‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. Read More
Multistate Water System Attacks Widen, Iran Suspected

Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs. Read More
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users. Read More
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

It’s time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets. Read More
Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups. Read More
Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research. Read More
Sherlock Holmes Was the ‘OG’ Social Engineer

The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and unethical hackers. Read More