Zoom on Tuesday announced rolling out patches for four vulnerabilities in its products, including a severe flaw that allowed zero-click remote code execution (RCE). Impacting Zoom’s clients on all supported platforms, three of the security defects were discovered in the… Read More "Zoom Patches Zero-Click Code Execution Vulnerability"
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. “Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding… Read More "OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development"
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window
Keith Prabhu, founder and CEO of Confidis, also argued that models such as GPT-5.6-Cyber may accelerate vulnerability discovery and weaponization without fundamentally shifting the attacker-defender balance, because attackers and defenders are likely to gain access to broadly similar capabilities Governance… Read More "OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window"
Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust
A flaw in Cursor’s command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer’s machine before they were asked whether they trusted it, and outside the sandbox even when the… Read More "Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust"
What Is an RFP Response? A Guide for Security and GRC Teams
A request for proposal (RFP) response is a vendor’s formal reply to a procurement document where a prospective buyer outlines all the information they need to make a final purchasing decision. It acts as a detailed pitch, typically covering pricing,… Read More "What Is an RFP Response? A Guide for Security and GRC Teams"
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that… Read More "A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call"
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Corma emerged from stealth mode on Monday with $60 million in funding for a foundation model designed specifically for defensive cybersecurity. Headquartered in Tel Aviv and San Francisco, Corma was founded in 2025. One of the company’s founders is Alon… Read More "Corma Raises $60 Million for Defensive Cybersecurity AI Model"
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device… Read More "A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices"
GitHub already has an EDR. You just have to listen to it
After studying recent supply-chain attacks, including Shai-Hulud, Trivy, and Megalodon, the researchers found that seemingly different incidents repeatedly used the same techniques, from forged commit identities and poisoned tags to workflow abuse, OpenID Connect (OIDC) theft, and attempts to erase… Read More "GitHub already has an EDR. You just have to listen to it"
Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo
Suisan City in California is continuing to grapple with an ongoing cyber-incident, amid a spate of cyber-attacks targeting local authorities in the US. The City government declared a state of emergency after its IT network was infected by “malicious software”… Read More "Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo"