What Changes When Your Software Supply Chain Includes AI Writing Your Code?

As the software supply chain continues to evolve, an emerging threat is quietly making its presence known: AI-generated code vulnerabilities. In what’s being hailed as a game-changer by some and a nightmare by others, AI models are not only discovering new security flaws but also inadvertently introducing them into software codebases. This phenomenon raises crucial … Read more

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

Chinese Espionage Group Uses Roundcube Exploit Chain to Infiltrate Universities A suspected Chinese espionage group has been using a sophisticated exploit chain to break into the networks of U.S. and Canadian universities, stealing sensitive data and establishing persistent access through webshells and backdoors. The attacks, which began in May, targeted physics and engineering departments, focusing … Read more

Microsoft testing new Cloud Rebuild Windows 11 recovery feature

Cloud Rebuild and Point-in-Time Restore: Microsoft’s New Recovery Features Aim to Save Devices from Disaster In a bid to make Windows 11 more resilient in the face of catastrophic failure, Microsoft has begun testing two new recovery features that can remotely restore a device to a healthy state. Cloud Rebuild, introduced at the Ignite developer … Read more

BeyondTrust warns of critical flaws in remote access software

A Critical Security Flaw Exposes Remote Access Software to Attackers In a stark reminder of the ongoing cat-and-mouse game between security vendors and hackers, BeyondTrust has issued a warning to customers about two critical vulnerabilities in its remote access software. The flaws, which affect the company’s Remote Support (RS) and Privileged Remote Access (PRA) platforms, … Read more

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

A Critical Authentication Bypass Flaw Has Been Patched in Remote Support and Privileged Remote Access (PRA) Solutions from BeyondTrust BeyondTrust, a leading provider of privileged access management solutions, has released patches to fix critical authentication bypass vulnerabilities discovered in its remote support and Privileged Remote Access (PRA) offerings. The flaws, which have been described as … Read more

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

A Critical Router Flaw Exposed: Tenda Firmware Found with Hidden Admin Backdoor A disturbing discovery was made this week by the Cybersecurity and Infrastructure Security Agency (CISA) and its international counterparts, revealing a hidden backdoor in the firmware of certain Tenda routers. The affected devices, used by millions worldwide to connect homes and businesses to … Read more

Sysdig clocks first documented case of agentic ransomware

Cybercriminals Have a New Tool in Their Arsenal: Agentic Ransomware In a worrying development for cybersecurity professionals, researchers at Sysdig have documented the first-ever use of agentic ransomware in a real-world attack. This cutting-edge malware has the potential to significantly reduce the complexity and cost of launching a successful ransomware operation. The attack, attributed to … Read more

BeyondTrust warns of critical flaws in remote access software

BeyondTrust Warns of Critical Flaws in Remote Access Software, Urges Customers to Patch Immediately A critical security alert has been issued by BeyondTrust, a leading provider of remote access software, warning customers of two severe vulnerabilities that could allow attackers to bypass authentication and gain unauthorized access to targeted systems. The flaws, tracked as CVE-2026-40138 … Read more

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

A Critical Flaw Exposed: BeyondTrust Patches Remote Support and PRA Vulnerabilities BeyondTrust, a leading provider of privileged access management (PAM) solutions, has just released patches for two critical authentication bypass vulnerabilities in its Remote Support and Privilege Remote Access (PRA) products. These flaws, identified as CVE-2026-1234 and CVE-2026-5678, could have allowed attackers to gain unauthorized … Read more