Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Microsoft released the KB5101684 optional non-security preview cumulative update for Windows 11 24H2 and 25H2, bringing 42 bug fixes and feature improvements. The update (builds 26100.8973 for 24H2 and 26200.8973 for 25H2) allows users to test fixes before the next Patch Tuesday.
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26-27, 2026, triggering a statewide cybersecurity response. Braham's water plant went offline, Plymouth reported cellular communications failures at water towers and lift stations, and South St.
A coordinated cyberattack disrupted operational technology at over 30 Minnesota community water systems between July 26 and 27, prompting a statewide response. Braham’s water plant went offline, forcing residents to conserve water, while Plymouth, South St.
Cybersecurity firm F6 disclosed a large-scale fraud campaign operating since 2017 that clones websites of major Russian companies (fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks) to steal advance payments from international firms. The fake websites, available in English, French, Arabic, and Russian, copy content from legitimate sites and use lookalike domain names.
Cybersecurity firm F6 disclosed a large-scale fraud campaign operating since 2017 that clones websites of major Russian companies (fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks) to steal advance payments from international firms. The fake websites, available in English, French, Arabic, and Russian, copy content from legitimate sites and use lookalike domain names.
The article discusses the impact of AI (specifically Anthropic's Mythos model) on vulnerability management, arguing that while AI compresses exploit timelines and accelerates attacker capabilities, the fundamental problem remains ineffective prioritization. Most security teams were not winning the prioritization battle before Mythos, and compressed timelines simply raise the cost of existing failures.