“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
![[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk info@thehackernews.com (The Hacker News)](https://sekuritasit.com/wp-content/uploads/2026/04/webinar-cerby-T5bbZN.jpg)
[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk [email protected] (The Hacker News)
In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon Institute, hundreds of applications within the typical enterprise remain disconnected from centralized identity systems. These “darkRead More
-
Identity security at RSAC 2026: The new enterprise dynamics
Omdia analyst Todd Thiemann made the rounds at RSAC 2026 Conference, speaking with CISOs, practitioners and vendors to identify the latest shifts in identity and data security.Read More
-

The Hidden Cost of Recurring Credential Incidents [email protected] (The Hacker News)
When talking about credential security, the focus usually lands on breach prevention. This makes sense when IBM’s 2025 Cost of a Data Breach Report puts the average cost of a breach at $4.4 million. Avoiding even one major incident is enough to justify most security investments, but that headline figure obscures the more persistent problems caused by recurring credentialRead…
-

New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips [email protected] (The Hacker News)
New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that could be exploited to escalate privileges and, in some cases, even take full control of a host. The efforts have been codenamed GPUBreach, GDDRHammer, and GeForge. GPUBreach goes a step further than GPUHammer, demonstrating for the first time thatRead More
-

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware [email protected] (The Hacker News)
A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate “high-velocity” attacks and break into susceptible internet-facing systems. “The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recentRead More
-

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed [email protected] (The Hacker News)
Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution. “The CustomMCP node allows users to input configuration settings for connectingRead More
-
Meaningful metrics demonstrate the value of cyber-resiliency
Cyber-resilience metrics translate raw technical performance into real business outcomes. The right analytics can enhance more than just security operations.Read More
-

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations [email protected] (The Hacker News)
An Iran-nexus threat actor is suspected to be behind a password-spraying campaign targeting Microsoft 365 environments in Israel and the U.A.E. amid ongoing conflict in the Middle East. The activity, assessed to be ongoing, was carried out in three distinct attack waves that took place on March 3, March 13, and March 23, 2026, per Check Point. “The campaign is…
-

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea [email protected] (The Hacker News)
Threat actors likely associated with the Democratic People’s Republic of Korea (DPRK) have been observed using GitHub as command-and-control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. The attack chain, per Fortinet FortiGuard Labs, involves obfuscated Windows shortcut (LNK) files acting as the starting point to drop a decoy PDFRead More
-
What to know about red team testing and the law
Red teaming isn’t just about finding flaws in cyberdefenses. There are important legal implications that deserve careful consideration.Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
