Latest News

Guides

CISA Guidance on Isolating Vital Systems

The US and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack.

Vulnerabilities

Anthropic Uncovers Encryption Flaws with Claude Mythos

Anthropic's AI system, Claude Mythos, found weaknesses in HAWK and AES encryption algorithms, highlighting the need for ongoing cryptographic analysis and PQC readiness.

Analysis

Jay Clayton Confirmed as Director of National Intelligence

The Senate confirmed Jay Clayton as the next director of national intelligence with a 51-47 vote, capping a turbulent process delayed by President Donald Trump's initial cancellation of his confirmation hearing.

Vulnerabilities

CVE-2026-16812: Arista Patches Zero-Day in VeloCloud Orchestrator

Arista has patched a maximum-severity command injection vulnerability in VeloCloud Orchestrator, which is being actively exploited in attacks, allowing remote attackers to access privileged functionality.

Vulnerabilities

CVE-2013-4786 Vulnerability Exposes 24,000 Server BMCs

Over 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller interface.

Threats

Minnesota Water Utilities Hit by Coordinated Cyberattack

A coordinated cyberattack disrupted water and wastewater utilities in over 30 Minnesota communities, with the state's technology bureau providing guidance on response efforts.

Vulnerabilities

SSO Security Against Credential Attacks

Single sign-on (SSO) simplifies access but concentrates risk, as seen in the 2025 University of Pennsylvania breach, where attackers compromised a PennKey SSO account, resulting in the theft of data on 1.2 million individuals.

← Prev 1 1920212223 111 Next →