Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

C1 adds shadow AI discovery to its identity governance platform

C1 has launched shadow AI discovery to eliminate the massive security blind spots created by unauthorized AI agents, tools, and credentials. By automatically discovering and folding every AI-adjacent identity into C1’s existing identity governance platform, organizations can finally ensure that the governed path is the fastest path to safe AI adoption. Shadow AI discovery works across two surfaces. In the cloud, C1 uses connectors to find unowned agents and map every MCP server, API, and … More → The post C1 adds shadow AI discovery to its identity governance platform appeared first on Help Net Security.

BY Industry News
MIN READ 1 MIN READ
EXPLORE north_east
C1 adds shadow AI discovery to its identity governance platform
Google changes how it names cyber threat actors
CYBERSECURITY

Google changes how it names cyber threat actors

Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over years. Previously, Mandiant and Google’s Threat Analysis Group maintained separate naming schemes, resulting in a mix of sequential identifiers, such as APT1, and other independently developed names. GTIG says this made … More → The post Google changes how it names cyber threat actors appeared first on Help Net Security.

1 MIN READ arrow_forward
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
CYBERSECURITY

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

1 MIN READ arrow_forward
Booz Allen expands Vellox Suite with AI-driven threat detection platform
CYBERSECURITY

Booz Allen expands Vellox Suite with AI-driven threat detection platform

Booz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify exploitable paths and vulnerabilities based on the actual state of an enterprise’s infrastructure. This automation helps protect the systems that matter most and reduces the risk of operational disruption, limits how long attackers can remain undetected in an environment … More → The post Booz Allen expands Vellox Suite with AI-driven threat detection platform appeared first on Help Net Security.

1 MIN READ arrow_forward
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
CYBERSECURITY

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools. “The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in

1 MIN READ arrow_forward
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
CYBERSECURITY

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is a Microsoft Windows Server role that lets an organization run its own Public Key Infrastructure (PKI). It acts as a Certificate Authority (CA), issuing and managing digital certificates used for authentication, encryption, and signing across … More → The post PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) appeared first on Help Net Security.

1 MIN READ arrow_forward
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CYBERSECURITY

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

2 MIN READ arrow_forward