• Deterministic + Agentic AI: The Architecture Exposure Validation Requires

    Deterministic + Agentic AI: The Architecture Exposure Validation Requires

    Few technologies have moved from experimentation to boardroom mandate as quickly as AI. Across industries, leadership teams have embraced its broader potential, and boards, investors, and executives are already pushing organizations to adopt it across operational and security functions. Pentera’s AI Security and Exposure Report 2026 reflects that momentum: every CISO surveyed

    Read More

  • Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

    Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

    Microsoft on Tuesday released updates to address a record 169 security flaws across its product portfolio, including one vulnerability that has been actively exploited in the wild. Of these 169 vulnerabilities, 157 are rated Important, eight are rated Critical, three are rated Moderate, and one is rated Low in severity. Ninety-three of the flaws are

    Read More

  • OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams

    OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams

    OpenAI on Tuesday unveiled GPT-5.4-Cyber, a variant of its latest flagship model, GPT‑5.4, that’s specifically optimized for defensive cybersecurity use cases, days after rival Anthropic unveiled its own frontier model, Mythos. “The progressive use of AI accelerates defenders – those responsible for keeping systems, data, and users safe – enabling them to find and fix problems

    Read More

  • New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released

    New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released

    Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injection flaws affecting the Perforce VCS (version control software) driver. Details of the two flaws are below – CVE-2026-40176 (CVSS

    Read More

  • Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security

    Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security

    Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware as part of its ongoing efforts to beef up the security of Pixel devices and push memory-safe code at a more foundational level. “The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of…

    Read More

  • Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

    Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

    A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. “Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real

    Read More

  • Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)

    Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)

    OX Security recently analyzed 216 million security findings across 250 organizations over a 90-day period. The primary takeaway: while raw alert volume grew by 52% year-over-year, prioritized critical risk grew by nearly 400%. The surge in AI-assisted development is creating a “velocity gap” where the density of high-impact vulnerabilities is scaling faster than

    Read More

  • 108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

    108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

    Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. According to Socket, the extensions are…

    Read More

  • ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

    ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

    A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0. It relates to a case of unrestricted file upload that stems from improper validation of

    Read More

  • JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025

    JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025

    Banks and financial institutions in Latin American countries like Brazil and Mexico have continued to be the target of a malware family called JanelaRAT. A modified version of BX RAT, JanelaRAT is known to steal financial and cryptocurrency data associated with specific financial entities, as well as track mouse inputs, log keystrokes, take screenshots, and…

    Read More