China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

The China-linked threat actor known as UAT-7810 has expanded its ORB network with the introduction of new malware, dubbed LONGLEASH. This latest development highlights the evolving tactics employed by sophisticated nation-state actors and underscores the importance of staying vigilant in today’s increasingly complex cybersecurity landscape. UAT-7810 is a well-documented threat actor linked to China, known … Read more

Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security

Keyfactor Secures $1 Billion+ Investment for AI-Powered Post-Quantum Security Solution In a major development that highlights the growing urgency around post-quantum readiness, Keyfactor has secured a staggering investment exceeding $1 billion to accelerate its global operations and advance product innovation. The company’s end-to-end platform, known as the Trust Control Plane, provides centralized visibility into cryptographic … Read more

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

A newly disclosed Linux kernel vulnerability has left multi-tenant x86 public clouds vulnerable to a major security threat. Tracked as CVE-2026-53359, the flaw allows attackers to escape virtual machines (VMs) and execute code on the underlying host, posing a significant risk to cloud providers and their customers. The vulnerability, known as Januscape, affects the shadow … Read more

CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to all federal government agencies in the United States: they must patch an extremely critical vulnerability in the Adobe ColdFusion web application development platform by this Friday. The flaw, identified as CVE-2026-48282, is being actively exploited by malicious actors, and CISA has … Read more

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the continued threat posed by software weaknesses in widely used applications such as Adobe, Joomla, and Langflow. This move underscores the urgent need for organizations to prioritize vulnerability patching and risk mitigation. The … Read more

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

A devastating 15-year-old vulnerability, dubbed GhostLock, has been discovered to allow attackers to break free from even the most secure Linux environments, gaining root-level access and compromising entire systems. The flaw affects a staggering majority of Linux distributions in use today, leaving countless organizations vulnerable to exploitation. GhostLock exploits a fundamental weakness in the way … Read more

CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker

Tarah Wheeler’s Unlikely Path to Cybersecurity Leadership Meet Tarah Wheeler, Chief Information Security Officer (CISO) at TPO Group, a leading cybersecurity consultancy firm that serves high-stakes organizations such as critical industries and federal agencies. What sets Wheeler apart is her unconventional journey into the world of cybersecurity, which she describes as an “alleyway” where she … Read more

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Iran-Linked Hackers Unleash Sophisticated Cyberattacks on Israeli Targets A highly skilled and secretive group of hackers linked to Iran’s Ministry of Intelligence and Security (MOIS) has been conducting a series of complex cyberattacks against organizations in Israel. Dubbed “Cavern Manticore” by cybersecurity experts, this advanced persistent threat (APT) actor uses a modular command-and-control framework that … Read more

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A recently patched vulnerability in Adobe ColdFusion has been exploited by threat actors just two hours after its public disclosure. The flaw, tracked as CVE-2026-48282 and carrying a maximum severity rating of CVSS 10/10, allows for arbitrary code execution and was quickly identified by the vulnerability intelligence platform KEVIntel. The security defect is described as … Read more

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has enlisted the powerful AI-driven tool Mythos from Anthropic to scan and audit federal government software for security vulnerabilities. This move is part of a proactive effort to identify and patch potential weaknesses that could be exploited by foreign intelligence agencies or cybercriminals. According to sources familiar … Read more