“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
How to build AI security guardrails without blocking innovation
To take advantage of opportunities AI might present — without opening the door to a breach — an organization needs to put the right guardrails in the right places.Read More
-
The prosecution gap: Why cybercrimes go unpunished
Are cybersecurity criminals simply acting with impunity? It sometimes feels like it. Learn what defenders need to know and what investigators are doing about it.Read More
-

Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories [email protected] (The Hacker News)
Most good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95 subcategories in four main award categories. The reason is simple. Cybersecurity is full of work that deserves recognition and rarely gets it. Products that quietly close real gaps. Teams that stop incidents nobody…
-

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories [email protected] (The Hacker News)
It’s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there’s a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials. The bigger problem is how polished…
-

AI Broke Vulnerability Management. That’s Why CISOs Are Moving Budget to BAS. [email protected] (The Hacker News)
For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer was what made that work. Today, that buffer is gone. AI…
-

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack [email protected] (The Hacker News)
The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock investors with a backdoor known as SPECTRALVIPER. The campaigns involve a prolonged cyber espionage operation aimed at a Vietnamese infrastructure and transport construction corporation between mid-2024 and February 2026, as well as a supply chain…
-

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks [email protected] (The Hacker News)
GitHub has announced what it said are “breaking changes” coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the “npm install” command to trigger the execution of malicious code using npm lifecycle hooks. “Npm install”…
-
Check Point VPN Authentication Bypass Vulnerability
What is the Vulnerability? A critical authentication bypass vulnerability, CVE-2026-50751 (CVSS 9.3), is being actively exploited against vulnerable Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. The flaw allows unauthenticated attackers to bypass user authentication through a certificate validation logic weakness and establish a VPN…
-

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance [email protected] (The Hacker News)
Cybersecurity researchers have warned of a “resurgence and expansion” of JDY, a covert network associated with China-nexus state-sponsored threat actors. “The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale,” Lumen’sRead…
-

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities [email protected] (The Hacker News)
Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It’s tracked as CVE-2026-25089 (CVSS score: 9.1). “AnRead More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
