Latest Briefings
Arch Linux Halts AUR Package Adoption After Malware Takeover Surge
Arch Linux has temporarily disabled Arch User Repository package adoption following a wave of malicious takeovers, with researchers linking the campaign to…
Chinese Threat Actor Uses DeepSeek AI to Run Autonomous Server Attacks
Palo Alto Networks' Unit 42 uncovered a campaign in which a China-based hacker used DeepSeek paired with the open-source Hermes Agent to…
Anthropic Says Claude Escaped Sandbox, Published Malware to PyPI, Breached 3 Orgs
A misconfigured evaluation environment let Claude models reach the live internet during capture-the-flag tests, resulting in real malware on PyPI and compromised…
Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…
Security Researchers Warn AI Harnesses Are Ripe for Exploitation
The sprawling stack of components that surround and operate AI models, often called an AI harness, is emerging as a fresh attack…
Analog Devices Discloses Data Breach, Says Operations Unaffected
The semiconductor giant detected unauthorized access to its systems on June 23 and is separately assessing claims from an extortion group that…
US and 13 Allied Nations Refresh Minimum SBOM Guidance
Government agencies update the 2021 NTIA baseline for software bills of materials, adding new data fields for hashing, licensing, and tooling while…
Claroty: 1 in 5 Data Center OT Assets One Hop From Internet Exposure
New research from Claroty finds that while direct internet exposure of data center infrastructure is rare, thousands of power, cooling, and building…
OpenAI Says Rogue Agent Breached Four Third-Party Services in Hugging Face Incident
OpenAI has expanded the scope of its Hugging Face security incident, confirming an escaped AI agent used exposed credentials to access four…
Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV
A static low-privilege credential baked into Cisco Secure Firewall Management Center software is being actively exploited, prompting hot fixes, IOC guidance, and…
Spur Lands $200 Million from Insight Partners to Scale IP Intelligence Platform
Bootstrapped bot-detection and IP intelligence firm Spur Intelligence takes its first outside investment, aiming to help security and fraud teams unmask traffic…
Arista Patches Max-Severity VeloCloud Orchestrator Flaw Under Active Attack
CVE-2026-16812, an unauthenticated command injection flaw scoring a perfect 10.0, is being exploited against on-premises VeloCloud Orchestrator deployments. CISA has added it…