Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear

The White House’s Gold Eagle initiative aims to bridge a critical gap in vulnerability coordination, but questions remain about its implementation. Launched on July 14, Gold Eagle is a collaboration layer designed to help organizations respond to software vulnerabilities more efficiently in an era where large language models (LLMs) like Anthropic’s Claude Mythos are changing … Read more

The Real AI Threat Is Blind Trust

A recent attack involving an autonomous AI agent has exposed a growing enterprise risk that many organizations are not prepared for: AI systems capable of transforming untrusted input into authorized action. In this incident, attackers manipulated one AI agent to generate a legitimate-sounding instruction for another AI system authorized to move funds. The second agent … Read more

Inc Ransomware Exploits SonicWall SMA Zero-Days

Cybersecurity experts are sounding the alarm after a major ransomware group exploited two previously unknown vulnerabilities in SonicWall’s Secure Mobile Access (SMA) appliances. The zero-day attacks have already compromised multiple enterprise networks, highlighting the critical need for prompt action to secure these devices. The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, allow attackers to gain root-level … Read more

New Windows LegacyHive zero-day gives hackers admin privileges

A New Windows Zero-Day Exploit Threatens Admin Privileges: What You Need to Know A critical security vulnerability has been discovered in Windows systems, allowing attackers to gain admin privileges and potentially wreak havoc on a compromised machine. The exploit, dubbed LegacyHive, was revealed by a security researcher known as Nightmare Eclipse just hours after Microsoft … Read more

Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear

The White House’s Gold Eagle Initiative Aims to Plug Security Gaps, but Implementation Details Remain Murky A new initiative launched by the White House has sparked both excitement and confusion in the cybersecurity community. The Gold Eagle clearinghouse, designed to coordinate vulnerability response in a world where large language models (LLMs) like Anthropic’s Claude Mythos … Read more

Inc Ransomware Exploits SonicWall SMA Zero-Days

A Major Ransomware Group Exploits Critical Vulnerabilities in SonicWall Appliances In a disturbing development, hackers from the notorious Inc ransomware-as-a-service group have been exploiting two zero-day vulnerabilities in SonicWall’s Secure Mobile Access (SMA) appliances. The security flaws, CVE-2026-15409 and CVE-2026-15410, allow attackers to gain root-level access to these devices, putting millions of users at risk. … Read more

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories, a leading healthcare company, is investigating two separate cybersecurity incidents that have raised concerns about data breaches and extortion attempts. The company confirmed that unauthorized access was made to internal systems in its Cancer Diagnostics business, while also probing a second incident involving its LabCentral customer portal. At the center of the first … Read more

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A critical vulnerability has been discovered in WordPress core, allowing unauthenticated attackers to run arbitrary code on compromised sites. The flaw, identified as wp2shell, can be exploited without requiring any user credentials or authentication. This means that even if you have a secure password and up-to-date plugins, your site remains vulnerable to attack. The vulnerability … Read more

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

OpenSSL Servers Hit by Critical DoS Flaw, Leaving Them Permanently Bloated with Memory A severe denial-of-service (DoS) vulnerability has been discovered in OpenSSL, a widely-used library for secure internet communication. Dubbed HollowByte, this flaw allows unauthenticated attackers to trigger a condition that leaves affected servers permanently bloated with memory, rendering them unable to function. The … Read more