OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI’s Latest GPT Model Sparks Concerns Over Reduced Safeguards for Exploit Development A new version of OpenAI’s large language model, designed for exploit development and penetration testing, has been launched with significantly reduced safeguards. The move has raised eyebrows among security experts, who warn that the increased accessibility of this powerful tool could embolden malicious … Read more

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla Updates GPG Signing Key After Accidental Exposure, Low Risk of Malicious Activity A recent security incident has prompted Mozilla to update the GPG signing key used for Firefox and Thunderbird releases. The company had inadvertently exposed an unencrypted copy of the previous subkey on a private GitHub repository, sparking concerns about potential supply chain … Read more

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

A fake cryptocurrency startup, dubbed “CryptoLux,” has been used as a front to lure and hire suspected North Korean IT workers, who were then exploited for their skills in malicious activities. This brazen scheme highlights the growing threat of state-sponsored cybercrime and the ease with which attackers can manipulate legitimate-looking ventures to further their nefarious … Read more

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A recently disclosed vulnerability in cellular IoT devices has revealed a shocking truth: malicious SIM cards can secretly run attacker code inside the modems that power these devices. This means that hackers can gain control over the very foundation of IoT networks, exploiting vulnerabilities that could have far-reaching consequences for individuals and organizations alike. The … Read more

Cisco warns of high-severity ClamAV flaws with public exploits

A pair of high-severity vulnerabilities affecting ClamAV, a widely-used open-source antivirus engine, have been disclosed by Cisco. The flaws, which were found in the ZIP archive parser, can be exploited to crash the scanning process and deny service (DoS) attacks, and proof-of-concept exploit code is already publicly available. The two vulnerabilities, tracked as CVE-2026-20337 and … Read more

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

A devastating wave of ransomware attacks is sweeping across the globe, targeting organizations with a previously unknown exploit that leverages vulnerabilities in Fortinet and Schneider Electric security products. Gunra Ransomware, a highly aggressive malware strain, has successfully breached networks of multiple companies, leaving a trail of destruction and financial loss in its wake. At the … Read more

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Cybersecurity experts have sounded the alarm about a new threat vector that leverages malicious MCP servers to compromise sensitive information. The attack involves splitting instructions on these servers to make AI coding agents exfiltrate secrets, posing a significant risk to organizations and individuals with sensitive data. What’s most concerning is that this vulnerability can be … Read more