New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

Cloud Tenants Unleash New Bit2Watt Attack, Threatening Power Grids Worldwide A shocking discovery has left cybersecurity experts and power grid operators on high alert as researchers revealed a novel attack method that could allow cloud tenants to disrupt entire power grids without exploiting any vulnerabilities in the underlying software. Dubbed “Bit2Watt,” this sophisticated technique leverages … Read more

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google’s latest innovation, Gemini 3.5 Flash Cyber AI, is shaking up the cybersecurity landscape with its groundbreaking approach to identifying and fixing software vulnerabilities. This cutting-edge technology uses artificial intelligence (AI) to scan code and pinpoint weaknesses that could be exploited by hackers. What makes this tool so significant is its ability to not only … Read more

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Amazon Web Services (AWS) users are facing a potentially devastating security flaw that could allow attackers to rewrite configuration files and execute malicious code on their accounts. The vulnerability, dubbed “Kiro,” resides in AWS’s Config service, which is designed to monitor and audit resources within an organization’s cloud infrastructure. The Kiro flaw works by exploiting … Read more

N-day is Becoming N-Hour. Patching Faster Won’t Save You.

As AI-powered vulnerability discovery tools continue to accelerate, software vendors are struggling to keep pace with the rapid identification of new security flaws. The notion of “N-day” – a term used to describe the time between a vulnerability’s discovery and its public disclosure – is being rendered obsolete by the emergence of AI-driven threat detection. … Read more

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Hackers Can Hide Malicious Code in Android AI Agents, Putting Host PCs at Risk A newly discovered vulnerability in open-source Android AI agents has raised alarm bells for security experts and ordinary users alike. This issue allows malicious actors to hide code within seemingly innocuous text on an Android device’s screen, which can then execute … Read more

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Critical Security Flaw Found in Zimbra Collaboration Suite, Patches Issued for Immediate Update A severe security vulnerability affecting millions of users worldwide has been discovered in the popular open-source collaboration software Zimbra. The flaw, identified as a critical SNMP command injection bug, has been patched by the developers, and immediate update is strongly advised to … Read more

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

A Critical PAN-OS Flaw Exposes Organizations to Qilin Ransomware Attacks Qilin ransomware attackers have exploited a previously unknown vulnerability in Palo Alto Networks’ (PAN) PAN-OS operating system, allowing them to bypass authentication and gain initial access to compromised networks. This devastating flaw has already been leveraged by threat actors to wreak havoc on multiple organizations … Read more

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Cybersecurity researchers have confirmed that a critical remote code execution (RCE) vulnerability, CVE-2026-50522, affecting Microsoft SharePoint is being actively exploited by attackers. This zero-day exploit allows unauthenticated hackers to inject malicious code on vulnerable servers, giving them control over sensitive data and potentially leading to further compromise of the network. The vulnerability affects all versions … Read more

N-day is Becoming N-Hour. Patching Faster Won’t Save You.

Cybersecurity’s ticking time bomb is getting closer to detonation, with the alarming trend of N-day vulnerabilities being discovered and exploited at an increasingly rapid pace. The once-quaint notion of patching software flaws within a day or two has become a relic of the past, as AI-powered vulnerability discovery tools are reducing the window of opportunity … Read more

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

A newly discovered vulnerability in open-source Android AI agents has exposed a significant security risk, allowing malicious actors to inject invisible text on victims’ screens that can execute code on their host PCs. This sneaky tactic, known as “invisible screen text injection,” exploits the AI-powered chatbot’s ability to recognize and respond to user input, turning … Read more