(Adobe Stock) Apple fixes zero-day that exploited OS bug in open-source codeSteve ZurierFebruary 12, 2026Apple patches exploited zero-day in open-source component across iOS, macOS, watchOS.
The AI threat isn’t one exploit: It’s attackers hijacking trusted workflowsJack NaglieriFebruary 12, 2026
Infrastructure is affordability: Investing in systems that shape daily lifeCory SimpsonFebruary 11, 2026
SASE’s role in securing AI adoption: How existing tools can manage AI securityPaul WagenseilJanuary 22, 2026
Hackers, surprises and outer space: What we’ll see at Zero Trust World 2026Paul WagenseilJanuary 20, 2026
Threat ManagementFoxveil malware loader abuses Discord, Cloudflare, Netlify for stagingLaura FrenchFebruary 12, 2026The loader uses a novel string mutation mechanism and in-memory execution to evade detection.
Security OperationsPublished CVEs could hit record-breaking 50,000-plus in 2026Stephen WeigandFebruary 12, 2026FIRST forecasts 50K-plus CVEs in 2026 could strain security teams and planning.
Application securityConduent case breaks open after Volvo reports third-party compromiseSteve ZurierFebruary 11, 2026Conduent incidents reveal how third-parties must move to a disclosure-first model.
AI/MLAI-generated React2Shell malware infects 90-plus hostsLaura FrenchFebruary 11, 2026The malware was discovered through a Docker honeypot and is used for cryptojacking.
Security OperationsSSHStalker botnet hijacks 7,000 Linux systems using IRC and SSHSteve ZurierFebruary 10, 2026SSHStalker blends IRC control with automated SSH attacks; compromise 7K cloud-hosted Linux systems.
RansomwareSmarterMail vulnerabilities exploited in ransomware campaignsLaura FrenchFebruary 10, 2026CVE-2026-23760 and CVE-2026-24423 could both lead to RCE and are under active exploitation.
Application securityAIBOM generator finds new home at OWASP to boost AI transparencyOWASP GenAI Security Project Team February 10, 2026AIBOM Generator joins OWASP, advancing community-led AI supply chain transparency and security.
Endpoint/Device SecurityEmergency patches advised after attacks on Ivanti EPMM devicesSteve ZurierFebruary 9, 2026Exploited Ivanti EPMM RCEs hit agencies, prompting emergency patching amid fears of global spread.