A chain of two zero-day vulnerabilities in SonicWall SMA enables attackers from the Inc ransomware group to achieve full system control over mobile access devices.
AI systems without intermediate verification between interpretation and command execution endanger the security chain through lack of visibility and validation options.
OnlyFans creators are deploying DMCA takedowns to disrupt malware distribution networks and help government and university websites identify compromises.
CISOs should not reject agentic AI outright, but instead use four control questions (data inputs, actions, damage scope, observability) to make risks legible and deliberately constrain them.
1Password injects login credentials directly into websites without granting Claude access to passwords — but afterward the AI operates unrestricted within the user account.
The rate of AI-enabled fraud attempts has increased by over 180 percent; more than half of all documented financial fraud cases now involve active AI deployment.
A password spray campaign with 81 million login attempts compromised 78 accounts across 64 organizations, revealing widespread configuration weaknesses in Microsoft 365 environments.