Application securityJFrog Artifactory flaw exploited days after patch releaseSteve ZurierSeptember 1, 2026Attackers exploited a JFrog Artifactory flaw days after its patch, threatening software supply chains.
MalwareRevStealer malware spread through fake Claude Opus 5 downloadLaura FrenchSeptember 1, 2026The Windows infostealer uses several evasion measures to remain mostly invisible to security systems.
Critical Infrastructure SecurityChina-linked campaign targets high-value networks, critical infrastructureSteve ZurierAugust 31, 2026Fire Ant targets routers and authentication systems to spy, steal credentials and evade detection.
Vulnerability ManagementPaperCut issues emergency patches for actively exploited critical vulnerabilityLaura FrenchAugust 28, 2026Two flaws in the print management software could enable unauthenticated RCE.
AI/ML1,200 OpenAI agents colluded to cheat evaluations in lead-up to Hugging Face attackLaura FrenchAugust 28, 2026OpenAI and more than 100 other organizations are now calling for urgent collective action on cyber defense.
Critical Infrastructure SecurityUS denies access to China-linked group behind hacking federal agenciesSteve ZurierAugust 27, 2026DOJ and FBI seized China-linked cyber platforms used to target U.S. agencies and infrastructure.
AI/MLShadow AI surges as 80% of employee AI tools evade IT oversightLaura FrenchAugust 27, 2026Reco’s The State of Agent Security 2026 report highlights shadow AI, MCP risks and AI vulnerability trends.
Critical Infrastructure SecurityOver 100 US water utilities had cyberattacks in July, says CISASteve ZurierAugust 26, 2026More than 100 water systems faced attacks in July as CISA urges utilities to reduce OT exposure.
Application securityMobile banking trojans expand capabilities; 66% now allow full device takeoverLaura FrenchAugust 26, 2026Banking trojans have evolved to include remote control and ransomware capabilities.
Vulnerability ManagementCISA adds Oracle WebLogic bug to its list of exploited vulnerabilitiesSteve ZurierAugust 25, 2026Experts say exploiting WebLogic middleware gives attackers access to an enterprise's core business apps.