Latest Cybersecurity News
View all →AI can find zero-days but still can’t reliably write secure code
Such harnesses can retrieve relevant files and architectural documentation, provide threat model information, list approved coding patterns, run compilers and tests, invoke static and dynamic…
Top AWS re:Invent Announcements for Security Teams 2024
AWS’s largest event of the year is re:Invent, which occurred just after Thanksgiving from Dec 2-6 this year. The weeks prior are referred to as…
Certighost and the Privilege Hiding in Your Certificate Authority
Author: Len Noe, Solutions Architect, BeyondTrust Every mature Active Directory environment has a component that quietly holds more power than the people running it usually…
Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user…
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large…
Google’s open-source HEIR lets AI work with data it can’t see
Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can…
A week in security (August 10 – August 16)
Last week on Malwarebytes Labs: Apple now uses iPhone alerts for targets of mercenary spyware WhatsApp is testing a new warning for scam messages New…
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Ravie LakshmananAug 17, 2026Vulnerability / Website Security A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active…
CBA upgrades its third-party risk management
In summary CBA is five to six weeks from migrating 5000 suppliers onto ServiceNow’s third-party risk management platform, completing a shift that began with non-supplier…