FBI cyber leaders warn that companies still hesitate to report nation-state breaches, debunking myths about regulator sharing and touting a victim-first strategy.
SpyCloud's 2026 Identity Exposure Report finds exposed API keys, tokens and AI credentials driving a surge in attacks via non-human identities across enterprises.
CISA, NSA and FBI say China-based AI firms are running industrial-scale knowledge distillation campaigns to siphon capabilities from U.S. frontier models.[1][2]
Tencent patches WeChat WeWorm zero-click worm that hijacked accounts via VoIP calls, highlighting AI-driven exploit development and massive messaging risk.[1][2][6]
Microsoft’s September 2026 Patch Tuesday breaks records with fixes for 974 CVEs, including two zero-days already exploited and dozens more likely targets.
CloudSEK uncovered BigBear 2.0, an Evilginx2 phishing-as-a-service stealing MFA-backed Microsoft 365 sessions and exposing global enterprises to BEC risk.
Gamers Nexus research alleges LG smart TVs record audio, scan home networks and feed data into LG Ads Solutions, raising questions on consent and surveillance.
A critical CVE-2026-32475 file upload bug in Elementor Pro exposes WordPress sites to unauthenticated remote code execution, with fixes in version 4.2.2.