Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Flock Safety is tightening privacy controls by requiring all customers to use its Audit Assistance feature and reducing license plate data retention to seven days. These changes come in response to multiple scandals involving officer misuse of the company's surveillance technology.
A critical remote code execution vulnerability in VMware vCenter Syslog Server, tracked as CVE-2026-59310, is being actively exploited in a campaign that installs a reverse SSH tool for persistent remote access. Although the vulnerability has been patched, attackers are using it to gain RCE and maintain long-term access to compromised vCenter instances, emphasizing the need for urgent patching and threat hunting.
A new variant of the Mirai botnet introduces encrypted command-and-control communications and a sniffer for default access credentials. These additions significantly improve the malware's stealth and ability to compromise vulnerable IoT devices.
Hardware wallet maker Trezor disclosed a data breach impacting nearly 14,000 customers after its shipping and logistics provider, ShipMonk, was hacked. The incident underscores the growing threat of supply chain attacks targeting cryptocurrency-related services.
A campaign attributed to the Pakistan-aligned threat actor APT36 (Transparent Tribe) is targeting Afghan telecom providers and South Asian critical infrastructure with two previously undocumented backdoors: PATCHCORD, delivered via fake telecom installers, and SHEETCORD, which uses Google Sheets for command-and-control. The operator has also adopted AI-assisted malware and open-source C2 frameworks, reflecting an evolution in both targeting—shifting focus to Afghan telecoms alongside Indian government and energy sectors—and operational tradecraft.
A Black Hat USA 2026 discussion explores whether the current boom in AI-driven vulnerability discovery will eventually taper off, and whether it will result in fundamentally safer software. The debate centers on the long-term effectiveness and sustainability of automated bug hunting techniques.