News Archive
561 stories · page 10 of 24Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Dairy producer Fairlife halts US production due to cyber incident
Fairlife, a major dairy company with over $1 billion in retail sales in 2022, has suspended its United States production operations. The company has facilities in Michigan, New York, and Arizona. The halt is reportedly due to a cyber incident impacting its systems.

Multiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM
Researchers have disclosed several vulnerabilities affecting WolfSSL, GeoVision, and VTK-DICOM. The issues include improper input validation and integer underflow in WolfSSL, and a range of problems in GeoVision such as memory corruption, OS command injection, buffer overflows, and privilege escalation. These vulnerabilities have been addressed by the respective vendors.

Tennis Analogy Highlights Cybersecurity's Imperfect Nature
A cybersecurity professional uses a tennis analogy to challenge the common notion that defenders must be perfect while attackers only need one success. By referencing Roger Federer's career statistics, the author illustrates that winning a match, much like cybersecurity, doesn't always equate to winning every single point. The key lies in winning the crucial points and understanding the strategic nuances of the game.

New Helix Group Targets SharePoint Data via Vishing and MFA Abuse
A newly identified cybercriminal group, known as Helix, is employing sophisticated identity-based attacks to exfiltrate data from SharePoint environments. Their methods include voice phishing, device code phishing, and the abuse of multi-factor authentication systems.

AI to Drive More Windows Security Updates, Microsoft Says
Microsoft anticipates a rise in security updates for Windows due to its growing use of artificial intelligence. The company is leveraging AI to proactively identify vulnerabilities within its software, aiming to enhance overall system security.
Forg365 Phishing Platform Leverages AI for Microsoft 365 Account Theft
A new phishing-as-a-service operation, dubbed Forg365, is targeting Microsoft 365 accounts. This platform employs a combination of adversary-in-the-middle techniques and device code methods, enhanced by AI-generated lures to trick users into compromising their accounts.

Summer Staffing Shortages Expose IT Security Risks
Reduced IT staffing during summer vacation periods can create significant security vulnerabilities. Organizations are advised to leverage AI-driven automation to maintain consistent security operations and minimize reliance on manual processes, ensuring protection remains robust even with fewer personnel.

Microsoft to Retire OWA Light Client in Exchange Server
Microsoft is planning to remove Outlook Web Access (OWA) Light, a simplified version of its web-based email client, in an upcoming Exchange Server update. This move will likely encourage users to adopt the full Outlook Web App for a more feature-rich experience.

AI Coding Tools Vulnerable to Decades-Old Hacking Technique
Researchers have uncovered a vulnerability in AI coding assistants that allows them to be tricked into executing malicious code. This attack, named GhostApproval, leverages a long-standing technique to compromise a developer's machine through the AI tool. The exploit highlights potential security risks associated with the integration of AI into software development workflows.

Chrome 150 Update Fixes 27 Security Flaws
Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

8Layers Secures $2.9 Million for Identity Security Platform
Spanish startup 8Layers has successfully raised $2.9 million in an extended pre-seed funding round. This capital infusion comes just two months after the company launched its digital identity protection platform, signaling strong investor confidence in its market potential.

AI Coding Agents Can Be Tricked Into Executing Malicious Code
Researchers have demonstrated a vulnerability in AI coding agents, such as Anthropic's Claude Code and OpenAI's Codex, where they can be manipulated into executing malicious code instead of identifying security flaws. This 'Friendly Fire' attack exploits the autonomous mode of these agents, potentially leading them to run harmful code on the user's system.

Tenda Firmware Vulnerability Allows Unauthenticated Admin Access
A critical backdoor vulnerability has been discovered in Tenda device firmware, identified as CVE-2026-11405. This flaw enables unauthenticated attackers to gain administrative control over affected devices by accessing their web management interface. The vulnerability remains unpatched, posing a significant risk to users.

Fake 7-Zip Installers Hijack Devices for Proxy Network
A threat group known as Lurking Lizard has established a large-scale residential proxy network using over 230 fake domains. This operation, active since at least August 2022, leverages compromised devices, including those infected via fake 7-Zip installers, to route traffic for malicious purposes.

Honeypot Researcher Finds Bot's Plea for Help
A honeypot researcher discovered a peculiar scanning bot that uses a URL path as a plea for help, seemingly from someone in Belarus. The bot, which scans for open ports and sends basic HTTP requests, appears to be intentionally limited and not malicious. The author claims the bot's purpose is to draw attention to their situation.

When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed First
The increasing speed at which AI models discover software vulnerabilities, particularly in open-source components, is outpacing the ability of organizations to patch them. This necessitates a shift in risk prioritization, focusing on exploitability rather than just severity scores. An industry coalition called Athena aims to accelerate the defense of open-source software, while tools like those from Qualys help organizations identify which discovered vulnerabilities are actively being exploited and require immediate attention.

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti has released security updates to address seven vulnerabilities in its UniFi OS, including several critical flaws. One critical vulnerability, CVE-2026-50746, allows for command injection in the UniFi Connect Application, impacting systems that manage building infrastructure like smart lighting and EV chargers. Other patched issues include SQL injection, improper input validation, and SSRF vulnerabilities across various UniFi applications, potentially leading to privilege escalation.

Greek victims sue Intellexa over Predator spyware
Victims in Greece have filed a lawsuit against Intellexa, the company behind the Predator spyware. The spyware's use was revealed in 2022, with evidence found on numerous phones. This revelation previously resulted in the resignations of the head of Greece's intelligence service and the prime minister's chief of staff.

Cash App Owner to Pay $45 Million Over Lax Security Claims
Block, Inc., the owner of Cash App, has agreed to pay $45 million to settle allegations that it misrepresented the security protections offered to its users. State attorneys general stated that the company incorrectly claimed Cash App provided the same level of security as traditional banks.

Accenture Confirms Security Incident After Hacker Claims 35GB Source-Code Theft
Accenture has acknowledged a security incident after a threat actor advertised what they claim is stolen internal data. The attacker, using the alias "888", says they took more than 35GB of source code and cloud credentials from the consulting giant and are offering it for sale. Accenture says it has addressed the source of the issue and that its operations were not disrupted.

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

AI Coding Tools Trigger Endpoint Security Rules
Researchers have observed that AI coding assistants are inadvertently triggering endpoint security software designed to detect malicious activity. These tools, including Cursor, Claude Code, and OpenAI Codex, are setting off behavioral detection rules due to actions like credential harvesting and system reconnaissance, which mimic attacker behavior. The AI agents themselves are not malicious, but their operations resemble those of human intruders.

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
Microsoft has developed an internal AI system to proactively evaluate and strengthen its cloud infrastructure. This system operates at AI speed to match the scale and complexity of Microsoft's hyper-scale environments, ensuring security controls are robust and effective. While not a customer-facing product, the insights gained will inform future product improvements.

Accenture Confirms Data Breach Following Source Code Theft Claim
Accenture has confirmed a data breach occurred, which involved the alleged theft of source code. The company stated that the incident has been contained and remediated, with no impact on its operations or service delivery.