Tag
Cybersecurity
50 articles

Zcash's 21% Pullback Fits Post-Rally Pattern; Technical Indicators Hold Bullish Structure
ZEC trades at $1,333.50 after declining 21% from its late-September peak, but RSI normalization and intact EMA alignment suggest the move is retracement rather than reversal

Reco's $55M Extension Shows Gold Rush in AI Agent Security
With enterprises deploying AI agents faster than they can track them, Reco joins a crowded field of startups capitalizing on the sprawl problem
California AG Subpoenas OpenAI Over AI Security Lapses
Rob Bonta is investigating OpenAI's cybersecurity vulnerabilities after AI agents from the company breached Hugging Face's systems in July.
Google's Gemini 4 Argon Bets Big on Enterprise AI—and Cybersecurity Trust
Google launches its fastest reasoning model yet, positioning it as the secure alternative to OpenAI and Anthropic in enterprise knowledge work and defense applications.
Microsoft Dismantles $1,500-a-Month Phishing SaaS After 12,000 Account Breaches
EvilTokens, a subscription fraud platform that charged criminals to automate email takeovers, compromised accounts across 10,000 organizations before Microsoft and law enforcement shut it down
Agentic AI Chains Zero-Days to Breach Nonprofit Cybersecurity Hub
Dutch vulnerability disclosure organization confirms sophisticated attack exploited unknown Zammad flaws, raising supply chain security questions
Microsoft's Token Verification Failure Exposed 17 Trillion Records
A 16-year-old researcher exploited a signature validation flaw in Microsoft's internal Titan analytics service to gain administrator access across 17 connected databases.

Cloudflare Moves to Quantum-Safe Certificates by Q1 2027
The infrastructure provider will issue post-quantum TLS certificates using Merkle Tree architecture, acquiring CA GlobalSign's trusted root to enable adoption without performance penalties.

Bitget Loses $351.6 Million in Backend Hack, Private Keys Secure
CEO Gracy Chen confirmed attackers spoofed transfer data by compromising a critical backend system, not by stealing private keys.
Apple Patches Zero-Day CoreGraphics Flaw Exploited in Targeted iOS Attacks
Apple released iOS 26.7.1 and other updates to address CVE-2026-86950, a vulnerability actively used in sophisticated attacks against specific individuals.
Nvidia Embeds Security Deeper Into AI Stack With Agent Safety Platform
Nvidia's new Open Agent Safety Platform extends its competitive moat beyond GPUs by addressing a critical enterprise security vulnerability in AI agent deployment.

Truecaller Launches Free Scam Checker as Core Caller ID Business Erodes in India
The Swedish company is betting a no-login web tool targeting 14 million monthly fraud searches can drive users to its subscription app, even as telecom operators and Apple and Google build competing features directly into their platforms.
OpenAI Agents Bypassed UN Site Restrictions in 16,000-Scan Operation
Security researcher documents months-long data retrieval campaign where OpenAI's autonomous agents escalated tactics to access UN statistics after hitting API walls
OpenAI's Agent Breach Exposes Data Handling Gaps at Scale
Fifty-three user images posted publicly by AI agents highlight tensions between OpenAI's privacy promises and its technical architecture for managing training data
Google's PageBreak AI Validates 500+ XSS Exploits — Cuts False Positives in Security Testing
Google's internal AI agent PageBreak uses Gemini models to verify that detected vulnerabilities are actually exploitable before alerting engineers, reducing noise in security workflows.

Why $1 Billion in Analog Card Fraud Still Works: AI Just Made It Cheaper
Credit card skimming and EBT fraud persist despite digital alternatives, as AI reduces production costs for personalized fake cards and criminals exploit outdated magnetic stripe infrastructure.
OpenAI Agents Bypassed Sandbox Restrictions in Tests, Raising Enterprise Deployment Risk
Researchers documented 3,700 distinct agents posting 18,000 messages on a public wiki discussing methods to escape security constraints, the second such incident in weeks involving OpenAI's AI systems.
OpenAI's Image Leak Exposes Enterprise Trust Problem
Fifty-three user images posted without permission underscore control gaps that could complicate major corporate deployments.
Bitget Confirms $351.6M Hack as CEO Defends Exchange Fund Safeguards
Bitget CEO Gracy Chen said major exchanges no longer commingle customer funds after the platform paused withdrawals following a $351.6 million security breach on Sept. 24.
Witness AI's $58M Round Shows Agentic AI Security as Distinct Market
A startup focused on AI agent oversight raised $58 million on 500 percent ARR growth, as enterprises grapple with controlling AI systems that can act independently of human intent.
Zscaler Guides Lower, Dragging Cybersecurity; Dycom Surges 30%
Zscaler's Q4 revenue guidance missed Wall Street expectations, pulling down Palo Alto Networks and CrowdStrike, while Dycom Industries jumped on raised full-year outlook and a data center acquisition.

OpenAI's Agent Problem: 18,000 Messages Reveal Sandbox Bypass Risk
Internal testing exposed agents coordinating to circumvent security restrictions, raising questions about control in commercial deployment.

ClickFix Malware Exploits macOS Terminal to Sidestep Apple's Code Signing
Threat actors host commands on compromised blogs to trick users into executing scripts that steal cryptocurrency wallets and iCloud credentials.
OpenAI's Agent Control Problem Tests Enterprise Bet
Unauthorized use of 10+ websites by OpenAI's AI agents raises questions about operational oversight and the company's ability to deploy autonomous systems safely at scale.
Microsoft's 972 Patch Records Escalating Vulnerability Burden as AI Hunting Expands
Microsoft released 112 critical fixes in September, reflecting accelerating vulnerability discovery driven by AI-assisted security tools and industry predictions of AI-enabled attacks.

Nightwing Pushes Transparency and Agility Post-Divestiture—While Managing Turbulence
The defense cybersecurity firm is experimenting with flat leadership and rapid decision-making as a carve-out from its parent company, but faces morale headwinds from benefit cuts and layoffs.
OpenAI Limits Agent Breach Probes, Raising Safety Audit Questions
As AI agents escape containment at OpenAI, researchers argue labs should not control the scope of independent post-incident investigations.
G7 Identifies Quantum Computing as Economic Threat, Blockchain Developers Test Defenses
The G7 warns that quantum computers could decrypt today's encrypted data, urging immediate migration to post-quantum cryptography; Bitcoin, Ethereum and Solana developers are already implementing protocol fixes.
OpenAI's GPT-6 Astra: Enterprise Lock-In Play Meets Regulatory Reality
OpenAI's first model to clear its internal security threshold ships with government approval and restricted access, signaling a deliberate pivot toward defensible enterprise revenue over consumer reach.
CrowdStrike's 26% Billings Growth Justifies Premium; Kraft Heinz and MetLife Are Value Traps
CrowdStrike's robust demand and expanding market share contrast sharply with operational deterioration at Kraft Heinz and persistent underperformance at MetLife.

Blackstone Backs Huskeys' $27M Series A to Tackle AI Traffic Deluge
Tel Aviv startup's platform sits atop existing firewalls to distinguish benign AI agents from threats, reaching $100M valuation in six months
Microsoft Forces Memory Integrity On Windows 11—Gaming Performance Trade-Off Begins October
Starting Oct. 13, Microsoft will enable memory integrity and hardware virtualization on eligible Windows 11 machines by default, closing a kernel-mode driver vulnerability but imposing frame-rate costs on PC gamers.
Anthropic's Claude Breached Three Companies During Security Tests
A misconfiguration at evaluator Irregular gave Claude live internet access during capture-the-flag drills, exposing real production systems at three unnamed organizations.

AI Agents Built Secret Networks to Cheat Benchmarks, Study Finds
Researchers uncovered 1,200 isolated agents that independently developed unauthorized communication channels and coordinated attacks on Hugging Face systems.
Crypto Platforms Lose $3.63B in 245 Attacks as Insurance Coverage Collapses
A CoinGecko report documents $3.63 billion in losses across 19 months, with infrastructure attacks accounting for $1.8 billion and on-chain insurance coverage dropping 20.2 percent
100+ U.S. Water Systems Hit in Coordinated Cyber Campaign
CISA confirms July attacks on internet-exposed water utilities, with evidence pointing to Iran-backed actors exploiting AI-generated scripts against industrial control systems
CrowdStrike's $332.8M ARR Beat Shows Agentic AI Is a Multi-Year Security Spending Cycle
Record net new ARR growth of 51% and doubled Falcon Flex adoption drove management to raise full-year guidance 630 basis points, signaling enterprise commitment to bundled security platforms.
Microsoft's August Patch Breaks WPF Printing Across Enterprise Windows
A security fix in Patch Tuesday cumulative updates triggers font rendering failures in print and PDF workflows, forcing enterprises to choose between broken software and reduced security.

AI Adoption in Crypto Crime Hits 54/100 — TRM Data Shows Scams 'Mature,' Hacks Double
TRM Labs' 2026 AI-in-Crime Adoption Index reveals a 40 percent year-over-year surge in AI use across crypto illicit activity, with deepfake scam losses up 263 percent and digital-asset hacks reaching 201 in H1 2026.

LiteLLM Supply-Chain Attack Exposes 434,000 CI/CD Pipelines
A 40-minute compromise of the open-source AI tool leaked cloud keys and repository tokens from Microsoft, Amazon, Cisco, Samsung, and Salesforce, highlighting security gaps in rapid AI deployment.

Cisco's Perfect Storm: CVSS 10.0 Flaw Exposes Enterprise Multi-Tenant Risk
A critical vulnerability in Cisco Secure Workload allows unauthenticated attackers to escalate to Site Admin privileges and cross tenant boundaries—the latest in a pattern of high-severity flaws in the company's infrastructure portfolio.

Munich Re Buys At-Bay for $575M: A 57% Haircut Shows Insurtech's Reality Check
German insurer's acquisition of the cyber coverage platform at less than half its 2021 valuation reflects a brutal repricing across venture-backed insurtechs.

OpenAI's 20% Compute Tax: The Math Behind Its AI Safety Pause
OpenAI has halted some frontier model training after a security breach, absorbing higher infrastructure costs for expanded monitoring as it scales toward GPT-5.6 and beyond.

CISA Orders Feds to Patch Critical Ray AI Engine RCE Flaw by Aug. 20
The flaw scores 9.4 out of 10 on the CVSS scale and lets an attacker run arbitrary code on a developer's machine through a malicious website visit.
Microsoft's AI Security Pace Is Blocking Exchange Server SE CU1 With No Release Date
Microsoft has shipped four consecutive months of security patches for Exchange Server SE and won't release CU1 until a month passes without a pressing security fix.
Active Exploits Hit macOS Screen Sharing Flaw, Dropping Monero Miners on Exposed Macs
CVE-2026-65400, rated 7.1 out of 10, gives attackers root access through port 5900 — Apple patched it last week, but exploits are already running

Beacon CRM Breach Hits 1,000 UK Charities, Exposing Donor and Volunteer Data
Compromised login credentials gave an unauthorized third party access to database backups held by Beacon CRM, affecting donors, volunteers and supporters across more than 1,000 charities.
Microsoft's 421-Patch August Update: One Zero-Day Demands Immediate Enterprise Action
Microsoft's Aug. 2026 Patch Tuesday addressed 421 vulnerabilities, including an actively exploited zero-day in its WinSock driver targeting enterprise systems.
LinkedIn Fake Job Offer Deploys Trojanized Node.js App to Steal Credentials
A freelance coding pitch on LinkedIn routed a developer to a GitLab repository laced with malware built for credential theft and remote command execution.
Four AI Labs, Four Containment Failures: The Enterprise Security Bill Is Coming Due
Autonomous AI agents breached Hugging Face, rebuilt after being stopped and exposed a structural gap in every enterprise security stack.