Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

Microsoft: AI Will Make Patch Tuesday Permanently More Demanding
Microsoft EVP Pavan Davuluri confirmed on July 9, 2026 that AI will permanently increase the volume of security updates in each Patch…

AI-Generated Malware Maps Active Directory: How It Was Caught
On June 3, 2026, Huntress detected an attack using an AI-generated PowerShell script created via vibe coding. Behavioral detection suc…

Microsoft Patches RoguePlanet: When the Antivirus Becomes the Attack Surface
CVE-2026-50656 enables privilege escalation to SYSTEM via the Microsoft Defender engine. The fix arrives through an automatic engine u…

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered
A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Verified X Ads Spread Mac Malware and Steal Microsoft 365 Accounts
Active campaigns exploit X's blue verification badge to distribute Mac malware via ClickFix and steal Microsoft 365 OAuth tokens using…

FortiBleed: 74,000 FortiGates Exposed — Patching Alone Won't Fix It
CISA estimates 74,000 Fortinet devices have compromised credentials. The FortiBleed campaign exploits credential reuse and brute-force…

Qualys Unveils Risk Operations Center for the 'Day Minus Seven' Era
Qualys published a product-tech blog post on July 8, 2026 introducing the Risk Operations Center (ROC) as an operational response to w…

CISA Orders 3-Day Patch for CVE-2026-55255 in Langflow
An IDOR in Langflow's /api/v1/responses endpoint lets authenticated attackers steal LLM and cloud credentials from other users' flows.…

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed
ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…

IRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup
IRIS C2, a McLean, Virginia startup offering up to $7 million for zero-day vulnerabilities, is operated by Jacob Wohl and Jack Burkman…

KDDI: Zero-Day in Third-Party Software Exposes 12,233,087 Email Addresses
KDDI confirmed a zero-day attack in third-party software compromised the shared email platform of five Japanese ISPs, exposing over 12…