Security · Top stories
Kubernetes to Correct CVE Records for Unfixed Vulnerabilities in 2026
The Kubernetes project will correct inaccuracies in CVE records for older unfixed vulnerabilities on June 1, 2026. This change aims to improve transparency and ensure that vulnerability scanners can better identify risks that currently go undetected due to erroneous fixed version tags.
New Proposal for Interoperable Passkey Records and Go API Announced
A new specification for interoperable passkey records, inspired by Password Hashing Competition Strings, aims to simplify the integration of passkeys in applications. This proposal allows developers to handle passkey records as opaque strings, making implementation more efficient and reducing complexity in database interactions.
ExpressVPN Enhances Password Manager with New Features
ExpressVPN has updated its password manager, ExpressKeys, to include secure sharing and passkey support. This update is part of the broader trend of meeting increasing demands for secure data management across devices.
Amazon launches GuardDuty investigation agent for AI-powered threat assessment
Amazon introduced the GuardDuty investigation agent in public preview, enhancing threat assessments across AWS environments. This tool automates investigation processes, reducing time from hours to minutes and providing structured risk assessments and actionable recommendations.
Flock Safety abandons controversial acoustic distress detection system
Flock Safety has decided to discontinue its acoustic gunshot detection device aimed at identifying human distress due to privacy concerns. The decision follows backlash from privacy advocates and consultations with communities, emphasizing the system was never intended for general release.
India asserts leaked nuclear plant files are not a safety risk
India's nuclear operator confirmed that leaked documents related to the Kudankulam Nuclear Power Plant do not impact safety or security. The files, attributed to the World Leaks group, mainly pertain to non-nuclear infrastructure, according to official statements.
Upbound says hack caused $13 million in fraudulent Acima leases
Apple Releases Sixth RCs for macOS Sonoma 14.8.8 and Sequoia 15.7.8 with Security Updates
Apple has released the sixth set of Release Candidates for macOS Sonoma 14.8.8 and Sequoia 15.7.8, focusing on security improvements. These follow a series of RCs prompted by AI-related security risks.
Cybersecurity Startup Neo Secures $100M for Enterprise AI Control Platform
Cybersecurity startup Neo has emerged from stealth with $100 million in funding for its platform designed to control and secure AI software within enterprises. The platform provides security teams with tools for monitoring AI agents and applications while offering real-time attribution to identify unauthorized actions.
Web-based cryptography lacks true end-to-end security, expert claims
The article argues that web-based applications claiming end-to-end encryption fail due to inherent structural flaws. It asserts that such systems cannot provide reliable security because the same entity that operates the service also distributes the cryptographic code, undermining security claims.
New HIH Index Launches to Track Material Cyber Breaches
Richard Bird has launched the HIH Index to track material breaches, using two ledgers for data collection. The index aims to provide a resource for cybersecurity stakeholders and highlights discrepancies in reported losses over time, emphasizing an increase in companies affected rather than individual breach costs.
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
Federal agencies broaden alert on Iran-linked OT attacks
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Deepsec Launches Agent-Powered Vulnerability Scanner for Large Codebases
Deepsec released a vulnerability scanner that operates on existing large-scale repositories, optimizing on-demand reviews of code. The tool aims to uncover longstanding vulnerabilities, and its parallel processing feature allows for efficient scanning, even if interrupted.
Study Analyzes Security Bulletins of Qubes OS from 2011 to 2025
A longitudinal analysis of 109 Qubes Security Bulletins reveals persistent upstream vulnerability dependence. The study indicates that 79.8% of Qubes advisories can be attributed to external components rather than its core logic.
Abbott Laboratories investigates two cybersecurity incidents amid extortion claims
Abbott Laboratories is investigating two cyber incidents involving unauthorized access to its internal systems. The investigations include claims by the ShinyHunters group regarding data breaches linked to its Cancer Diagnostics business and LabCentral portal.
Brex develops CrabTrap for AI agent governance by analyzing real agent behavior
Brex created an internal platform named CrabTrap to enhance AI agent governance by analyzing actual agent behavior rather than relying solely on predefined rules. This shift utilizes an open-source proxy to intercept and evaluate network requests, addressing security challenges at the transport layer.
Cybersecurity Week in Review: Key Incidents and New Malware
A roundup of significant cybersecurity incidents highlights vulnerabilities from local actors, vendor breaches, and emerging malware. Notably, the new CrashStealer macOS malware poses threats to Apple devices, while various cyberattacks disrupt operations and lead to financial consequences for businesses.
AI-Powered Audits Uncover Bugs in Cloudflare and OpenVM Cryptographic Libraries
AI audit tool, zkao, discovered bugs in Cloudflare's CIRCL and OpenVM's zkVM libraries, including critical vulnerabilities. These bugs have been fixed, showcasing AI's role in enhancing cryptographic security.
Live SSH Honeypot Dashboard Displays Bot Interactions in Real Time
A new dashboard shows live telemetry from an SSH honeypot, showcasing real-time interactions of bots. This tool is intended for security research and education, providing insights into network threats and malicious activities.
Pentagon Suspends CMMC Phase 2 Pending Review to Address Contractor Challenges
The Pentagon has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) to review its implementation and address industry concerns. This suspension pauses third-party assessments but maintains Phase 1 self-assessments and existing regulations. A CMMC Reform Task Force will lead a 60-day evaluation to recommend future measures.
Armenia Detains Wrong Aleksandr Ermakov on US Extradition Request
Armenia has detained a Russian tourist, Aleksandr Ermakov, based on a US warrant for a REvil hacker with the same name. His lawyers argue he is not the individual sought by US authorities, highlighting potential issues in extradition processes and international law enforcement collaboration.
Senator Wyden urges U.S. officials to oppose Canadian surveillance legislation
Senator Ron Wyden has called on U.S. officials to evaluate Canadian legislation allowing surveillance of American citizens. The Lawful Access Act could compel U.S. companies to enable surveillance, jeopardizing national security and user privacy.
Traceforce Launches Security Monitoring Tool for AI Applications
Traceforce has launched a security monitoring tool that provides visibility into AI app usage across devices. This tool enables companies to monitor AI software activities and detect potential security breaches, addressing a growing need for security in rapidly evolving AI environments.
Google Cloud Integrates AI for Improved Cybersecurity in Software Development
Google Cloud has integrated AI into its software development lifecycle to enhance cybersecurity. By embedding AI agents, Google aims to provide faster and automated threat responses, capitalizing on deep contextual analysis. Key developments include the creation of an autonomous security model and the introduction of the Google AI Threat Defense platform, which unifies security data and speeds up vulnerability response.
n8n Token Exchange Vulnerability Allows Unauthorized User Logins
n8n's workflow automation platform experienced a security flaw allowing attackers to log in as users from different issuers. The bug allowed valid tokens from one issuer to erroneously authenticate users from another, impacting Enterprise deployments that trust multiple external token issuers.
Microsoft Releases Key Windows Security Updates and Support Changes
Microsoft has rolled out security updates KB5101650 and KB5099414 for Windows 11 versions 25H2/24H2 and 23H2, fixing 571 vulnerabilities. Simultaneously, Windows 10 received its KB5099539 update addressing 570 vulnerabilities, with extended support until 2027. Windows 11 24H2 Home and Pro editions will no longer receive updates after October 13, 2026, urging users to upgrade.
China Suspends Major Cybersecurity Firms from Military Procurement
China has suspended or banned over a dozen leading cybersecurity firms from military procurement due to contract bidding misconduct. This marks a significant enforcement action in the country's state procurement system, highlighting concerns about compliance within the industry.
Trend Micro, Tanium, ESET, and Tenable Patch Critical Vulnerabilities
Cybersecurity firms Trend Micro, ESET, Tanium, and Tenable have released patches for severe vulnerabilities in their products. These updates are crucial as they address potential exploits that could allow attackers to execute remote code and escalate privileges.
Microsoft fixes critical security bug in Age of Empires II
Microsoft patched a significant vulnerability in Age of Empires II that allowed hackers to take over victims' computers via a malicious game invite. This fix is part of a broader effort where AI aided in identifying multiple security flaws across Microsoft's products.
TuxBot v3 Evolution IoT Botnet Shows Signs of LLM Development
Cybersecurity researchers revealed the TuxBot v3 Evolution IoT botnet framework, which incorporates elements generated with a large language model (LLM). Functional issues were noted alongside its sophisticated features, highlighting potential risks in IoT security as AI tools assist in malware development.
Firewally: A Free Mac App for Controlling Internet Access of Applications
Firewally, a new free app available on the Apple App Store, allows Mac users to control which applications can access the internet. This additional layer of control enhances MacOS security by enabling users to set default policies and block app access when necessary.
Windows Bind Link Attacks Can Evade Endpoint Detection Tools
Researchers at Bitdefender reveal that Windows bind links can be exploited to hide malware from EDR tools. This manipulation allows attackers to redirect legitimate paths to malicious files, evading detection by security systems reliant on path validation.
Webinar Addresses Security Risks in AI-Era Ad Tech
A new on-demand webinar highlights the Approval Gap in ad tech, emphasizing the security risks posed by unmonitored third-party scripts. It features insights from Reflectiz and Taboola, discussing how to vet vendors effectively to protect customer data.
Siemens, Schneider, Rockwell Address Critical ICS Vulnerabilities in July Patch Tuesday
Siemens, Schneider Electric, and Rockwell Automation released advisories for vulnerabilities in their industrial control system (ICS) products. Significant vulnerabilities, including critical flaws with CVSS scores up to 10, were addressed, mitigating risks of remote exploitation and operational disruption.
US Expats in DRC Face Travel Restrictions Amid Ebola Outbreak, Sent to Germany for Care
Two Americans in the Democratic Republic of Congo have tested positive for Ebola and are being treated in Germany. The Trump administration has imposed strict travel restrictions, requiring US citizens in DRC to spend 21 days in a third country before returning home. The outbreak, led by the Bundibugyo strain, is the third largest recorded and highlights ongoing global health coordination challenges.
Cybersecurity stocks rise as IBM CEO highlights cybersecurity spending shift
Cybersecurity stocks saw significant gains following comments by IBM CEO Arvind Krishna, who identified increasing cybersecurity concerns as a top priority for clients. Krishna highlighted that spending is shifting as companies reassess their budgets amid fears of advanced AI-driven cyber threats.
Security Hub adds AI workload protection, supports Microsoft Azure
Security Hub introduces AI workload protection and support for Microsoft Azure. These enhancements address customer demand for integrated security management across multiple cloud environments, allowing for streamlined risk assessment and response.
Synopsys Denies Data Breach Claims Linked to Bosch Hack
Synopsys has found no evidence of a data breach after a cybercriminal group, D1R, claimed to have hacked its systems and accessed customer data, including from Bosch. The firm maintains that its systems are secure and that the hackers’ claims are unfounded, potentially minimizing the urgency of the security threat.