CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

US Cybersecurity Agency Warns of Critical TrueConf Server Flaws Under Active Attack A serious vulnerability in popular video conferencing platform TrueConf has been exploited by hackers, prompting the US cybersecurity agency CISA to urge federal agencies to patch the issue immediately. The warning highlights the urgent need for organizations to address this critical flaw before … Read more

Microsoft Patches Exploited Entra ID Vulnerability

Microsoft has rolled out a batch of 22 critical security updates to address severe vulnerabilities in its products, including one that’s already being exploited by attackers. The tech giant has patched the issue internally, but hasn’t disclosed any information about the attacks involving this flaw. The most pressing concern is a zero-day vulnerability tracked as … Read more

Lawmakers seek watchdog review of federal hacking of Americans

Federal Government’s Secret Hacking Practices Under Scrutiny as Lawmakers Demand Transparency A growing concern over the US government’s use of hacking and spyware to surveil American citizens has led a pair of lawmakers to request an investigation into the matter. Sen. Ron Wyden (D-Ore.) and Rep. Greg Casar (D-Texas) have written to the Government Accountability … Read more

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

US Cybersecurity Agency Warns of Active Attacks on TrueConf Video Conferencing Platform The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies, urging them to immediately patch two critical vulnerabilities in the popular video conferencing platform, TrueConf. The agency has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) … Read more

Microsoft Patches Exploited Entra ID Vulnerability

Microsoft has just rolled out a batch of 22 critical security updates to patch severe vulnerabilities in multiple products. Among these patches is one that addresses a zero-day exploit in its Entra ID service, which was being actively targeted by attackers. The exploited vulnerability, tracked as CVE-2026-69836, had the potential for remote code execution (RCE), … Read more

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Cybersecurity Compliance Confidence Soars Among Defense Contractors, but Can They Back It Up? The defense industry is breathing a collective sigh of relief as contractors express increased confidence in their cybersecurity compliance. However, a closer look at two recent surveys reveals a concerning disconnect between confidence and actual readiness. According to a survey by Kiteworks, … Read more

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

A Growing Divide Between Defense Contractors’ Confidence and Reality Two recent surveys paint a concerning picture for defense contractors: while they claim to be more confident than ever in their cybersecurity compliance, their ability to prove it is lagging behind. This disconnect has significant implications for both individual companies and the broader national security landscape. … Read more

Rust Supply Chain Attack Linked to North Korean Hackers

North Korean hackers have launched a sophisticated supply chain attack on the Rust programming language ecosystem, compromising one of its most popular packages and potentially putting millions of users at risk. The attack, which occurred on August 20, involved a malicious version of the arrayref crate being pushed to crates.io from a legitimate maintainer’s account. … Read more