As concluded in the 2026 Verizon Data Breach Investigations Report. Vulnerability exploitation has overtaken credential abuse as the #1 initial access vector — 31%, up 55% year-over-year, versus 13% for credentials. That shift highlights an operational problem for every security… Read More "Top 10 Attack Surface Management Software Solutions in 2026"
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that… Read More "Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws"
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Swati KhandelwalAug 11, 2026Cryptography / Software Supply Chain Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company’s own private code repositories.… Read More "Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo"
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages have been found querying an attacker-controlled Ethereum wallet to work out where to fetch their next stage of malware, reading command-and-control (C2) addresses out of a blockchain transaction. Sonatype Research Labs identified the packages on August 10… Read More "Six npm Packages Read C2 Addresses From Ethereum Wallet"
The Ultimate Ransomware Defense Guide (2026)
Ransomware is the fasted-growing category of cybercrime. It’s estimated that over 4,000 ransomware attacks occur daily. Given the sheer volume of these attacks and the deep attack surface connections between organizations and their vendors, there’s a high likelihood that some… Read More "The Ultimate Ransomware Defense Guide (2026)"
Zoom Patches Zero-Click Code Execution Vulnerability
Zoom on Tuesday announced rolling out patches for four vulnerabilities in its products, including a severe flaw that allowed zero-click remote code execution (RCE). Impacting Zoom’s clients on all supported platforms, three of the security defects were discovered in the… Read More "Zoom Patches Zero-Click Code Execution Vulnerability"
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. “Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding… Read More "OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development"
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window
Keith Prabhu, founder and CEO of Confidis, also argued that models such as GPT-5.6-Cyber may accelerate vulnerability discovery and weaponization without fundamentally shifting the attacker-defender balance, because attackers and defenders are likely to gain access to broadly similar capabilities Governance… Read More "OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window"
Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust
A flaw in Cursor’s command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer’s machine before they were asked whether they trusted it, and outside the sandbox even when the… Read More "Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust"
What Is an RFP Response? A Guide for Security and GRC Teams
A request for proposal (RFP) response is a vendor’s formal reply to a procurement document where a prospective buyer outlines all the information they need to make a final purchasing decision. It acts as a detailed pitch, typically covering pricing,… Read More "What Is an RFP Response? A Guide for Security and GRC Teams"