Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
In what is described as the first purported near-autonomous attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan. The AI-powered attack marks a significant escalation in cyber warfare capabilities, enabling faster target reconnaissance and adaptive exploitation.
Oracle released its August 2026 Critical Security Patch Update (CSPU) addressing 925 unique CVEs across 943 security updates, including 154 critical-severity patches. This represents a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs.
Sophos researchers discovered threat actors impersonating AI brands to deliver malware. The attackers create fake AI tool websites and distribute malicious installers that appear to be legitimate AI applications but actually deploy information-stealing malware.
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478. 📌 **Analyst Note:** The lack of public technical details for CVE-2026-19478 makes detection difficult; organizations running self-managed GitLab should monitor for unusual activity and apply patches promptly.
When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in support for OAuth 2.0, AWS IAM, and API key authentication through AgentCore Gateway. However, some enterprise environments still rely on legacy authentication mechanisms such as HTTP Basic Authentication.
Researchers discovered a meta-hacking technique called CoSnitch that can manipulate Microsoft Copilot into revealing its own security weaknesses. The attack exploits AI assistants to map out internal architecture and identify vulnerabilities by tricking the AI service into disclosing sensitive information about its security posture.