Browsing Category
News Brief
83 posts
Nvidia, CrowdStrike, 30+ Firms Launch Open Secure AI Alliance
Nvidia, CrowdStrike and dozens of rivals-turned-partners are betting that "open" beats regulated — building shared AI security tools now, before Washington decides who gets to use frontier models at all.
Adobe Patches 11 ColdFusion, Campaign Classic Flaws: Four Hit Max Severity
Adobe has patched 11 vulnerabilities in ColdFusion and Campaign Classic, including six critical flaws in ColdFusion that allow remote code execution. No active exploitation is reported. Users should update affected versions promptly.
Phishing Kits Abuse Microsoft Login Codes to Steal Cloud Access
LevelBlue says phishing kits are industrializing OAuth device-code attacks, giving attackers Microsoft 365 tokens without stealing a password first.
Microsoft’s Record Patch Tuesday Upstaged Within Hours by New Defender Zero-Day
Microsoft's June Patch Tuesday addressed about 200 vulnerabilities, but the emergence of a new exploit, RoguePlanet, highlights ongoing security concerns with Microsoft Defender.
Acer 5G Hotspot Has Three Critical Bugs: Patches Pending
Acer says firmware updates are coming and offers workaround fixes for three critical bugs.
Cisco Confirms Third SD-WAN Manager Zero-Day of 2026
Cisco warns of a high-severity flaw in its SD-WAN Manager, enabling attackers with netadmin access to gain root control.
CISA Pushes Oracle WebLogic Bug from Patch Backlog to Active-Exploit Priority
The agency added CVE-2024-21182 to its known exploited vulnerability catalog, giving federal agencies until June 4 to address a WebLogic Server flaw Oracle patched in July 2024.
DJI Audit Finds No Backdoors as FCC Fight Moves From Policy to Proof
DJI's independent security assessment found no significant risks in its drones, strengthening its position against U.S. regulations, despite ongoing security concerns and market uncertainties.
‘Malware-Slop’ npm Package Targets Claude AI User Files
OX Security said a malicious npm package tried to steal files from Claude user workspaces and upload them to GitHub.
Attackers Turned Trusted Developer Updates Into a Credential Trap
A supply-chain campaign hit trusted developer tools and package registries, exposing how quickly poisoned updates can steal cloud, code and CI/CD credentials.