Cybersecurity
204 articles RSS
IoT Security Regulation Accelerates on Both Sides of the Atlantic as NIST Rewrites Federal Guidance and the EU CRA's First Deadline Approaches
NIST is overhauling its IoT cybersecurity guidance for federal agencies while the EU Cyber Resilience Act's first enforcement deadline in September 2026 forces manufacturers to build vulnerability reporting infrastructure from scratch.
Flashpoint Report Finds Agentic AI Discussions on Criminal Forums Surged 1,500 Percent as Infostealers Fuel 3.3 Billion Stolen Credentials
Flashpoint's 2026 report documents a 1,500 percent spike in AI-related criminal forum activity, 3.3 billion stolen credentials from infostealers, and a 53 percent rise in ransomware incidents.
Passkeys Gain Regulatory Momentum as India Mandates Two-Factor Authentication and NIST Formalizes Syncable Credentials
India's Reserve Bank enforces mandatory two-factor authentication for all digital payments from April 1, while NIST's updated identity guidelines and Microsoft's passwordless-by-default accounts mark a coordinated global shift toward phishing-resistant authentication.
Qilin Ransomware Group Targets German Political Party Die Linke, Claiming 1.5 Terabytes of Stolen Data
Qilin ransomware group claims attack on German political party Die Linke, threatening to leak 1.5 terabytes of internal data in what the party calls a hybrid warfare operation.
Drift Protocol Suffers $285 Million Exploit in Largest DeFi Hack of 2026 as Analysts Point to North Korea
Attackers used Solana's durable nonce feature to hijack Drift's governance and drain $285 million in 12 minutes, with blockchain forensics firms linking the heist to North Korean operatives.
Kubescape 4.0 Graduates Runtime Threat Detection to GA and Introduces Security Scanning for AI Agents on Kubernetes
The CNCF incubating project ships runtime threat detection powered by CEL-based rules, a centralized security metadata store, and the first open-source controls for auditing AI agent configurations in Kubernetes clusters.
Google Patches Fourth Chrome Zero-Day of 2026 as CISA Orders Federal Agencies to Update Within Two Weeks
Google patches CVE-2026-5281, a use-after-free in Chrome's Dawn WebGPU layer exploited in the wild, marking the fourth Chrome zero-day of 2026. CISA gives federal agencies until April 15 to update.
Italy Fines Intesa Sanpaolo Nearly 50 Million Euros in March After Insider Breach Went Undetected for Two Years
Italy's data protection authority hit the country's largest bank with two separate fines totaling nearly 50 million euros for an insider data breach and unlawful customer profiling.
Unit 42 Exposes Shadow Campaigns, a State-Aligned Espionage Operation That Breached 70 Government Organizations Across 37 Countries
Palo Alto Networks researchers reveal TGR-STA-1030, an Asia-based threat group that compromised law enforcement agencies, finance ministries, and telecoms across 37 countries while scanning government infrastructure in 155 nations.
Anthropic Accidentally Exposes Claude Code's Entire Source Code Through npm Packaging Error, Days After Mythos Leak
A misconfigured npm package exposed 512,000 lines of Claude Code's TypeScript source code via a source map file pointing to Anthropic's cloud storage, marking the company's second data exposure in less than a week.
Two Cybersecurity Professionals Face Up to 20 Years in Prison After Pleading Guilty to Running BlackCat Ransomware Attacks
An incident response manager at Sygnia and a ransomware negotiator at DigitalMint admitted to moonlighting as ALPHV/BlackCat affiliates, targeting five US companies and causing over $9.5 million in losses.
OpenAI Patches ChatGPT DNS Data Exfiltration Flaw and Codex Command Injection That Exposed GitHub Tokens
Check Point and BeyondTrust disclose two distinct vulnerabilities in OpenAI products that allowed covert data theft through DNS queries and GitHub token compromise via branch name injection.