AI agents can chain credentials and tools to reach beyond direct permissions, as a Hugging Face evaluation showed.
A Linux KVM flaw on ARM64 can expose host kernel memory to guests and enable guest-to-host escape when nested virtualization is enabled.
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes.
North Korean Contagious Interview campaign compromised 30,000 devices and stole at least $10.71 million in cryptocurrency.
SharePoint CVE-2026-65660 enables authenticated RCE; Microsoft patched it on August 11, and no in-the-wild exploitation is reported.
SideCopy targets Indian academic institutions with spear-phishing that abuses mshta.exe to deploy ReverseRAT for collection and remote access.
DORA’s second year shifts focus to proving ICT controls work, with network evidence supporting monitoring, detection, and incident response.
CISA added Zyxel CVE-2026-7273 to KEV after active exploitation, while Arctic Wolf reported attacks on a Veeam Windows flaw.
A Mac Muse flaw lets malware running as the logged-in user reroute dictation, inject instructions, and steal the assistant's session token.
WordPress fixed a comment flaw that could lead to server code execution if a logged-in administrator opened the page.
Ireland's DPC fined Google €403 million over GDPR violations in how three features handled location data from 2018 to 2020.
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.