Legacy VPN Purge Urged by Sen. Wyden
Sen. Ron Wyden calls for federal agencies to discard older, insecure public-facing VPNs and adopt modern, secure remote-access technology to prevent cyberattacks.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Sen. Ron Wyden calls for federal agencies to discard older, insecure public-facing VPNs and adopt modern, secure remote-access technology to prevent cyberattacks.
Mobile devices operate outside the security perimeter, making it difficult for security teams to understand the components and dependencies of applications, leaving them vulnerable to attacks.
A highly personalized phishing campaign used Telegram to target an exiled Belarusian activist and users in Russia and Kazakhstan, attempting to hijack their accounts with fake security alerts.
A proof-of-concept exploit for the Certighost vulnerability allows attackers to hijack Windows domains by manipulating machine account attributes and obtaining a certificate from Active Directory Certificate Services.
Shadow AI agents pose a significant risk to organizations, with 48% of cybersecurity professionals ranking them as the most dangerous attack vector of 2026.
Google's Threat Intelligence Group has introduced a new naming system for hackers, using memorable word pairs to identify threat actors and reduce confusion.
Hackers used an autonomous AI agent to spy on Thailand's Ministry of Finance, gaining access to multiple systems and stealing credentials, according to Hunt.io researchers.
A massive malvertising campaign uses fake webpages with malicious JavaScript to build malware directly in browser memory, targeting retail traders and crypto investors.
Nvidia and tech giants launch Open Secure AI Alliance to develop and share open source tools for securing AI systems and agents.