Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
You can now connect your agents to the <a class="Link" href="https://docs.aws.amazon.com/agent-toolkit/latest/userguide/mcp-server.html" target="_blank" rel="noopener"...
AWS has introduced OAuth support for its AWS MCP Server, enabling users to connect their agents using the same credentials and sign-in methods as the AWS Management Console or AWS CLI. This integration supports AWS Identity and Access Management (IAM) federation, AWS IAM Identity Center, and root or IAM users, providing a browser-based experience powered by industry-standard OAuth. Additionally, AWS has rolled out new security and governance tools, including global condition keys for OAuth, token introspection and revocation, dynamic client registration, new AWS CloudTrail elements, and an API for headless OAuth connectivity.
A Russian state-linked group is exploiting hotel and hospitality Wi-Fi networks to target travelers globally through a campaign called CaptiveCrunch. The attackers manipulate DNS and HTTP traffic via captive portals, redirecting users to phishing pages mimicking Microsoft logins or delivering malware like the CornFlake RAT (remote access trojan) and ChocoShell infostealer.
Cisco Talos disclosed multiple vulnerabilities in WolfSSL, GeoVision, and VTK-DICOM. The vendors have patched the vulnerabilities. Snort rules are available for detection.
Cisco Talos disclosed multiple vulnerabilities across three software products: WolfSSL, GeoVision, and VTK-DICOM. WolfSSL, an open-source library for secure data transfer, had three flaws, including improper input validation (CVE-2026-28739, CVE-2026-25106) and an integer underflow (CVE-2026-33091). GeoVision, a security technology provider, was found to have 14 vulnerabilities spanning 37 CVEs, including memory corruption (CVE-2026-12488), OS command injection (CVE-2026-12486), buffer overflows (CVE-2026-12485), and privilege escalation (CVE-2026-42368).
Google has temporarily disabled an AI feature in Google Earth that allowed users to generate artificial images based on real satellite data. The feature, launched on July 30 using Google’s Nano Banana 2 image generator, enabled users to create photorealistic deepfakes by combining text prompts with real-world geographic details.