Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or expose information through model behavior.
The program covers qualifying...
A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially gain root-level control.
Tracked as CVE-2026-43502, the flaw was demonstrated through an exploit called ZcopyReaper by security researchers at NebuSec. This vulnerability affects the Reliable...
This week's roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven cyberattacks, browser and firewall...
Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a fraudulent request that appeared to originate from a legitimate government agency. Here is the detailed breach report and the...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
The issue affects GitLab Community Edition and Enterprise Edition...
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and attempted to harvest developers’ API keys through a then-undisclosed...
Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8.
Administrators who can reproduce the failure say certificate-based tunnels that worked immediately before the...
Anthropic's Threat Intelligence team has disclosed a sweeping new report detailing how state-sponsored espionage groups, financially motivated cybercriminals, and lone hacktivists weaponized its Claude AI models to automate entire cyberattack chains, generate zero-day exploits, and dynamically rewrite malware to...
WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had previously lacked one.
The move follows a real-world incident...
Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.
Check Point's own research team uncovered...