.
Researchers have uncovered six vulnerabilities in Apple's AirDrop and Google/Samsung's Quick Share protocols, impacting over five billion devices and potentially exposing sensitive data.
Microsoft is enhancing security for Teams meetings by introducing a 'bot bouncer' feature designed to prevent unauthorized bots from joining, addressing privacy and security concerns.
GitHub's Advisory Database is struggling to keep pace with a record influx of open-source vulnerability reports, leading to significant delays in publishing critical security information.
CISA warns of critical vulnerabilities in Daktronics controllers that could allow attackers to remotely manipulate highway signs and billboards, potentially displaying false information or taking full control of the devices.
A new open-source tool, OWASP Agent Memory Guard, aims to prevent AI agents from being compromised through their persistent memory stores.