Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Anthropic has caught Russia-linked spies using Claude AI to assist in cyber operations, such as generating phishing lures and drafting social engineering messages. The spies targeted Ukrainian and NATO-aligned entities, and Anthropic disclosed the incident in its latest threat report.
Researchers at Group-IB discovered that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. This allows attackers to carry out fraudulent transactions while potentially bypassing anti-fraud systems that do not correlate activity across Android profiles.
A Ukrainian hacker has been sentenced to four years in a US prison for his role in Conti ransomware attacks targeting US government agencies and businesses. The individual was extradited to the US and pleaded guilty to computer intrusion and wire fraud charges.
A growing recognition in cybersecurity is that the ability to find vulnerabilities has outpaced the ability to manage them effectively. Security teams are discovering more flaws than ever, but without proper risk-based prioritization frameworks, organizations may invest resources patching low-impact issues while leaving critical business risks unaddressed.
GitLab has disclosed a maximum severity path traversal vulnerability, CVE-2026-85706, that affects both Community and Enterprise Edition servers, allowing attackers to read arbitrary files. The company has released patches and strongly recommends immediate upgrades to prevent data exposure.
Microsoft has fixed an issue where Teams and Outlook were failing to launch on Windows 11 systems after recent updates, particularly on ARM Windows PCs. The fix is included in the latest cumulative update, resolving application crashes and startup failures that affected enterprise productivity.