CISA adds ConnectWise, Microsoft flaws to KEV catalogLaura FrenchApril 30, 2026The Windows flaw stems from an incomplete patch of a vulnerability exploited by APT28.
4 ways to build resilience in an era of geopolitical tension and rising AI threatsSteve DurbinApril 28, 2026
Trust or fail: AI unlocks the value of unstructured data but raises new challenges for AI successPaul WagenseilApril 28, 2026
Controlling AI at machine speed: Detecting risk, protecting systems, and reversing mistakesPaul WagenseilApril 24, 2026
Your SOC, not the vendor’s: Why the AI SOC has to be customizable, not a black boxPaul WagenseilApril 20, 2026
AI as the defender: Reinventing proactive cybersecurity through intelligent automationPaul WagenseilApril 16, 2026
AI/MLLiteLLM exploited within 36 hours of disclosure via SQL injection bugSteve ZurierApril 29, 2026Latest case was the second time in five weeks the Python package was exploited.
RansomwareTeamPCP-linked VECT 2.0 ransomware unintentionally destroys files larger than 128 KBLaura FrenchApril 29, 2026Researchers revealed several “amateur” mistakes made in Windows, Linux and ESXi variants.
IdentityMicrosoft patches Entra ID bug that let AI agents escalate privilegesSteve ZurierApril 28, 2026Flaw in Entra ID AI agent role enabled privilege escalation and takeover.
Threat ManagementGlassWorm attackers activate new ‘sleeper’ extensions on Open VSXLaura FrenchApril 28, 2026A new cluster of 73 extensions impersonating legitimate projects has been tied to the GlassWorm campaign.
Threat ManagementMedtronic says cyberattack did not disrupt its operationsSteve ZurierApril 27, 2026Attack raised concerns because it was second one on a major medical device maker since the Iran war started.
Application security‘AiFrame’ browser attacks continue with fake authenticator, converter extensionsLaura FrenchApril 24, 2026The malicious extensions inject iframes to display phishing content and extract other data.
RansomwareUNC6692 impersonates help desk employees to drop SNOW malware via TeamsSteve ZurierApril 24, 2026Attackers abuse Teams chat to deliver malware after help desk phishing scam.
RansomwareTrigona ransomware attackers use novel tool for data exfiltrationLaura FrenchApril 24, 2026The uploader_client.exe command-line utility allows for rapid and granular data theft.