Policy

84 stories from 23 sources

BleepingComputer · 17h ago

Critical SharePoint RCE flaw exploited to steal machine keys

Critical SharePoint RCE flaw exploited to steal machine keys Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affecte…

impact 81
BleepingComputer · 21h ago

Critical wp2shell WordPress flaws exploited to install webshells

Critical wp2shell WordPress flaws exploited to install webshells Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent websh…

impact 81
BleepingComputer · 2h ago

CISA orders urgent action on actively exploited Langflow RCE flaw

CISA orders urgent action on actively exploited Langflow RCE flaw The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vuln…

impact 64
BleepingComputer · 1d ago

Closing the Identity Gaps in Critical Infrastructure Security

Closing the Identity Gaps in Critical Infrastructure Security Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust shoul…

impact 48
EFF · 3w ago

Primed for Malware: Stop Selling Compromised Android Devices

Primed for Malware: Stop Selling Compromised Android Devices Time and time again, researchers have found numerous compromised Android devices for sale at large online retailers like Amazon. When these devices get indivi…

impact 42
Wired · 15h ago

OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI Models Escaped Containment and Hacked Hugging Face The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off…

impact 38
Wired · 4d ago

Your Period Tracker Is (Probably) Spying on You

Your Period Tracker Is (Probably) Spying on You Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

impact 30
Dark Reading · 12d ago

Fresh ATM Crypto Software Bugs: Jackpot or Bust?

Fresh ATM Crypto Software Bugs: Jackpot or Bust? Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.

impact 29
GitHub Blog · just now

Next chapter: Restructuring GitHub’s bug bounty program

Next chapter: Restructuring GitHub’s bug bounty program GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The p…

impact 16
CoinTelegraph · 4h ago

Galaxy pledges $5M for developers quantum-proofing Bitcoin

Galaxy pledges $5M for developers quantum-proofing Bitcoin Galaxy pledged up to $5 million in grants for developers working on Bitcoin’s quantum security and elected a council of quantum-advisory experts to research qua…

impact 16
BleepingComputer · 8h ago

OpenAI says its AI models hacked Hugging Face during testing

OpenAI says its AI models hacked Hugging Face during testing OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested i…

impact 16
BleepingComputer · 14h ago

Police dismantle Kratos phishing platform, arrest developer

Police dismantle Kratos phishing platform, arrest developer Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its develo…

impact 16
Wired · 2d ago

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written…

impact 16
KrebsOnSecurity · 7d ago

Microsoft Patches a Record 570 Security Flaws

Microsoft Patches a Record 570 Security Flaws Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerab…

impact 16
Dark Reading · 11d ago

Jen Ellis: Connecting Cyber Community With Political Machinery

Jen Ellis: Connecting Cyber Community With Political Machinery Security Pro File: On the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Jen…

impact 16
Cloudflare Blog · 3w ago

Your site, your rules: new AI traffic options for all customers

Your site, your rules: new AI traffic options for all customers For our second Content Independence Day, we’re giving website owners finer options to manage AI traffic. Instead of a one-size-fits-all block, all customer…

impact 16
SecurityWeek · 1h ago

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Vibe-Coded Apps Riddled With Exploitable Security Flaws Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post…

impact 16

All Categories