Every website needs to be set up with a cloud service provider, but what about your other CSP: Content Security Policy? The Content Security Policy (CSP) is a standard provided in an HTTP response header that helps prevent cross-site scripting… Read More "What is a Content Security Policy (CSP)?"
Microsoft Launches Flurry of AI Security Initiatives
You need agents to fight agents. At least that’s what David Weston, corporate VP for AI security at Microsoft told his audience during a Microsoft Security launch preview on July 27. During the event, the Redmond-based company announced a flurry… Read More "Microsoft Launches Flurry of AI Security Initiatives"
Phishing Dominates as Initial Entry Method for Cyber-Attacks
Phishing attacks were the dominant method of initial entry for cyber incidents that required remediation during the last quarter, analysis of attacks by the incident responders who were called in to deal with them has revealed. This as campaigns have… Read More "Phishing Dominates as Initial Entry Method for Cyber-Attacks"
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and… Read More "Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks"
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
A years-old Linux kernel flaw allowing local privilege escalation to root has been disclosed after AI-assisted research uncovered a race condition in net/sched. In new research published July 27, Lee Jia Jie of Singapore offensive security firm STAR Labs said… Read More "AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched"
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Swati KhandelwalAug 11, 2026AI Security / Cyber Attack A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The… Read More "Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets"
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that. According to research from threat exposure management firm Zafran Security… Read More "Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard"
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
Industrial giants Siemens, Schneider Electric, and Phoenix Contact have published August 2026 Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS products. Siemens has published 10 new advisories. One covers a maximum-severity missing-authentication vulnerability in Simatic IoT2050… Read More "ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact"
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Ravie LakshmananAug 12, 2026Network Security / Vulnerability Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as… Read More "Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS"
NHS Warns Staff Over Unauthorized Access to Patient Data
Britain’s health service has warned staff that they could face jail time if found guilty of accessing patient data without a legitimate reason. Head of the NHS, Jim Mackey, said inappropriate access of medical records was “wholly unacceptable, a disgraceful… Read More "NHS Warns Staff Over Unauthorized Access to Patient Data"