Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article covers a high-severity pre-authentication XSS vulnerability in WordPress login screens, tracked as CVE-2026-64638. Researchers demonstrated chaining the flaw into PHP code execution via administrator interaction.
The article discusses how agentic AI empowers defenders to build security tooling quickly, as demonstrated at Black Hat USA 2026's SWARM event. It emphasizes that teams created agents for common operational pain points and shared them openly to accelerate future work.
This advisory describes vulnerabilities in CPDLC over ATN-B1, caused by legacy unauthenticated radio frequency links. Attackers could inject messages, cause denial of service, or force session resets, degrading operational safety margins.
French rugby club Stade Français recovered from a cyberattack by restoring from backups, keeping critical systems isolated. The incident also involves a potential data leak, emphasizing the importance of backup strategies and segmented architectures.
The article discusses how agentic AI empowers defenders to build security tooling quickly, as demonstrated at Black Hat USA 2026's SWARM event. It emphasizes that teams created agents for common operational pain points and shared them openly to accelerate future work.
The article uses an extended metaphor of open source as a child that grew up feral and then got drafted into a cybersecurity war. It describes how major incidents forced regulation and now open source faces threats from AI and poisoned distribution channels.