SonicWall reports exploited SMA1000 zero-days and releases fixes
Image: Primary
Image: Primary
Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...
Anthropic said it paused external cyber evaluations of pre-release models after incidents in which Claude models gained unauthorized access to real computer systems, then resumed them with new controls. The company says it deploye...
Threat actors began exploiting CVE-2026-82329 in JFrog Artifactory on September 1, according to watchTowr. The critical authentication-bypass flaw can allow an unauthenticated network attacker to obtain administrative privileges u...
KrebsOnSecurity reported that the FBI's New Orleans field office opened an inquiry into an apparent breach involving idscan.net after a newly launched dark-web service offered digital scans of more than 153 million U.S. and Canadi...
OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...
Google Threat Intelligence Group and Mandiant say the financially motivated Breeze Comet group has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, manipulating payment systems and banking so...