Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Mozilla revoked the cryptographic key used to sign Firefox and Thunderbird Linux downloads after an unencrypted copy was mistakenly committed to a private code repository. While no unauthorized access was detected, the revocation invalidates all past signatures, requiring manual key updates for users who verify signatures or use RPM packages.
Kaspersky detected a Head Mare APT attack exploiting two new vulnerabilities in TrueConf video conferencing servers (versions 5.3.X to 5.5.5). The attackers gained unauthenticated access via port 4307/TCP, executed malicious scripts, and replaced client installers with infected versions containing PhantomCore malware.
The Mira Hormone Monitor system contains eight critical vulnerabilities affecting both the hardware firmware (v1.7.1.47) and Android application (v4.5.15.4). These flaws enable unauthorized access to sensitive health data, account takeover, device rebinding to malicious actors, and user tracking through Bluetooth Low Energy (BLE) weaknesses.
Multiple critical vulnerabilities in Johnson Controls' C-CURE 9000 and Victor application server (Update A) could allow unauthenticated attackers on an adjacent network to execute arbitrary code. Successful exploitation may impact physical security systems, posing significant risks to critical manufacturing infrastructure.
The Pulsetto Vagus Nerve Stimulator contains a critical vulnerability (CVE-2026-18844) in its firmware, allowing unauthenticated attackers to send hidden commands over Bluetooth Low Energy (BLE). These commands can disable safety features or modify stimulation settings, posing a direct risk to user safety.
This article argues that the traditional approach of patching vulnerabilities is insufficient to secure AI systems. Instead, organizations must focus on designing systems that make vulnerabilities irrelevant, as AI introduces new and evolving risks.