Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts. Hide My Email

BY The Hacker News
MIN READ 1 MIN READ
EXPLORE north_east
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Beyond Human Identity: A Runtime Governance Model for Autonomous AI Agents in the Enterprise Cloud
CYBERSECURITY

Beyond Human Identity: A Runtime Governance Model for Autonomous AI Agents in the Enterprise Cloud

Introduction Enterprise identity management was built around people. Identity and Access Management (IAM) platforms started with employees, contractors, and partners, then stretched to cover service accounts, APIs, and machine identities. Every one of those extensions kept a quiet assumption intact: the identity itself does not make decisions. AI agents break that assumption. Organizations are deploying coding assistants, customer support agents, security copilots, and workflo…

1 MIN READ arrow_forward
Do more with AWS WAF labels using dynamic label interpolation
CYBERSECURITY

Do more with AWS WAF labels using dynamic label interpolation

AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from a known bot category or that it matched

1 MIN READ arrow_forward
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
CYBERSECURITY

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been

1 MIN READ arrow_forward
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
CYBERSECURITY

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot

1 MIN READ arrow_forward
Manual Patching Can’t Outrun AI. Automated Remediation Can.
CYBERSECURITY

Manual Patching Can’t Outrun AI. Automated Remediation Can.

Executive Summary AI is rapidly transforming vulnerability discovery, outpacing many security teams’ ability to adapt. Microsoft’s July 2026 Patch Tuesday addressed a record 622 vulnerabilities, an early signal of AI-accelerated discovery at scale compounding an already-large backlog that manual remediation can no longer keep pace with. Qualys TruRisk Eliminate’s AI-Powered Patch Reliability Score assesses whether

1 MIN READ arrow_forward
CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
CYBERSECURITY

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox

1 MIN READ arrow_forward
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
CYBERSECURITY

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE

1 MIN READ arrow_forward
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
CYBERSECURITY

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

1 MIN READ arrow_forward