Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

A newly discovered flaw in Shark’s vacuum cleaner software could potentially allow attackers to take control of other connected devices in the region, highlighting the growing threat of IoT vulnerabilities and the need for timely patching. The issue, which affects Shark’s ION series of vacuums, was uncovered by a researcher who used an AI-powered tool … Read more

AI Can Find Bugs, But Human Knowledge Still Proves Them

As artificial intelligence (AI) models become increasingly adept at discovering software vulnerabilities, many organizations are left wondering what this means for their security posture. The latest development comes from researchers who have demonstrated that AI can identify flaws in code with remarkable accuracy – but human expertise is still essential to verify and validate these … Read more

Old UEFI Shims Expose Systems to Secure Boot Bypass

Old UEFI Shims Left Systems Vulnerable to Secure Boot Bypass Attacks A disturbing discovery has been made in the world of cybersecurity, as a nearly decade-old vulnerability has been unearthed that allows attackers to bypass Secure Boot protections on systems. A group of old Unified Extensible Firmware Interface (UEFI) shim bootloaders, signed by Microsoft and … Read more

China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

Chinese Cybersecurity Firms Face Military Procurement Bans Amid Shift in PLA Oversight A new report by threat intelligence group Natto Thoughts has revealed that China’s military procurement system has taken a hard stance against several top cybersecurity vendors, suspending or permanently banning them from future contracts. At least 21 enforcement actions have been tied to … Read more

Police Disrupt a €140M Cyber Fraud Ring in Spain

Spanish Police Disrupt $161 Million Cyber Fraud Ring with Global Reach A massive cybercrime operation in Spain has been dismantled by law enforcement, resulting in the freezing of €3 million in stolen funds and the arrest of four key suspects. The gang, which had been operating for some time, used a range of sophisticated tactics … Read more

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

A New Era of Automated Vulnerability Discovery: OpenAI’s GPT-Red Puts Pressure on Security Teams In a significant development, OpenAI has unveiled its latest AI-powered tool, GPT-Red, designed to automate prompt injection testing and help fortify its cutting-edge language model, GPT-5.6 Sol. This innovative approach not only underscores the growing reliance on artificial intelligence in cybersecurity … Read more

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Windows Bind Link Attacks Expose Security Gaps in EDR Tools A recent study by Bitdefender has uncovered three attack techniques that exploit Windows’ bind links to evade detection by endpoint detection and response (EDR) products. These vulnerabilities highlight a significant security weakness, as they allow attackers to load hidden malware without triggering alarms on the … Read more

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

Four major cybersecurity companies have released patches this month to fix severe vulnerabilities in their products, leaving users vulnerable to potential attacks. Tenable, a leading provider of vulnerability management solutions, has patched a critical-severity path traversal vulnerability in its Tenable Agent. This flaw, identified as CVE-2026-15265, could allow an attacker to gain remote code execution … Read more

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

A notorious security researcher has struck again, releasing a zero-day exploit that allows attackers to escalate privileges on Windows systems. Nightmare Eclipse, also known as Chaotic Eclipse, has dropped yet another unpatched vulnerability in Microsoft’s products, this time targeting the Windows User Profile Service. The fresh exploit, dubbed LegacyHive, enables an attacker to load other … Read more