Microsoft on Thursday disclosed a zero-day vulnerability in Exchange that's under active exploitation, but four days later customers are still awaiting a patch. The zero-day, tracked as CVE-2026-42897 ...
AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast ...
Robert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier consider whether columns they ...
In a role reversal, investment dollars in AI security startups exceeded the value of AI acquisitions in 1Q26 by more than $1 ...
A Taiwanese student experimenting with software-defined radio shut down three bullet trains for nearly an hour, leading to an ...
Congress sent a letter to Instructure about the Canvas cyberattack, after it said it reached an "agreement" with the ...
A ransomware attack on Foxconn's North American facilities is one of 600 hits on manufacturers this year, as gangs ...
Threat actors are publishing RubyGems packages that include scrapers targeting public-facing UK government servers, but with ...
Security governance needs to be more than an annual compliance exercise. New companies are emerging to address ...
It's the first time in two years with no zero-days. But with 137 flaws to patch, including nine critical ones, admins still ...