Why “Shady AI” is Security’s Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who…
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who…
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the…
Ravie LakshmananAug 20, 2026Vulnerability / Email Security A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to…
Ravie LakshmananAug 20, 2026Network Security / Enterprise Security Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including…
Ravie LakshmananAug 20, 2026Vulnerability / Application Security Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900…
Adversa AI has disclosed an attack technique that it says can cause xAI’s Grok chatbot to send a user’s name, approximate location, subscription tier, and…
Ravie LakshmananAug 22, 2026Privacy / Regulation The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a…
Ravie LakshmananAug 21, 2026Vulnerability / Threat Intelligence Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the…
Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of…
Ravie LakshmananAug 21, 2026Malware / Automotive Security Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware…
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an…
Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations…