CVE-2026-50751: Patching is Not Enough
A recent emergency directive from CISA highlights the limitations of patching in preventing cyber attacks, as a vulnerability in Check Point's Remote Access VPN was exploited by a Qilin ransomware affiliate.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
A recent emergency directive from CISA highlights the limitations of patching in preventing cyber attacks, as a vulnerability in Check Point's Remote Access VPN was exploited by a Qilin ransomware affiliate.
An international operation has taken down 326 servers and 142 domains used by cybercrime gangs distributing SocGholish, Amadey, and StealC malware, with €41 million in crypto assets seized and 27 million stolen login credentials reclaimed.
Microsoft and law enforcement have teamed up to take down two widely-used cybercrime tools, Amadey and StealC, in a novel court-authorized disruption operation.
Microsoft releases Windows 11 KB5095093 update with new Point-in-Time restore feature, fixing numerous bugs and improving system reliability.
A new backdoor called Mistic has been linked to KongTuke, an initial access broker that sells compromised corporate networks to ransomware groups.
Agentic AI can make bad decisions confidently and quickly if given incomplete or inaccurate context, posing significant security risks.
AI agents can be manipulated by maliciously designed information, leading to unintended actions and security breaches, with content injection and semantic manipulation being two common types of traps.
A malicious Microsoft Edge extension called Edgecution has been used in a ransomware attack to deploy a Python-based backdoor by leveraging the Chrome Native Messaging protocol.
Operation Endgame has disrupted the infrastructure used by Amadey and StealC malware operations, resulting in the seizure of 326 servers and 142 domains, and the recovery of 27 million stolen credentials.