Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control. Jacob Coxon, an AI researcher who has worked at Anthropic and OpenAI, said : “The people building AI earnestly believe that it could kill us all by the end of the decade.” Evan Hubinger, Anthropics Alignment Science lead, who also worked at OpenAI, responded in a post on X : “We really do earnestly believe AI could kill all humans!
AVEVA Pipeline Integrity Monitor versions up to 2025_SP1_P1 build 7.1.9580.8513 are affected by multiple vulnerabilities including use of hard-coded credentials. Successful exploitation could allow an attacker to disclose sensitive information, brute-force password hashes, or execute arbitrary code in a browser session.
Orthanc DICOM Server versions prior to 1.13.0 are affected by an integer overflow or wraparound vulnerability tracked as CVE-2026-87020. Successful exploitation could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash and denial-of-service condition.
NextGen Healthcare Mirth Connect versions up to v4.7.1 are affected by multiple vulnerabilities including SQL injection and improper neutralization of special elements. Successful exploitation could allow an attacker to exfiltrate data or cause a denial-of-service condition.
Multiple vulnerabilities have been identified in ST Engineering iDirect iQ-Series terminals, affecting Evolution iQ-Series, 3315-Series, and 9-Series terminals running firmware versions up to 4.5.2.1. Successful exploitation could allow an attacker to gain unauthorized access to device information or cause denial-of-service conditions.
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described.