Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an…
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an…
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a…
Ravie LakshmananSep 18, 2026Mobile Security / Malware Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat…
Capita CEO Adolfo Hernandez earned £1.6m in his last pay packet, while thousands of retired civil servants were forced to apply for emergency loans because…
The British government’s refusal to confirm whether it has issued an order to bypass encryption to access customer data held by Apple has become farcical, a…
A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month. Conductor is an…
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution Pierluigi Paganini September 18, 2026 Check Point fixed CVE-2026-91843, a critical flaw that could let attackers…
As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models…
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can…
Recorded Future was just named a Leader in The Forrester Wave: External Threat Intelligence Service Providers, Q3 2026. We’re incredibly proud of this acknowledgment, just…
Key Takeaways Periodic audits provide a point-in-time assessment, but they cannot demonstrate whether controls remain effective between audit cycles. Qualys platform data shows 10.5 billion…
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on…