Ravie LakshmananAug 11, 2026Botnet / Vulnerability Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The… Read More "Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing"
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
“The entire operation, from finding the flaw to building a working exploit, was carried out by A [Security] using fewer than 20 prompts on publicly available AI models in under 24 hours,” the company said in its report. “This class… Read More "Zoom zero-click RCE flaws allow attackers to compromise meeting participants"
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
A burgeoning ransomware-as-a-service (RaaS) operation is using known exploited vulnerabilities in campaigns against critical infrastructure and government organizations around the globe. US and South Korean government agencies issued a joint cybersecurity alert on Monday regarding Gunra, a ransomware gang that… Read More "Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA"
RedWing Android Spyware Sold as a Service on Telegram
A new Android spyware strain has been observed being rented out to criminals through Telegram, giving even low-skilled attackers the tools to hijack phones and steal banking credentials, researchers have found. Zimperium’s zLabs named the malware RedWing and described it… Read More "RedWing Android Spyware Sold as a Service on Telegram"
Surviving a LockBit Ransomware Attack: The ROI of Visibility
In August 2023, while thousands of students at William Jewell College were hauling mini-fridges and textbooks into dorms, the invisible, digital heart of the campus was flatlining. There was no internet. No email. Even the HVAC system, tied to a… Read More "Surviving a LockBit Ransomware Attack: The ROI of Visibility"
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
AI governance, once the purview of the legal department, is now knocking on the CEO’s door. But many C-Suite executives are still treating it as something to delay addressing until after AI regulations are set in stone. This can be… Read More "The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It"
Incident Response Playbook for Actionable Workflows
Covers malware only, not identity or cloud Written when endpoint malware was the primary threat Add explicit identity and cloud/SaaS containment branches No backup decision owner Assumes the primary owner is always reachable Two-deep on-call rotation with clear handoff rules… Read More "Incident Response Playbook for Actionable Workflows"
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Swati KhandelwalAug 11, 2026Vulnerability / Windows Security Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network… Read More "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack"
Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Almost a third of UK manufacturers (30%) experienced a cyber incident over the past year, either directly or through their supply chain. Despite this, the sector’s cyber resilience maturity remains far from optimal, according to a new report by Make… Read More "Only Half of UK Manufacturers Have a Cyber Incident Response Plan"
Top Vendor Risk Monitoring Solutions for Continuous Oversight
Most vendor risk programs still rely on periodic assessments that capture a single snapshot of a vendor’s security posture, then go silent for months while that posture changes. Attackers exploit those same gaps between scheduled reviews, and the numbers prove… Read More "Top Vendor Risk Monitoring Solutions for Continuous Oversight"