Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.
The latest .NET Framework updates from Microsoft’s August Patch Tuesday cause printing and PDF export functionality to fail in WPF applications. Users relying on Windows Presentation Foundation for document workflows are impacted.
Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, used to deliver next-stage payloads and potentially sell access to ransomware groups. WordlistLoader is deployed via ClearFake campaigns that use the ClickFix technique to trick victims into running malicious commands under the guise of CAPTCHA verification, ultimately installing the Amatera Stealer.
Hackers are infecting Android-powered car head units with malware that turns them into nodes for a proxy botnet. The compromised devices route internet traffic, masking the attackers’ origins and enabling malicious activities.
The rapid use of AI coding assistants introduces open-source packages at a scale that overwhelms traditional security review processes, leading to remediation debt. Data from 300 enterprise leaders reveals that many teams struggle to assess vulnerabilities, licensing, and ownership of AI-generated dependencies.
A critical flaw in Keycloak’s password recovery mechanism lets an unauthenticated remote attacker bypass the email-based action token and directly reset any user’s password. The vulnerability, tracked as CVE-2026-18963, carries a CVSS score of 9.1 and affects multiple versions of the open-source identity and access management server.