OpenAI has pledged to spend $1bn on subsidizing access to its Daybreak cyber models for essential services across the US and around the world. The Daybreak for Frontline Defenders initiative will see OpenAI assist critical sectors implement its AI models… Read More "OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential S"
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Hackers targeted operational technology (OT) systems at two private water utilities in Colorado in late August, apparently attempting to cause disruptions. Few technical details are available, but it seems the attackers targeted industrial control systems (ICS) at the water utilities,… Read More "Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems"
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Security experts have warned that a major data breach at a Japanese image-sharing service could pose a significant security and privacy risk to users via exposed metadata records. The breach at Gyazo, disclosed on September 11, exposed nearly 24 million… Read More "Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records"
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them. Tracked as CVE-2025-39682 (CVSS score of 9.8), the first of the bugs is a… Read More "Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities"
GraphWorm: Why revoking tokens won’t stop OneDrive C2 backdoors
Sit with the consequence for a second. Your investigation reaches the point where you have identified the application, you file with the platform and the tokens get revoked. The implant’s next poll fails. If the operator is watching, and an… Read More "GraphWorm: Why revoking tokens won’t stop OneDrive C2 backdoors"
Revolut Customers Targeted with New Wave of Phishing Attacks
Hackers have seized on a data breach at digital financial firm Revolut to try and harvest more account information from customers, according to Malwarebytes. The security vendor said it had uncovered several examples of Revolut customers receiving smishing messages by… Read More "Revolut Customers Targeted with New Wave of Phishing Attacks"
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams… Read More "ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure"
5 ways AI is reshaping the cybersecurity job market
Mario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company’s dedicated vulnerability management function in late 2025, folding its responsibilities directly into IT and product security. AI… Read More "5 ways AI is reshaping the cybersecurity job market"
Google Confirms Gemini AI Breached Three Firms
Google has confirmed that one of its Gemini models accessed the systems of three real companies during a cybersecurity test in May. The Wall Street Journal first reported the incidents on Friday, describing them as the first known case of… Read More "Google Confirms Gemini AI Breached Three Firms"
Introducing Subprocessor listing in Trust Center profiles
At UpGuard, we believe your Trust Center should be the single place your prospects and customers go to get their trust questions answered. Today, we’re excited to announce subprocessor listing in the Trust Center. This capability lets you publish your… Read More "Introducing Subprocessor listing in Trust Center profiles"