Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Kaspersky identifies Mirage Kitten APT using previously undocumented malware for cyber-espionage. The group employs custom backdoors and tunnelers to maintain covert access and exfiltrate data.
The APT group Mirage Kitten (also known as UNC1549, Smoke Sandstorm, or Nimbus Manticore) has been targeting aerospace, aviation, defense, and telecommunications sectors in the Middle East and Africa with a new malware toolkit. Their attacks involve spear-phishing campaigns using fake recruitment portals and impersonated videoconferencing pages to deliver malicious payloads.
Microsoft launched MAI-Cyber-1-Flash, its first cybersecurity-specific AI model, inside the MDASH vulnerability identification and remediation platform. Combined with GPT-5.4, MDASH scored 95.95% on CyberGym at 50% lower cost than the previous best configuration.
Microsoft has introduced a new cybersecurity AI model called MAI-Cyber-1-Flash, integrated into its MDASH vulnerability identification and remediation system. The model, combined with GPT-5.4, achieved a 95.95% score on CyberGym Level 1, a known-vulnerability reproduction test, while reducing costs by 50% compared to Microsoft's previous MDASH configuration.
A critical command injection vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), in Arista’s VeloCloud Orchestrator (VCO) on-premises versions is being actively exploited in the wild. This flaw allows remote attackers to execute arbitrary code, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.