Most teams that assess cloud vendors already have a general idea of the Consensus Assessment Initiative Questionnaire (CAIQ) and Cloud Controls Matrix (CCM). However, you may not have a good answer for what it takes to run that assessment. Turning… Read More "The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment"
This Coin-Sized Device Can Hack a Boeing 737
The researchers aren’t revealing which port they targeted on the 737, nor are they releasing some details of how their hacking device is able to spoof commands to the plane’s computers. They’ve worked closely with Boeing to share their findings,… Read More "This Coin-Sized Device Can Hack a Boeing 737"
Ceva Logistics Operations Disrupted by Cyberattack
Shipping and logistics giant Ceva Logistics has had its European operations disrupted after hackers compromised its systems. The disruption occurred on July 29, and the company is still scrambling to restore the impacted services. Eight warehouses across Europe have been… Read More "Ceva Logistics Operations Disrupted by Cyberattack"
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Ravie LakshmananAug 12, 2026Vulnerability / Web Security Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of… Read More "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws"
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
When executed, “cscript.exe” runs a series of scripts carrying out basic system reconnaissance like collecting the machine GUID, hostname, and supported languages. It then replaces “runtimebroker.dll” in the user’s AppData directory with a reflexive loader and modifies Chrome’s Security Extension… Read More "Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool"
Russian-Linked Hackers Accessed Polish Power Plant OT Through APN
The Polish CERT (CERT.PL) has published details of another attack on its energy infrastructure which took place during a suspected Russian cyber campaign in December 2025. The post mortem on the attack took three months to complete and was therefore… Read More "Russian-Linked Hackers Accessed Polish Power Plant OT Through APN"
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
During the 25 years Gerardo Pachuca has spent investigating thieves who steal cargo from semitrucks, he says he’s never seen behavior this brazen. The consultant and former Los Angeles sheriff’s detective claims that two times in recent months, robbers stole… Read More "‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware"
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel and AMD on Tuesday announced patches for a total of more than 80 vulnerabilities across their products. Intel has published 42 new advisories covering 72 vulnerabilities. The company patched several high-severity flaws in PROSet/Wireless WiFi software that could allow… Read More "Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined"
How Fidelis Network Behavior Analysis Detects Advanced Threats
Network behavior analysis can help detect command-and-control, lateral movement, DNS tunneling, DGA activity, phishing behavior, internal spear phishing, exploitation attempts, file and directory discovery, unusual data movement, insider misuse, and compromised account activity. The strongest detections usually come from correlating… Read More "How Fidelis Network Behavior Analysis Detects Advanced Threats"
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Ravie LakshmananAug 12, 2026Vulnerability / Threat Intelligence Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a… Read More "Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access"