Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure.
French authorities have detained an 18-year-old suspected member of the ZeroBytes hacking group following an investigation into cyberattacks targeting French organizations. The suspect is accused of participating in distributed denial-of-service attacks, data breaches, and defacement campaigns.
Threat actors are increasingly switching from AI-powered coding assistants to building custom AI frameworks designed specifically for malware development and credential theft. These AI frameworks help attackers automate phishing campaigns, generate convincing lures, and analyze stolen credentials at scale.
CISA has released an advisory (ICSA-26-251-01) regarding vulnerabilities in CareCam Pro IP Cameras, including the ANJIA AJL33PC0801 model running firmware linux_202008261138_svn13796 with U-Boot 2010.06 bootloader. Successful exploitation of these vulnerabilities could allow an attacker to take full control of the affected device.
A municipal utility company in Bavaria, Germany is recovering from a cyberattack that encrypted internal systems and disrupted operations. The attack affected the utility ability to provide services to customers.
The NSA, CISA, and FBI have released a joint advisory warning that China-based AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been conducting industrial-scale knowledge distillation campaigns against U.S. frontier AI models since at least late 2024. These companies extracted billions of tokens across millions of API requests from models including Claude, GPT, Gemini, and Grok to train their own R1, V3, Qwen, and other models, likely with Chinese government awareness.