Cisco releases open-source ‘DNA test for AI models’Laura FrenchMay 1, 2026The Model Provenance Kit allows organizations to trace model origin and similarity.
4 ways to build resilience in an era of geopolitical tension and rising AI threatsSteve DurbinApril 28, 2026
New software supply chain attack uses sleeper packages for credential theft and CI tamperingSC StaffMay 1, 2026
Vietnamese operation uses Google AppSheet for Facebook phishing, targets 30,000 accountsSC StaffMay 1, 2026
Trust or fail: AI unlocks the value of unstructured data but raises new challenges for AI successPaul WagenseilApril 28, 2026
Controlling AI at machine speed: Detecting risk, protecting systems, and reversing mistakesPaul WagenseilApril 24, 2026
Your SOC, not the vendor’s: Why the AI SOC has to be customizable, not a black boxPaul WagenseilApril 20, 2026
AI as the defender: Reinventing proactive cybersecurity through intelligent automationPaul WagenseilApril 16, 2026
Security OperationsSonicWall releases firmware updates for three CVEsSteve ZurierMay 1, 2026SonicWall patches 3 flaws; experts warn ransomware actors may quickly exploit unpatched firewalls.
Threat ManagementMicrosoft: QR code, CAPTCHA-gated phishing more than double in Q1 2026Laura FrenchMay 1, 2026The company detected about 8.3 billion email-based phishing threats between January and March.
Application security‘Copy Fail’ bug can obtain root privileges in Linux distributions since 2017Steve ZurierApril 30, 2026AI-found Linux flaw enables easy root access, heightening risk across cloud and shared systems.
Vulnerability ManagementCISA adds ConnectWise, Microsoft flaws to KEV catalogLaura FrenchApril 30, 2026The Windows flaw stems from an incomplete patch of a vulnerability exploited by APT28.
AI/MLLiteLLM exploited within 36 hours of disclosure via SQL injection bugSteve ZurierApril 29, 2026Latest case was the second time in five weeks the Python package was exploited.
RansomwareTeamPCP-linked VECT 2.0 ransomware unintentionally destroys files larger than 128 KBLaura FrenchApril 29, 2026Researchers revealed several “amateur” mistakes made in Windows, Linux and ESXi variants.
IdentityMicrosoft patches Entra ID bug that let AI agents escalate privilegesSteve ZurierApril 28, 2026Flaw in Entra ID AI agent role enabled privilege escalation and takeover.
Threat ManagementGlassWorm attackers activate new ‘sleeper’ extensions on Open VSXLaura FrenchApril 28, 2026A new cluster of 73 extensions impersonating legitimate projects has been tied to the GlassWorm campaign.