Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
LevelBlue SpiderLabs details how their machine-learning URL scanner identifies emerging phishing campaigns by tracking instances where their engine is the sole detector on VirusTotal. The blog examines several notable campaigns that employ multi-stage redirection chains, where victims are relayed through multiple infrastructure layers to evade detection.
At Black Hat USA 2026, AI dominated discussions, but the central takeaway was not about its capabilities but the pressing question of accountability when AI systems fail. The article explores how cybersecurity controls lag behind rapid AI advancements, leaving organizations and regulators grappling with who bears responsibility for breaches or errors.
Attack Chains addresses the challenge of disconnected security alerts by automatically linking low-confidence signals into a coherent attack narrative. Instead of burdening analysts with manual correlation, the solution provides a unified view of adversary campaigns unfolding within the environment.
Three separate data breaches at Britain's ACRO criminal records office went undetected for two years due to unread antivirus alerts and an unpatched content management system. A reprimand notice revealed the security lapses that exposed sensitive criminal records data.
CVE-2026-20349 is a high-severity denial-of-service vulnerability in Cisco ASA and Secure FTD software exploited in the wild. Insufficient error checking in the Remote Access SSL VPN service lets unauthenticated attackers trigger device reloads.
CVE-2026-68820 is an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver (AFD.sys) that allows local attackers to gain SYSTEM privileges via a race condition. It was exploited by the North Korean Lazarus group as part of Operation Dream Job to install a kernel rootkit.