Windows LegacyHive zero-day flaw gets free, unofficial patches

A recently disclosed Windows zero-day flaw has been patched by a cybersecurity company, even though Microsoft hasn’t yet released an official fix. The vulnerability, dubbed LegacyHive, allows attackers to escalate privileges on up-to-date Windows systems and gain automatic code execution when an admin account logs in. The issue was found by a security researcher using … Read more

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

A Critical Flaw in ServiceNow’s AI Platform Exposes Users to Unauthenticated Code Execution Risks, Leaving Organizations Scrambling to Secure Their Networks ServiceNow, a leading provider of cloud-based IT service management platforms, has recently disclosed a critical vulnerability in its AI-powered platform that allows attackers to execute arbitrary code without authentication. The flaw, discovered by researchers … Read more

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

A new strain of ransomware, dubbed ENCFORGE, has been discovered targeting artificial intelligence (AI) model files through a vulnerability in Langflow, a popular video editing software. This attack highlights the increasing sophistication of cyber threats and the need for organizations to prioritize AI-powered security measures. ENCFORGE leverages a remote code execution (RCE) flaw in Langflow, … Read more

Ernst & Young Data Breach Affects Personal, Financial Information

Ernst & Young Data Breach Exposes Sensitive Client Information Professional services giant Ernst & Young (EY) has been forced to notify its clients that their personal and financial information was compromised in a data breach. The incident, which occurred in late March and early April, exposed sensitive details including names, addresses, Social Security numbers, account … Read more

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

A recently discovered vulnerability in the OpenSSL library has left many servers vulnerable to a denial-of-service (DoS) attack that can exhaust their memory before any security handshake even takes place. The issue, dubbed “HollowByte,” affects various types of applications and servers that use OpenSSL, including Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, PostgreSQL, and others. … Read more

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Critical SonicWall Zero-Days Exploited for Weeks Before Patch Release Cybersecurity firm Volexity has revealed that two recently patched vulnerabilities in SonicWall appliances were exploited by a threat actor known as UTA0533 for several weeks before patches became available. The flaws, identified as CVE-2026-15409 and CVE-2026-15410, allowed remote attackers to gain unauthorized access to SMA1000 secure … Read more

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

American-Israeli cybersecurity startup Neo emerges from stealth mode with $100 million in funding to control and secure enterprise AI software. The company’s platform enables security operations teams to govern and monitor AI agents, applications, and traditional software across their environments. Neo’s platform serves as a control layer that provides real-time attribution mechanisms, allowing teams to … Read more

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

A New Era in AI Security: Neo Emerges from Stealth with $100M to Control Enterprise AI Software In a significant move, American-Israeli cybersecurity startup Neo has emerged from stealth mode with a whopping $100 million in funding to develop and deploy its cutting-edge platform for controlling and securing enterprise AI software. The company’s seed and … Read more

Cybersecurity Keeps Events ‘Uneventful’

This year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. From the World Cup to the United States’ 250th celebration, major events have become prime targets for a range of threats, from physical attacks on attendees to cyber breaches targeting sensitive information. The truth is … Read more