Hackers are demanding a $3 million ransom from the British fintech giant Revolut after siphoning data from it through fake government requests for five months. Last week, the company notified potentially affected users that their personal information, passports, email addresses,… Read More "Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom"
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Swati KhandelwalSep 17, 2026Vulnerability / DNS Security Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious… Read More "Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone"
Self-modifying AI agents expose a blind spot in enterprise security
As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they rely on while carrying out routine tasks. Researchers at AI security firm Irregular asked… Read More "Self-modifying AI agents expose a blind spot in enterprise security"
Anthropic Users Hit by Infostealer Attacks, Session Thefts
Anthropic proactively signed an unknown number of users out of Claude after a threat actor stole their login sessions, accessed their accounts, and consumed their allotted usage. The attacks came to light via email alerts sent to affected users that… Read More "Anthropic Users Hit by Infostealer Attacks, Session Thefts"
New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Security researchers at Zimperium have discovered a new Android malware strain targeting credential and bank detail harvesting. The malware, named RatHat by the researchers, is linked to threat actors that appear to be operating in China. It incorporates novel techniques… Read More "New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data"
A Guide to Vendor Risk Management Reporting in 2026
Vendor Risk Management encompasses a wide range of cybersecurity risk factors. As such, a VRM report design could range from highly detailed to concise, depending on the specific reporting requirements of stakeholders and the board. This list represents the most… Read More "A Guide to Vendor Risk Management Reporting in 2026"
Using High-Energy Laser, US Shoots Down Drones Near Mexico Border
This week, the US Army used a high-energy multipurpose laser to shoot down three drones near the US-Mexico border, which official reports claimed were “posing a physical threat to US military personnel and CBP partners,” referring to Customs and Border… Read More "Using High-Energy Laser, US Shoots Down Drones Near Mexico Border"
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of… Read More "Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard"
AI Model Evaluator METR Hit by Credential Theft, Probing
A security nonprofit that helps evaluate risks in frontier AI models disclosed two cybersecurity incidents this week, including a breach that exposed an API key and a separate vulnerability that could have exposed nonpublic evaluation data. METR (Model Evaluation and… Read More "AI Model Evaluator METR Hit by Credential Theft, Probing"
Cisco Warns of Active Exploitation of Critical ISE Flaw
Cisco has warned customers of the active exploitation of a maximum severity flaw affecting its Cisco Identity Services Engine (ISE) product. The flaw, CVE-2026-76460, is due to insufficient control on an API endpoint. It has a maximum CVSS rating of… Read More "Cisco Warns of Active Exploitation of Critical ISE Flaw"