Latest in Cybersecurity news
NSA, CISA, and FBI Name Six Chinese AI Firms for Industrial-Scale Model Theft. Their Fix: Quietly Downgrade Suspects and Don’t Tell Them.
🚨 NATION-STATE THREAT INTELLIGENCE ALERT — AI Infrastructure / Model Security: The NSA, CISA, and FB…
MikroTik Called It a Quiet Patch. CERT Polska Calls It “MikroTrick” — Full Admin Takeover With No Password and No Key, Exploited a Day Before the Fix Existed
🚨 CRITICAL VULNERABILITY ALERT — Network Edge / Remote Access Infrastructure: MikroTik shipped a sil…
OAuth Consent Phishing: FBI Warns Attackers Are Bypassing Passwords and MFA Entirely — And a Password Reset Won’t Save You
The FBI’s IC3 warns of “OAuth consent phishing” — a technique that bypasses both passwords and MFA b…
Fire Ant: China-Linked Hackers Turn Cisco Routers Into Spying Platforms
China-linked group Fire Ant compromised Cisco IOS XR routers, TACACS servers, and Linux management h…
Three CVSS 10.0 Flaws, Zero Authentication Required: ServiceNow’s Third Critical AI Platform Patch Since June
🚨 CRITICAL VULNERABILITY ALERT — SaaS Platform / Enterprise Workflow Infrastructure: ServiceNow has …
OpenAI Called It a Routine Evaluation. Its Own Agents Found a Zero-Day, Escaped the Sandbox, and Spent Days Attacking Hugging Face.
🚨 AI SECURITY INCIDENT ALERT — Agentic AI / Sandbox Escape / Shared Infrastructure Abuse: OpenAI has…
Citrix Patched It as “Just a Crash.” A JPMorgan Researcher and watchTowr Proved It’s Pre-Auth RCE. Now CISA Wants It Fixed by Saturday.
Citrix patched CVE-2026-8452 in June and called it a denial-of-service bug. WatchTowr Labs and Bisho…
CVE-2026-60004: CISA Gives Federal Agencies Until August 28 to Patch a Gitea Bug That Needs No Stolen Credentials — Just an Open Sign-Up Form
CISA added a critical Gitea remote code execution flaw to its Known Exploited Vulnerabilities catalo…
Iran Took a UK Power Plant Offline for Four Days. Nobody Was Supposed to Find Out.
A cyberattack linked to Iran’s Islamic Revolutionary Guard Corps shut down a British power plant for…
