Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Microsoft highlights the growing risks of AI agents operating without proper identity and access controls, emphasizing the need for least-privilege principles. AI agents, which autonomously chain actions across systems, can inadvertently access or modify sensitive data if assigned overly broad permissions.
<button class="btn-collapse" type="button" aria-expanded="true"...
This article reports on ongoing attack campaigns by the Kimsuky threat actor, who impersonates diplomats to deliver PebbleDash and PrxClient malware via spear phishing. The group has been active in 2026, continuing their malicious activities.
AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1].
This article reports on the Kimsuky group's latest attacks, where they impersonate diplomats and use spear phishing to install PebbleDash malware. AhnLab's ASEC provides analysis of the attack techniques and malware.
This article analyzes CVE-2026-42533, a critical heap buffer overflow vulnerability in NGINX's map directive. The flaw allows remote unauthenticated attackers to corrupt memory and potentially execute arbitrary code.