Cybersecurity
204 articles RSS
Chrome and Firefox Retire DigiCert's G1 Root Certificates, Closing the Book on a Two-Decade-Old WebPKI Anchor
On April 15, 2026, Mozilla and Google removed DigiCert's legacy G1 root certificates from their trust stores, forcing holdouts on legacy chains to reissue TLS certificates or face untrusted errors.
Cisco Patches Four Critical Flaws in Identity Services Engine and Webex, Including a 9.8-Severity SSO Bypass
Cisco discloses four critical vulnerabilities across ISE and Webex, with the most severe allowing unauthenticated attackers to impersonate any user via a broken SSO certificate check.
NIST Abandons Universal CVE Enrichment, Shifting the National Vulnerability Database to Risk-Based Triage as Submissions Surge 263 Percent
NIST will now enrich only CVEs meeting federal priority criteria, leaving thousands of vulnerabilities without severity scores as AI-driven discovery overwhelms the 21-person NVD team.
ACLU-Led Coalition of 75 Groups Demands Meta Abandon 'Name Tag' Facial Recognition Before It Ships on Ray-Ban Glasses
A 75-organization coalition is pressing Meta to permanently drop plans for a face-identifying feature on its AI glasses, calling it 'a red line society must not cross.'
Microsoft's April 2026 Patch Tuesday Ships 163 Fixes, Including an Exploited SharePoint Spoofing Flaw and a Publicly Disclosed Defender Escalation
April's update is Microsoft's second-largest Patch Tuesday on record, with 8 critical flaws, two zero-days, and privilege escalation bugs accounting for well over half of the patches.
Meta Removes End-to-End Encryption From Instagram DMs as Take It Down Act Deadline Approaches
Meta will strip end-to-end encryption from Instagram direct messages on May 8, citing low adoption, just eleven days before the Take It Down Act compels platforms to police intimate content.
ShinyHunters Breach Rockstar Games via Third-Party Cloud Exploit, Release Financial Data After GTA VI Maker Refuses Ransom
Hackers exploited Anodot's integration with Rockstar's Snowflake cloud to steal nearly 80 million records of financial and analytics data, then published them after the studio refused to pay.
CPUID Website Hijacked to Distribute STX RAT Through Trojanized CPU-Z and HWMonitor Downloads
Attackers compromised CPUID's backend API and replaced download links for four popular hardware tools with malware-laden installers, infecting over 150 users across multiple countries.
APT28 Hijacked 18,000 Routers Worldwide While Deploying PRISMEX Malware Against Ukraine and NATO Allies
APT28 compromised 18,000 routers across 120 countries for credential theft while deploying PRISMEX malware against Ukraine and NATO logistics targets.
European Commission Confirms Data Breach After ShinyHunters Publish Stolen Europa.eu Records
The European Commission confirms a breach of its AWS-hosted Europa.eu platform after ShinyHunters published over 90 GB of stolen data. CERT-EU traces the intrusion to a supply chain attack on the Trivy security scanner.
Back-to-Back API Security Reports Reveal That 92 Percent of Organizations Cannot Defend Their AI Agents as Authenticated Attacks Dominate the Threat Landscape
Salt Security and KushoAI release dueling reports on the same day showing API security has become the critical blind spot of the agentic AI era, with nearly all attacks now originating from authenticated sources.
Wasmtime Ships Largest-Ever Security Patch After LLM-Driven Audit Uncovers 12 Vulnerabilities Including Two Critical Sandbox Escapes
The Bytecode Alliance patches 12 Wasmtime flaws, two critical, found during a three-week LLM-assisted security sprint by Mozilla, UCSD, Akamai, and F5.