“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
Agentic AI’s role in amplifying and creating insider risks
AI agents might just outdo humans in causing insider risk chaos. From employees using shadow AI to rogue agents, it’s time to keep humans and machines in check.Read More
-
RSAC 2026 recap: AI security and network security trends
RSAC 2026 spotlighted AI security as a key theme. Explore insights on securing AI agents, enterprise browsers, sovereignty and platformization trends.Read More
-

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign [email protected] (The Hacker News)
The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025. The large-scale exploitation campaign has been codenamed Read More
-

Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access [email protected] (The Hacker News)
A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to light in July 2024. “Read More
-

Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign [email protected] (The Hacker News)
An active campaign has been observed targeting internet-exposed instances running ComfyUI, a popular stable diffusion platform, to enlist them into a cryptocurrency mining and proxy botnet. “A purpose-built Python scanner continuously sweeps major cloud IP ranges for vulnerable targets, automatically installing malicious nodes via ComfyUI-Manager if no exploitable node is alreadyRead More
-
![[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk info@thehackernews.com (The Hacker News)](https://sekuritasit.com/wp-content/uploads/2026/04/webinar-cerby-T5bbZN.jpg)
[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk [email protected] (The Hacker News)
In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon Institute, hundreds of applications within the typical enterprise remain disconnected from centralized identity systems. These “darkRead More
-
Identity security at RSAC 2026: The new enterprise dynamics
Omdia analyst Todd Thiemann made the rounds at RSAC 2026 Conference, speaking with CISOs, practitioners and vendors to identify the latest shifts in identity and data security.Read More
-

The Hidden Cost of Recurring Credential Incidents [email protected] (The Hacker News)
When talking about credential security, the focus usually lands on breach prevention. This makes sense when IBM’s 2025 Cost of a Data Breach Report puts the average cost of a breach at $4.4 million. Avoiding even one major incident is enough to justify most security investments, but that headline figure obscures the more persistent problems caused by recurring credentialRead…
-

New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips [email protected] (The Hacker News)
New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that could be exploited to escalate privileges and, in some cases, even take full control of a host. The efforts have been codenamed GPUBreach, GDDRHammer, and GeForge. GPUBreach goes a step further than GPUHammer, demonstrating for the first time thatRead More
-

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware [email protected] (The Hacker News)
A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate “high-velocity” attacks and break into susceptible internet-facing systems. “The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recentRead More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
