Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned. Gunra is a ransomware-as-a-service (RaaS) which primarily exploits known vulnerabilities in internet-facing… Read More "Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastruc"
SharePoint Vulnerability Exploited Shortly After PoC Release
A SharePoint vulnerability patched last month is now being exploited in the wild, with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit. The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday… Read More "SharePoint Vulnerability Exploited Shortly After PoC Release"
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
Ravie LakshmananAug 12, 2026Browser Security / Privacy A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them… Read More "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One"
WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
A previously unseen NFC relay malware family has been deployed alongside a remote access trojan in a single 13-minute phone call, letting a fraudster take out a loan in the victim’s name and relay their card data to a fake… Read More "WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam"
Mindgard Raises $30 Million to Protect AI Systems
AI security startup Mindgard today announced raising $30 million in a Series A funding round that brings the total raised by the company close to $42 million. The investment round was led by Album VC, with additional support from Karma… Read More "Mindgard Raises $30 Million to Protect AI Systems"
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used… Read More "OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning"
The AI harness is the new attack surface
“Teams think in terms of apps, services, pipelines, or bots,” Santos says. Harnesses disappear into code repositories, SaaS products, and vendor configuration screens instead of showing up as discrete assets in security inventories. Even the terminology is inconsistent. “One team… Read More "The AI harness is the new attack surface"
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Malware used by North Korea’s Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace companies across Europe and India. Check Point Research reported the… Read More "Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day"
The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment
Most teams that assess cloud vendors already have a general idea of the Consensus Assessment Initiative Questionnaire (CAIQ) and Cloud Controls Matrix (CCM). However, you may not have a good answer for what it takes to run that assessment. Turning… Read More "The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment"
This Coin-Sized Device Can Hack a Boeing 737
The researchers aren’t revealing which port they targeted on the 737, nor are they releasing some details of how their hacking device is able to spoof commands to the plane’s computers. They’ve worked closely with Boeing to share their findings,… Read More "This Coin-Sized Device Can Hack a Boeing 737"