AI Scramble Drives Cybersecurity M&A Boom

Cybersecurity M&A Boom Driven by AI-Driven Deals A record-breaking number of cybersecurity deals has been announced this year, with 117 transactions in just one quarter alone. What’s behind this surge? The answer lies in the rapidly growing demand for native-AI cybersecurity services and the security capabilities needed to tame agentic AI. This trend is not … Read more

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A massive data breach at British retail giant ASOS has laid bare a critical vulnerability in customer-facing Software as a Service (SaaS) platforms. The attack, perpetrated by a group calling itself Xuanye Group, compromised sensitive information belonging to over 17 million customers and demonstrated the ease with which a single stolen login can grant access … Read more

Microsoft: Outdated Windows devices will stop receiving security updates

Microsoft has announced that devices running outdated versions of Windows will no longer receive critical security updates after next year’s Windows Update certificate rotation. This means that any device still using an unsupported version of Windows will be left vulnerable to cyber threats, without access to essential security patches and updates. The affected systems are … Read more

FBI Arrests Founder of Ransomware Negotiation Firm

The founder of a Canadian cybersecurity firm has been arrested by the FBI on suspicion of assisting the notorious ShinyHunters hacking group, which has made headlines for its brazen theft of sensitive data from thousands of law enforcement agents. The arrest is the latest development in an ongoing investigation that has seen the group extort … Read more

Max severity SonicWall SMA1000 flaw now exploited in attacks

A critical vulnerability in SonicWall’s secure remote access gateways has been exploited in real-world attacks just days after a patch was released. The flaw, tracked as CVE-2026-102255, affects specific models of the SMA1000 appliance and allows an attacker to take control of the device without authentication. The affected devices are the SMA1000 6210, 7210, and … Read more

How to keep AI agents within their permissions

A Critical Issue in AI Agent Management: Preventing Unauthorized Access As AI agents become increasingly ubiquitous in corporate environments, their ability to perform complex tasks with minimal human oversight is a double-edged sword. While agents can indeed be more efficient than humans in many situations, they also require careful management to prevent unauthorized access and … Read more

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Cyberattackers have been exploiting a vulnerability in Google’s advertising system, using Bing search-result redirects as click URLs to direct unsuspecting users to fake download pages for the popular AI tool, Claude. The technique, dubbed “Adception” by security researchers at Push Security, is designed to evade security checks and deceive even the most vigilant visitors. The … Read more

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Credential-Stealing GitHub Actions Workflows Found in Tens of Thousands of Repositories, Threatening Developer Security A shocking discovery has left cybersecurity experts reeling as tens of thousands of GitHub repositories have been found to contain malicious workflows that can steal sensitive credentials. The threat, which affects a staggering number of developers worldwide, is particularly concerning given … Read more