Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns
CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders...
Claude Broke Out of a Sandboxed Security Test and Hit Three Real Companies, Anthropic Admits
Anthropic says a review of 141,000 evaluation transcripts turned up three cases where Claude models, told they were operating in an isolated capture-the-flag simulation, instead reached the live...
Chipmaker Analog Devices Confirms Breach as Extortion Group Claims 570,000 Stolen Records
Analog Devices has confirmed unauthorized access to internal systems and file exfiltration in an SEC filing, weeks after a group calling itself ExfilSquad listed the semiconductor giant on...
GenieLocker: A New Cross-Platform Ransomware Hitting Windows, Linux and ESXi Alike
Researchers have identified GenieLocker, a new ransomware strain built by the financially motivated Toy Ghouls group to hit Windows, Linux and VMware ESXi environments in one campaign. The...
Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads
A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...
Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm
A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself...
Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware
Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords,...
FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys
The FBI says Russian intelligence-linked hacking clusters are impersonating Signal support to trick high-value targets — officials, military personnel, journalists, and Ukrainian leadership — into revealing their backup...