(Adobe Stock) Medtronic says cyberattack did not disrupt its operationsSteve ZurierApril 27, 2026Attack raised concerns because it was second one on a major medical device maker since the Iran war started.
Tropic Trooper targets Chinese speakers with SumatraPDF trojan and VS Code tunnelsSC StaffApril 27, 2026
Controlling AI at machine speed: Detecting risk, protecting systems, and reversing mistakesPaul WagenseilApril 24, 2026
AI on the attack: How defenders turn artificial intelligence against cyber threatsPaul WagenseilApril 15, 2026
Code, control, and chaos: Rethinking security in the age of AI-driven developmentPaul WagenseilApril 13, 2026
Application security‘AiFrame’ browser attacks continue with fake authenticator, converter extensionsLaura FrenchApril 24, 2026The malicious extensions inject iframes to display phishing content and extract other data.
RansomwareUNC6692 impersonates help desk employees to drop SNOW malware via TeamsSteve ZurierApril 24, 2026Attackers abuse Teams chat to deliver malware after help desk phishing scam.
RansomwareTrigona ransomware attackers use novel tool for data exfiltrationLaura FrenchApril 24, 2026The uploader_client.exe command-line utility allows for rapid and granular data theft.
AI/MLAI-driven cloud attacks reach ‘functional’ maturity, says Unit 42Steve ZurierApril 23, 2026PoC proves that attackers can leverage AI to exploit cloud weaknesses at machine speed.
Supply chainNamastex npm packages compromised in ‘CanisterWorm’ supply chain attackLaura FrenchApril 23, 2026A self-propagating script was added to @automagik/genie and @pgserve packages.
Application securityAI-driven attacks target governments, cloud agents, supply chainsOWASP GenAI Security Project Team April 23, 2026OWASP: AI-driven attacks hit government, cloud and supply chains at scale.
AI/MLFirefox report offers early insight into Claude Mythos AI modelSteve ZurierApril 22, 2026AI model finds hundreds of bugs in Firefox, boosting defense — but also lowering barriers for attackers.
Vulnerability ManagementFlaw in Microsoft-owned GitHub repository allowed RCE via issue submissionLaura FrenchApril 22, 2026Attackers could have extracted a GITHUB_TOKEN secret, potentially enabling unauthorized changes.