A widely distributed YouTube ad blocker extension with over 10 million downloads can be abused through server-side configuration to execute arbitrary malicious code without evidence of active abuse to date.
The critical deserialization vulnerability CVE-2026-12569 in PTC Windchill PDMLink is being actively exploited; attackers are installing web shells and targeting sensitive design and engineering data in defense, aerospace, and automotive sectors.
The national implementation law (NISG) 2026 anchors the EU NIS2 Directive in Austrian law and expands cybersecurity and reporting requirements for critical infrastructures and important entities.
The Open Source Sustainability Initiative helps enterprises systematically meet security and compliance requirements for outdated open-source software.
Russian intelligence operatives are phishing not only Signal accounts but also their backup recovery keys — a single compromised key enables permanent access to all messages and account takeover.
Anthropic’s Opus 4.6 withstood 6,000 prompt injection attacks in a public security test without compromise, indicating improved defense mechanisms — but such stability results do not replace comprehensive security design in production.