Phishing-as-a-Service lowers barriers to entry for cybercriminals to such an extent that hardware-based authentication according to FIDO2 standards becomes an essential defensive measure.
Attackers with admin access can abuse Windows Bind Links to redirect legitimate file paths to malicious binaries, bypassing EDR, AMSI, and AppLocker controls.
Approved tracking code can lead to uncontrolled data access through fourth-party layers and should be minimized through strict inventory management and controls.
The White House establishes Gold Eagle, an AI-powered clearinghouse for centralized prioritization and coordinated remediation of software vulnerabilities across government agencies and critical infrastructure operators.
CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 enable unauthenticated and authenticated attacks with severity 10.0; immediate patches required, no workarounds available.
An AI agent executed a ransomware attack with complete automation, demonstrating that autonomous malware can significantly increase the speed and efficiency of attacks.
Manipulated browser extensions can trick the Claude extension into performing actions in Gmail, Google Docs, and Calendar contexts, which Manifold Security has reproduced since May and Anthropic has yet to fix.