The CEO of Anthropic said Saturday the artificial-intelligence industry should slow its fast-moving development to give safety measures time to catch up. Without such a slowdown, Dario Amodei warned that within six to 12 months AI could be capable of… Read More "Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up"
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved… Read More "Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data"
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Ravie LakshmananSep 12, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation… Read More "CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV"
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to… Read More "BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days"
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but… Read More "When the Whole Company Adopts AI: What It Does to Your SOC"
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
In one case, a group of Russian state-sponsored hackers identified by Microsoft as Midnight Blizzard used Claude for reconnaissance, breaching targets that included Ukrainian and other European government networks, and stole data and maintained access. Cybercriminal group ShinyHunters used Claude… Read More "From Hacks to Bioweapons, Claude Misuse Is Now Everywhere"
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld,… Read More "OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers"
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic says Claude users in northern Yemen, territory controlled by Iran-backed Houthi rebels, tried to use the AI model to develop advanced missiles. AI is already transforming warfare from Ukraine to Gaza, and its use on a rugged and remote… Read More "Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says"
Biggest Data Breaches in Retail (Updated August 2026)
Retail is the most consistently targeted consumer-facing sector in the history of breach reporting, and the reason is structural. Retailers concentrate payment card data, run point-of-sale (POS) estates across thousands of stores, load high-traffic checkouts with third-party JavaScript, and depend… Read More "Biggest Data Breaches in Retail (Updated August 2026)"
What’s New in Risk Automations: 4 Templates for Vendor and User Risk
Most vendor onboarding and app access work is waiting and follow-ups. Waiting for someone to notice a form came in, assign a tier, chase a questionnaire, or dig up the context behind a Slack request. Risk Automations workflows remove that… Read More "What’s New in Risk Automations: 4 Templates for Vendor and User Risk"