(Adobe Stock) React2Shell bug exploited by China-linked groups, fix briefly disrupts CloudflareSteve ZurierDecember 5, 2025React2Shell shows patching must be immediate — attackers now weaponize flaws within hours.
From governance to power: How America’s new NSS reframes cyber and critical infrastructureCory SimpsonDecember 7, 2025
Securing America’s ports: Hidden maritime security threats from foreign-owned and operated technologyEd HarrisDecember 7, 2025
North Korean hacker infected by malware, exposing ties to $1.4 billion Bybit heistSC StaffDecember 5, 2025
Spyware maker Intellexa accused of remote access to customer surveillance systemsSC StaffDecember 5, 2025
The future of workforce access: Why security leaders must get password-smartBill BrennerDecember 1, 2025
RansomwareEvolving fake resume campaign leads to RedLoader, ransomware infectionLaura FrenchDecember 5, 2025A threat group known as GOLD BLADE is evolving its tactics to deploy RedLoader and QWCrypt.
AI/MLCybersecurity startup 7AI raises record $130M to scale agentic AIStephen WeigandDecember 5, 20257AI’s record funding underscores rising confidence in agentic AI to transform security operations.
Threat IntelligenceChina-linked threat actor WARP PANDA targets US entities with BRICKSTORMLaura FrenchDecember 5, 2025The group targets VMware vCenter environments, gaining initial access through edge devices.
Application securityMCP servers emerge as new supply chain risk as real attacks accelerateOWASP GenAI Security Project Team December 5, 2025Recent MCP breaches show how privileged servers enable data theft, stressing need for strict controls.
RansomwareRansomware attack on Marquis Software Solutions targeted 74 banksSteve ZurierDecember 4, 2025Data from over 400,000 users stolen in a ransomware attack on SonicWall firewall.
Application securityCISA issues joint guidance on secure use of AI in OT systemsLaura FrenchDecember 4, 2025The document outlines four key principles to follow when considering AI use in OT.
Application securityIndia backs off from requiring government-made security appSteve ZurierDecember 3, 2025Experts preferred EU approach of mandating security outcomes on vendors versus a government app.
AI/MLClaude Agent Skills could be used to deploy malware, researchers sayLaura FrenchDecember 3, 2025An attacker could distribute a malicious Skill that quietly retrieves external scripts.