Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover.
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to the CyberAgents Exchange.Securing AI agents requires analyzing a broad attack surface that includes LLM instructions, tool-chaining permissions, and prompt injection risks, going far beyond traditional software security.The CyberAgents Exchange inspection process dynamically matches the appropriate AI model tier to each submission’s risk level, ensuring comprehensive vetting without excessive computational overhead.Recently at OpenAI's “Intelligence at Work: Cyber Summit,” Tenable and OpenAI announced a groundbreaking review process to vet the security of open-source AI agents, skills, MCP servers, and multi-agent playbooks, building on our June partnership.
In a follow-up analysis, SpiderLabs examines the latest proof-of-concept disclosures from the leak persona Nightmare-Eclipse, which previously focused on Microsoft's ecosystem including Windows Defender, Cloud Files, and core operating system functionality. The latest PoCs expand the attack surface by targeting additional system components and demonstrating new exploitation techniques that could affect enterprise security postures.
Ukraine prosecutor general steps down amid scam call center bribery probe Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield fraudulent call centers from law enforcement. “This is a political decision, and I made it consciously,” Kravchenko said Monday.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, and CVE-2026-76461. These flaws affect a range of products and have been confirmed as actively exploited in the wild by threat actors.
A major vulnerability is disclosed. The alert lands immediately.