Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Google Adopts New Threat Actor Naming System

The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.

BY Ionut Arghire
MIN READ 1 MIN READ
EXPLORE north_east
Google Adopts New Threat Actor Naming System
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
CYBERSECURITY

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already

1 MIN READ arrow_forward
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
CYBERSECURITY

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel’s network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local

1 MIN READ arrow_forward
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
CYBERSECURITY

Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved

1 MIN READ arrow_forward
Shadow AI incident response begins with logs that may already be gone
CYBERSECURITY

Shadow AI incident response begins with logs that may already be gone

In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Wityak also discusses the gap between an AI policy in a wiki and a control … More → The post Shadow AI incident response begins with logs that may already be gone appeared first on Help Net Security.

1 MIN READ arrow_forward
AI took more than junior developer jobs and the bill comes later
CYBERSECURITY

AI took more than junior developer jobs and the bill comes later

A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and the patch merges before lunch. The second path wins on every number your team reports this quarter. It also removes the only training that junior was going to get, and it removes it at every … More → The post AI took more than junior developer jobs and the bill comes later appeared first on Help Net Security.

1 MIN READ arrow_forward
Download: The High-Performance Team Playbook
CYBERSECURITY

Download: The High-Performance Team Playbook

Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentionally across people, structure, leadership, and AI. What you’ll learn: How to build ownership, trust and clarity in engineering teams How to hire and retain for performance, not comfort How to structure teams that scale without … More → The post Download: The High-Performance Team Playbook appeared first on Help Net Security.

1 MIN READ arrow_forward
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
CYBERSECURITY

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. “VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

1 MIN READ arrow_forward
Cloud Security Alliance CISO Community Releases Emergency Guidance After Autonomous AI Model Breached Hugging Face's Production Systems During a Security Evaluation
CYBERSECURITY

Cloud Security Alliance CISO Community Releases Emergency Guidance After Autonomous AI Model Breached Hugging Face's Production Systems During a Security Evaluation

New report analyzes the first publicly documented fully autonomous cyberattack and delivers practical steps security leaders should take to strengthen their AI resilience today SEATTLE – July 28, 2026 – The Cloud Security Alliance (CSA) today released Hugging Face Incident Initial Post Mortem, a strategy briefing distilling lessons from the first publicly documented fully autonomous attack in which OpenAI models broke out of their test sandbox, exploited a zero-day vulnerability, and co…

1 MIN READ arrow_forward