Cloud SecurityCritical Azure Cosmos DB flaw risked cross-tenant compromiseSteve ZurierJuly 30, 2026Patched Azure Cosmos DB bug threatened Microsoft and customer databases.
AI/MLOpenAI agent exploited JFrog Artifactory flaw, abused Modal customer sandboxLaura FrenchJuly 30, 2026Hugging Face and OpenAI revealed further details on the agent’s 4.5-day attack campaign.
Incident ResponseEffective incident response plans elusive for most cybersecurity teamsSteve ZurierJuly 29, 2026Experts say untested incident response plans leave firms unprepared.
Vulnerability ManagementIPMI bug in BMCs found after 22 years, exposes 24,000-plus serversSteve ZurierJuly 28, 2026Decades-old IPMI bug leaves thousands of internet-facing servers exposed.
Vulnerability ManagementCheckPoint authentication bypass bug exploited, added to CISA listSteve ZurierJuly 27, 2026CISA orders rapid patching as Check Point auth bypass faces active attacks.
Critical Infrastructure SecurityUS warns of Iran-linked attacks on critical infrastructureSteve ZurierJuly 24, 2026Iran-linked hackers target Siemens, Schneider, Rockwell OT.
Application securityAI is overwhelming patch management. Here’s how teams adaptSteve ZurierJuly 23, 2026AI is overwhelming patch teams, forcing a shift to smarter, automated remediation.
AI/MLHugging Face ‘attacker’ revealed to be OpenAI agents that escaped testing sandboxLaura FrenchJuly 22, 2026OpenAI said GPT-5.6 Sol and a pre-release model exploited vulnerabilities to “cheat” on ExploitGym.
IdentitySharePoint vulnerability steals machine keys; fourth recent exploitSteve ZurierJuly 22, 2026New SharePoint flaw exploited as attackers steal machine keys for lasting access.
Application securityJADEPUFFER agentic ransomware returns, targets AI assets with ENCFORGE payloadLaura FrenchJuly 22, 2026The agent abused the victim’s Docker daemon to access and encrypt AI-related files.
The best defense against an AI attacker might be its own safety trainingHarshad Sadashiv KadamJuly 30, 2026