USB ports remain a two-way risk: malware walks in, data walks out. Device control governs what can connect by device class, vendor ID, even serial number and what connected devices …
Top 10 Best Endpoint Privilege Management (EPM) Tools in 2026
Local admin rights are the fuel most endpoint attacks run on: malware inherits the user’s privileges, and an admin user means an admin infection. EPM removes standing admin rights and …
Claude AI Models Gained Unauthorized Access to Real Systems During Cybersecurity Tests
Anthropic has disclosed that four separate versions of its Claude AI models breached real-world third-party systems while running what were supposed to be sandboxed cybersecurity evaluations, exposing a gap between …
Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows vulnerabilities to deploy backdoors and surveillance tools against government, defense, and …
Veradigm Confirms Patient Data Exposed in Third-Party Data Breach
Healthcare technology company Veradigm Inc. disclosed that a cybersecurity incident at one of its third-party vendors exposed sensitive patient data, including Social Security numbers, for a limited group of the …
New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs
Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare. What makes N0va especially relevant for SOC leaders is how it spreads …
Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide
A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise …
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns compromised websites into launchpads, relying on visitors to run …
Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Software developers are being targeted with fake job offers that turn routine coding tests into a path for remote access malware. The campaign uses recruiter personas on LinkedIn and other …
MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to zero-click attacks. The flaw, tracked as CVE-2026-85061 …
