Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

A Critical Vulnerability in Fortinet Products is Being Exploited to Deploy a Powerful Backdoor Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a powerful backdoor, known as PivotC2 RAT. This high-severity bug was patched by Fortinet in January, but it appears that some organizations are still … Read more

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

Microsoft’s Windows Defender is once again at the center of a cybersecurity storm, courtesy of a new zero-day exploit dubbed ShieldCrash. This latest vulnerability, discovered by security researcher Nightmare Eclipse, targets fully patched Windows systems and allows attackers to gain full System privileges. The proof-of-concept (PoC) code released by Nightmare Eclipse demonstrates an arbitrary file … Read more

EU Cyber Resilience Act to Enforce New Reporting Requirements

The European Union has taken a significant step towards enhancing cyber resilience in its member countries with the introduction of the Cyber Resilience Act (CRA). Starting September 11, businesses operating in the EU will be required to report serious product security incidents within 24 hours, or face hefty penalties. This move marks a major shift … Read more

Trezor warns users of email provider breach, phishing attacks

Cryptocurrency hardware wallet maker Trezor is warning its customers of a phishing attack that’s exploiting a recent breach of its third-party email provider. The attackers are sending fake “critical security alert” emails claiming to inform users about a vulnerability in the microcontrollers used by Trezor cold storage wallets, but this is actually a ploy to … Read more

Microsoft fixes bug that wiped Windows desktop settings

Microsoft has just fixed a critical bug that was causing desktop settings to be lost or reset on some Windows devices. The issue, which affected Windows 11 systems running on versions 24H2 and 25H2, wiped out wallpaper and theme settings, leaving users with a blank black screen. What’s more alarming is that this bug also … Read more

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

Major Chipmakers Issue Critical Security Advisories to Patch Vulnerabilities in Popular Products The world’s leading chipmakers have published crucial security advisories this week, warning customers about vulnerabilities recently discovered in their products. AMD, Arm, and Nvidia have all issued fixes for critical flaws that could allow attackers to crash systems, steal sensitive information, or take … Read more

Android’s September 2026 Updates Patch 180 Vulnerabilities

Android’s September 2026 Security Patch Brings Relief for Millions of Users Google has released patches for a staggering 180 vulnerabilities in its Android operating system, marking one of the largest security updates in recent history. The patches, which are part of the September 2026 Android security updates, address critical and high-severity flaws that could have … Read more

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

As cyberattacks become increasingly sophisticated, a new threat has emerged that’s giving lesser-resourced attackers nation-state-level reach: Artificial Intelligence (AI). According to Google’s Threat Intelligence Group (GTIG), adversaries are leveraging AI to automate and scale their attacks, rendering traditional security measures ineffective. Google’s GTIG has been tracking the evolution of AI-assisted attacks, which started with relatively … Read more

HelmGuard Raises $7.3 Million for Agentic GRC and Security

HelmGuard Raises $7.3 Million to Revolutionize Risk Management with AI-Powered Platform Cybersecurity startup HelmGuard has secured a significant $7.3 million in seed funding, co-led by Infinity Ventures and Frontline, to further develop its innovative agentic governance, risk, and compliance (GRC) and security platform. Founded in 2024 by former Palantir executive John Daley and Jack Miller, … Read more

Identity-Based AI Attack Threatens Security of Enterprise Data

A New AI Attack Vector Exposes Enterprise Data to Threat Actors In a disturbing development that highlights a critical flaw in modern enterprise artificial intelligence (AI) pipelines, security researchers have identified a new type of attack flow that can bypass standard security controls and hijack an organization’s data. Dubbed “workflow identity hijacking,” this attack vector … Read more