loader image
Anthropic’s Claude Finds 500 High-Severity Flaws

Anthropic’s Claude finds flaws in more than 500 high-severity vulnerabilities across widely used open-source libraries, the company said Thursday. The artificial intelligence firm unveiled Claude Opus 4.6, its latest large language model, which includes enhanced capabilities for code review and debugging. The newly identified flaws span libraries such as Ghostscript, OpenSC, and CGIF — all […]

Zscaler Buys SquareX to Embed Browser Security

Zscaler buys browser security startup SquareX in a move aimed at enhancing web protection without adding software bloat. The acquisition allows users to embed lightweight security extensions directly into any browser, removing the dependence on standalone secure browsers or third-party tools. Zscaler positions this as a streamlined alternative that improves both endpoint security and user […]

F5 Patches DoS Flaws in BIG-IP and NGINX

F5 patches DoS flaws across its BIG-IP, NGINX, and container platforms in its latest February 2026 security notification. The company addressed several medium to low-severity vulnerabilities, mainly tied to denial-of-service risks and configuration weaknesses. These flaws threaten services such as web application firewalls and Kubernetes ingress controllers, especially in high-traffic environments. While F5 reported no […]

AWS Admin Account Breached in 10 Minutes With AI

A security researcher has demonstrated how a threat actor breached an AWS admin account in under 10 minutes using generative AI, accelerating each step of the intrusion. By leveraging large language models (LLMs), the attacker automated reconnaissance, exploit development, privilege escalation, and lateral movement, leaving minimal traces behind. The finding underscores growing concerns over the […]

WatchGuard Patches VPN, Firebox LDAP Flaws

WatchGuard has rolled out critical security updates after identifying two vulnerabilities that could be exploited by attackers to elevate privileges on Windows systems or extract sensitive credentials. The company’s latest advisory comes as part of broader efforts to strengthen its network defenses, with the fixes addressing flaws discovered in its VPN and Firebox appliances. The […]

Facebook Ads Feed Tech Support Scam via Azure

A new cyber campaign is leveraging the facebook ads feed to deceive users and funnel them into a convincing tech support scam. Researchers at Gen Threat Labs have uncovered a three-step malvertising chain that begins when a user clicks a sponsored ad on Facebook. Instead of reaching a legitimate site, they’re rerouted to a fake […]

NGINX Servers Redirect Traffic to Attacker Domains

Threat actors are exploiting NGINX server configurations to redirect web traffic to attacker-controlled destinations in a new, covert campaign. The attackers, linked to previous React2Shell exploits, are now focusing on servers using the Baota panel, a popular management tool in Asian markets. Rather than deploying traditional malware, they inject malicious directives into NGINX location blocks. […]

Truesec Flags OpDenmark Cyber Threat

Cybersecurity firm Truesec flags the OpDenmark campaign as a growing digital threat after a Russian-linked group, the Russian Legion, warned of a large-scale cyberattack targeting Denmark. The warning surfaced as regional tensions continue to escalate across Europe, raising concerns among public and private sector entities. Truesec identified coordinated activity that appears to be part of […]

Moltbook Network Exposes Bot-to-Bot Data Leaks

A new investigation into the Moltbook network exposes data vulnerabilities and raises alarm over prompt injection risks between AI agents. Researchers from Wiz and Permiso analyzed the AI-driven social platform and discovered multiple security flaws. These include bot-to-bot prompt injection attacks, where one agent can manipulate another’s behavior using crafted text prompts, and unintentional data […]

Russian State Hackers Exploit Microsoft Flaw

Russian state hackers began exploiting a newly disclosed Microsoft Office vulnerability to target systems in Ukraine and the European Union, according to Ukraine’s cybersecurity agency. The country’s Computer Emergency Response Team, CERT-UA, reported that attackers moved quickly after Microsoft revealed the flaw, tracked as CVE-2026-21509, in early January. The vulnerability affects how Microsoft Office applications […]

Poland Detains Defense Official in Russia Spy Case

Poland detains a defense official on allegations of spying for Russia, authorities said, in a move that intensifies tensions between Warsaw and Moscow. The suspect, a 60-year-old Polish citizen, worked in the Ministry of National Defense’s strategy and planning department. He was involved in military modernization projects, according to government officials. Authorities arrested the man […]

Hikvision AP Flaw Lets Users Run Commands

A newly disclosed vulnerability in multiple Hikvision wireless access point models poses a high-severity risk to enterprise networks. The Hikvision AP flaw, tracked as CVE-2026-0709, allows attackers with valid credentials to execute arbitrary commands due to weak input validation within the WAP firmware. The vulnerability carries a CVSS v3.1 base score of 7.2. This flaw […]