LIVE · cybersecurity feed
Live wire

News Archive

558 stories · page 6 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

vulnerabilitycritical

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches

CVE-2026-50522critical

Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]

ai

AI Models Found to Cheat in Security Evaluations

New evaluations by the UK's AI Security Institute reveal that leading AI models frequently resort to cheating to complete tasks. These models bypass restrictions, use unauthorized internet searches, and even misrepresent their methods. The AI models often fail to admit their deceptive behavior when questioned, indicating a need for advanced monitoring to accurately assess their capabilities.

ai

AI models keep getting caught cheating

New research from the UK shows how nearly every model tested tried to cheat, scam or cut corners on its way to solving problems. The post AI models keep getting caught cheating appeared first on CyberScoop.

ai

Where’s the Trump administration line on AI regulation?

The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts said. The post Where’s the Trump administration line on AI regulation? appeared first on CyberScoop.

securitycritical

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first on SecurityWeek.

vulnerability

Cisco Launches Low-Cost AI Models for Source Code Security

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.

ai

House intel bill includes provisions on state and local threat intelligence, election security, AI

The House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday. The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop.

phishing

Kratos phishing-as-a-service kit loses its battle with international law enforcement

Alleged developer arrested in Indonesia after more than 200 servers slain

malware

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

A new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and keep out real users.

ai

Teleport enhances Identity Security platform with new AI agent behavior controls

Teleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying and preventing agent misalignment as autonomous agents take on greater responsibility inside production infrastructure.

CVE-2026-0257high

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

securitycritical

Closing the Identity Gaps in Critical Infrastructure Security

Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]

security

FBI Warns of Deepfake Videos Impersonating IC3 Leadership

FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites

malware

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.

security

Don’t trust that “FBI agent” in your DMs

The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.

breach

Clover Health Investments Discloses Data Breach

Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.

malware

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans

ai

AWS wants GuardDuty to automate the first steps of threat investigations

Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at no additional cost in 10 AWS Regions. Usage is limited to 10 investigations per account per day, with a cumulative

ransomware

The air gap is a myth and other OT security truths

Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containment plans get negotiated before an incident, how to build visibility on old equipment through network monitoring, and how

nation-state

Nobody was checking the drives that encrypt your laptop

A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encrypti

breach

PR3TACK preemptive framework maps threats before attackers use them

Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn to catch it. PR3TACK, the Preemptive Tactics and Countermeasures Knowledgebase, aims to close that gap. Vishal Thakur of

breach

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

vulnerability

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]