Enterprise Defenses Recovered at the Edge and Collapsed Inside

Cybersecurity teams are facing a new challenge as threat actors exploit identity exposure to bypass enterprise defenses, not just at the edge but also deep within internal networks. In a growing trend, hackers are using exposed identities and cross-domain privilege escalation to create active attack paths that can remain hidden even after initial breach points … Read more

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

A Critical Flaw in AI API Security Exposes Weaker Models’ Secrets A recent discovery has highlighted a significant vulnerability in the way some artificial intelligence (AI) models interact with each other. Researchers have found that weaker AI models can decode the reasoning behind stronger models’ decisions, potentially exposing sensitive information and undermining trust in AI … Read more

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

**Multiple Chrome VPN Extensions Caught Redirecting Traffic Through Proxies, Putting Users’ Data at Risk** A disturbing discovery has been made in the world of cybersecurity, as multiple popular Chrome VPN extensions have been caught routing users’ internet traffic through unauthorized proxies. This revelation highlights a critical vulnerability that could compromise sensitive information and leave users … Read more

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

A New Zero-Day Exploit in Microsoft Defender Allows System Privileges Grab In a shocking revelation, a security researcher known as Nightmare Eclipse has unleashed a new zero-day exploit in Microsoft Defender called ShieldBreak. This vulnerability is particularly concerning because it can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and … Read more

Signal adds new security feature to thwart man-in-the-middle attacks

Signal’s Latest Move: Automatic Key Verification Takes Aim at Man-in-the-Middle Attacks In a significant step to strengthen its users’ online security, messaging app Signal has introduced Automatic Key Verification – a new feature designed to detect and prevent man-in-the-middle (MitM) attacks. This innovative system uses Cloudflare and Trail of Bits as trusted third-party auditors to … Read more

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Cybersecurity experts have sounded an alarm after discovering that malicious LiteLLM releases linked to a Trivy hack may have exposed over 2,100 organizations worldwide. The threat actors exploited vulnerabilities in the popular security scanning tool, using it as a springboard for privilege escalation and domain hopping attacks. The Trivy hack allowed attackers to create customized … Read more

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

A critical vulnerability in VMware vCenter has been exploited by attackers, giving them persistent remote access to affected systems. VMware’s virtualization platform is used by over 500,000 organizations worldwide, including some of the largest enterprises and government agencies. This means that a significant number of companies are potentially vulnerable to this attack. The vulnerability, tracked … Read more

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe Patches Three Critical Flaws in ColdFusion and Campaign Classic, Leaving Many Vulnerable Adobe has released a slew of patches for its ColdFusion and Adobe Campaign Classic platforms, addressing three critical vulnerabilities that could allow attackers to gain complete control over affected systems. With CVSS scores ranging from 9.8 to the maximum possible score of … Read more

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

A new Microsoft Defender zero-day exploit has been disclosed by a security researcher, allowing attackers to gain SYSTEM privileges on fully patched Windows systems. The exploit, named “ShieldBreak,” was released just days after Microsoft’s August 2026 Patch Tuesday security updates. The vulnerability is particularly concerning because it bypasses another previously patched flaw in Microsoft Defender … Read more

Signal adds new security feature to thwart man-in-the-middle attacks

Signal has rolled out a new security feature designed to thwart man-in-the-middle (MITM) attacks on its encrypted chat platform. Automatic Key Verification is part of a “key transparency” system that uses trusted third-party auditors to verify the integrity of Signal conversations, giving users a new way to ensure their chats haven’t been intercepted. This new … Read more