Browsing Category
Latest News
47 posts
AI’s AppSec Catch-22: Faster Code, More Risk and a Shrinking Audit Trail
VIDEO: AI is speeding up software development, challenging security teams to balance rapid release with vulnerability management, leading to risks of deploying known vulnerabilities without adequate oversight.
SocGholish Takedown: 14,971 WordPress Sites Cleaned, Evil Corp Hit
Four countries, 106 servers seized, nearly 15,000 hijacked sites scrubbed. The fake-update pipeline goes dark.
Creative Soundbar Hack Hits a Bad Note
Turn it up to pwned. No authentication, no pairing, no physical access — just a custom firmware pushed over Bluetooth and a Katana V2X that now spies, types, and won't easily forget how.
Innovating Beyond the Security Bottleneck
Replica Cyber CEO Kris Schroeder says security teams need a safer way to support high-risk work as businesses turn to exceptions, workarounds and isolated environments to keep innovation moving.
Gartner Warns One-Size-Fits-All AI Agent Governance Will Backfire
Gartner predicts 40% of enterprises will demote or shut down autonomous AI agents by 2027 after governance gaps surface in production.
The 5 Biggest Shifts in Verizon’s 2026 DBIR: Security Teams Worked Harder and Still Lost Ground
Vulnerability exploitation overtook stolen credentials, third-party exposure climbed and security teams struggled to keep pace with growing attack volume.
MSHTA Won’t Die, and Attackers Know It
Attackers continue abusing Microsoft’s decades-old MSHTA utility, exposing a familiar Windows problem: Legacy components often stay active because removing them could break something.
Pwn2Own Berlin 2026 Closes With $1.3M Paid, 47 Zero-Days and a New Champion
DEVCORE's Orange Tsai-led team dominated all three days to claim the 2026 Master of Pwn title, while STARLabs SG delivered the weekend's most technically significant moment with a memory corruption exploit that broke out of a VMware ESXi hypervisor and crossed tenant boundaries.
Researchers Return to Pwn2Own Berlin Stage With $1M+ Prize Pool Still in Play
Orange Tsai's $200,000 Exchange exploit added fresh bruises to one of enterprise security's most battered attack surfaces as AI tools kept falling across the contest stage.
Closing the Gap: Tackling ‘Configuration Drift’ in Modern Security
AI security tools ease tasks but increase configuration drift, compromising cybersecurity effectiveness.