You survived the click—but now the click has evolved. In Part 2, the crew follows phishing and ransomware down the rabbit hole into double extortion, initial access brokers, cyber insurance drama, and the unsettling rise of agentic AI that can click, run scripts, and make bad decisions for you. The conversation spans ransomware economics, why payin...
Ongoing attacks involving the high-severity missing authorization bug impacting Digiever DS-2105 Pro network video recorders, tracked as CVE-2025-52163, have prompted the issue's inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, with federal civilian executive branch agencies urged to mitigate the weakness or retire impacted instances by Jan. 12, reports The Hacker News.
BleepingComputer reports that MongoDB has advised the urgent patching of the high-severity flaw, tracked as CVE-2025-14847, which could be abused to allow remote code execution and server takeovers.
Threat actors have launched attacks exploiting the half-decade-old medium-severity improper authentication vulnerability in Fortinet's FortiOS SSL VPN, tracked as CVE-2020-12812, according to Security Affairs.
It’s the holidays, your defenses are down, your inbox is lying to you, and yes—you’re gonna click the link. In Part 1 of our holiday special, Doug White and a panel of very smart people explain why social engineering still works decades later, why training alone won’t save you, and why the real job is surviving after the click. From phishing and sm...
The vulnerability emerged due to Cursor's use of the Model Context Protocol to connect AI assistants within the IDE to external tools, databases, and APIs, enabling more autonomous development workflows.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.