OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

A recently discovered vulnerability in the OpenSSL library has left many servers vulnerable to a denial-of-service (DoS) attack that can exhaust their memory before any security handshake even takes place. The issue, dubbed “HollowByte,” affects various types of applications and servers that use OpenSSL, including Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, PostgreSQL, and others. … Read more

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Critical SonicWall Zero-Days Exploited for Weeks Before Patch Release Cybersecurity firm Volexity has revealed that two recently patched vulnerabilities in SonicWall appliances were exploited by a threat actor known as UTA0533 for several weeks before patches became available. The flaws, identified as CVE-2026-15409 and CVE-2026-15410, allowed remote attackers to gain unauthorized access to SMA1000 secure … Read more

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

American-Israeli cybersecurity startup Neo emerges from stealth mode with $100 million in funding to control and secure enterprise AI software. The company’s platform enables security operations teams to govern and monitor AI agents, applications, and traditional software across their environments. Neo’s platform serves as a control layer that provides real-time attribution mechanisms, allowing teams to … Read more

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

A New Era in AI Security: Neo Emerges from Stealth with $100M to Control Enterprise AI Software In a significant move, American-Israeli cybersecurity startup Neo has emerged from stealth mode with a whopping $100 million in funding to develop and deploy its cutting-edge platform for controlling and securing enterprise AI software. The company’s seed and … Read more

Cybersecurity Keeps Events ‘Uneventful’

This year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. From the World Cup to the United States’ 250th celebration, major events have become prime targets for a range of threats, from physical attacks on attendees to cyber breaches targeting sensitive information. The truth is … Read more

Attackers Combo Up Evasion Tactics for BEC Phishing

Attackers are combining multiple evasion tactics to deliver Business Email Compromise (BEC) phishing attacks with a high degree of success. This campaign, dubbed “The TFF Trap,” has been observed by researchers at Fortinet since late March and involves the use of disguised font files, Lua interpreters, and in-memory execution to bypass endpoint defenses. At its … Read more

Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push

As cybersecurity teams struggle to keep pace with the ever-evolving landscape of threats, one software vendor is exploring an innovative approach to vulnerability remediation: leveraging large-language models (LLMs) to identify and fix flaws in their products. Ivanti’s chief security officer, Daniel Spicer, recently shared insights into the company’s project, which has already yielded surprising results. … Read more

‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover

A devastating cybersecurity threat has emerged in the form of “WP2Shell”, an exploit chain that allows attackers to take control of millions of WordPress sites worldwide. Barely three days after the vulnerabilities were disclosed, malicious actors are already chaining together two critical flaws – CVE-2026-60137 and CVE-2026-63030 – to launch large-scale attacks against some of … Read more

Cybersecurity Keeps Events ‘Uneventful’

This year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. From the World Cup to the United States’ 250th celebration, event organizers and security teams have had their work cut out for them. But what happens when threats surrounding major events begin long before anyone … Read more

CISOs Feel the Heat Over AI Risk

Cybersecurity Executives Feel the Heat as AI Adoption Accelerates The rapid adoption of artificial intelligence (AI) technologies has brought a perfect storm to cybersecurity executives, with 26% considering leaving their jobs due to increased stress and pressure. This alarming statistic comes from a recent column by Splunk’s field chief information security officer (CISO), Kirsty Paine, … Read more