CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

US Cybersecurity Agency Warns of Active Attacks on TrueConf Video Conferencing Platform The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies, urging them to immediately patch two critical vulnerabilities in the popular video conferencing platform, TrueConf. The agency has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) … Read more

Microsoft Patches Exploited Entra ID Vulnerability

Microsoft has just rolled out a batch of 22 critical security updates to patch severe vulnerabilities in multiple products. Among these patches is one that addresses a zero-day exploit in its Entra ID service, which was being actively targeted by attackers. The exploited vulnerability, tracked as CVE-2026-69836, had the potential for remote code execution (RCE), … Read more

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Cybersecurity Compliance Confidence Soars Among Defense Contractors, but Can They Back It Up? The defense industry is breathing a collective sigh of relief as contractors express increased confidence in their cybersecurity compliance. However, a closer look at two recent surveys reveals a concerning disconnect between confidence and actual readiness. According to a survey by Kiteworks, … Read more

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

A Growing Divide Between Defense Contractors’ Confidence and Reality Two recent surveys paint a concerning picture for defense contractors: while they claim to be more confident than ever in their cybersecurity compliance, their ability to prove it is lagging behind. This disconnect has significant implications for both individual companies and the broader national security landscape. … Read more

Rust Supply Chain Attack Linked to North Korean Hackers

North Korean hackers have launched a sophisticated supply chain attack on the Rust programming language ecosystem, compromising one of its most popular packages and potentially putting millions of users at risk. The attack, which occurred on August 20, involved a malicious version of the arrayref crate being pushed to crates.io from a legitimate maintainer’s account. … Read more

Critical Isolated-vm Vulnerability Leads to RCE on Host

Critical Isolated-vm Vulnerability Exposes Host Systems to Remote Code Execution Attacks A severe security flaw in a popular Node.js library has left developers scrambling to patch their applications and protect against potential remote code execution (RCE) attacks. The isolated-vm library, used by many organizations to execute untrusted JavaScript code within a sandboxed environment, contains a … Read more

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

A New Phishing Toolkit Emerges, Using Passkeys to Bypass Password Resets Cybersecurity researchers have uncovered a sophisticated new phishing toolkit that uses passkeys to maintain access to compromised accounts even after password resets. iAuthFlow V2, a malware toolkit available on Russian-language cybercrime forums for $10,000, has been analyzed by Abnormal researchers, who have revealed its … Read more

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

**New Attack Technique Exploits Flaw in AI Safety Guardrails, Raises Concerns Over Data Protection** A disturbing discovery by researchers at Adversa AI has shed light on a novel attack technique that bypasses safety guardrails in popular AI-powered chat platforms. Dubbed “Cryptographic Context Injection,” this tactic allows malicious actors to inject encrypted prompts into AI models, … Read more

Rust Supply Chain Attack Linked to North Korean Hackers

North Korean Hackers Strike at Rust Ecosystem with Sophisticated Supply Chain Attack In a brazen and well-planned attack, North Korean hackers have compromised one of the most popular open source software (OSS) projects in the world. The target was the Rust ecosystem, specifically the arrayref crate, an essential utility for converting arrays that has been … Read more

Critical Isolated-vm Vulnerability Leads to RCE on Host

A Critical Isolated-vm Vulnerability Has Been Discovered, Allowing Attackers to Take Control of Host Systems In a worrying development that highlights the ongoing cat-and-mouse game between security researchers and threat actors, a critical vulnerability has been discovered in isolated-vm, a popular Node.js library used by developers worldwide. The bug, which affects ExternalCopy, a function responsible … Read more