Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey’s State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55

BY The Hacker News
MIN READ 1 MIN READ
EXPLORE north_east
The Fastest Path to AI Adoption Runs Through Security
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
CYBERSECURITY

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week. The AI company said the models were operating with “reduced cyber refusals for evaluation purposes” that might otherwise limit their ability to

1 MIN READ arrow_forward
Why Modern SOCs Need Multi-Layered Detections
CYBERSECURITY

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on

1 MIN READ arrow_forward
First-Person Identity Theft Story
CYBERSECURITY

First-Person Identity Theft Story

Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts hangs on the security of our email accounts.

1 MIN READ arrow_forward
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
CYBERSECURITY

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA)

1 MIN READ arrow_forward
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
CYBERSECURITY

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the

1 MIN READ arrow_forward
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
CYBERSECURITY

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had

1 MIN READ arrow_forward
LG to Ban Residential Proxies from Smart TV Apps
CYBERSECURITY

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

1 MIN READ arrow_forward
Growing up the hard way
CYBERSECURITY

Growing up the hard way

Open source is growing up. Explore why AI, regulation, and enterprise security are reshaping how organizations consume open source software.

1 MIN READ arrow_forward
The Model Did Exactly What We Asked
CYBERSECURITY

The Model Did Exactly What We Asked

An AI “went rogue” last week, just like out of a science fiction movie. Not because it turned on us, but to achieve its defined objective. Just as we were planning our CISO huddle on the Hugging Face attacks, a jaw dropping post from OpenAI was released that completely reframed the entire situation. Hold on people, because this one sure sounds like a story from a SciFi movie. What actually happened On July 21, OpenAI and Hugging Face jointly disclosed the details behind an i…

1 MIN READ arrow_forward
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
CYBERSECURITY

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches Background On July 21, Oracle released its Critical Patch Update (CPU) for July 2026, the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this quarter, 18% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 52.7%, followed by medium severity patches at 24.7%. This quarter’s update includes 261 critical patches across 228 CVEs. Severity Issues Patched CVEs Critical 261 228 High 763 613 Medium 358 332 Low 67 62 Total 1449 1235 Analysis This quarter, the Oracle E-Business Suite product family contained the highest number of patches at 410, accounting for 28.3% of the total patches, followed by Oracle Fusion Middleware at 355 patches, which accounted for 24.5% of the total patches. A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product Family Number of Patches Remote Exploit without Auth Oracle E-Business Suite 410 45 Oracle Fusion Middleware 355 219 Oracle Communications 168 122 Oracle PeopleSoft 84 45 Oracle MySQL 54 9 Oracle Siebel CRM 45 32 Oracle Commerce 39 26 Oracle Supply Chain 39 16 Oracle Financial Services Applications 31 26 Oracle GoldenGate 27 9 Oracle Enterprise Manager 27 13 Oracle Retail Applications 22 20 Oracle JD Edwards 20 4 Oracle Java SE 19 17 Oracle Virtualization 16 0 Oracle Database Server 15 6 Oracle TimesTen In-Memory Database 14 4 Oracle Utilities Applications 14 10 Oracle Construction and Engineering 7 7 Oracle Analytics 7 5 Oracle Systems 6 0 Oracle SQL Developer 5 5 Oracle Autonomous Health Framework 4 3 Oracle Application Testing Suite 4 4 Oracle Food and Beverage Applications 4 4 Oracle HealthCare Applications 4 4 Oracle APEX 3 2 Oracle Hospitality Applications 2 2 Oracle Essbase 1 1 Oracle Global Lifecycle Management 1 1 Oracle NoSQL Database 1 1 Oracle Spatial Studio 1 1 Solution Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the July 2026 advisory for full details. Identifying affected systems A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released. Get more information Oracle Critical Patch Update Advisory - July 2026 Oracle July 2026 Critical Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

3 MIN READ arrow_forward