Vulnerabilities & Exploits

Is Your GitLab AI Gateway Safe From This 9.9 Critical Flaw?
Infrastructure & Network Security Is Your GitLab AI Gateway Safe From This 9.9 Critical Flaw?

The AI Gateway serves as the essential compute layer for GitLab Duo, making a sandbox escape particularly dangerous for organizations relying on AI-assisted coding. The discovery of CVE-2026-90970, which carries a near-perfect severity rating of 9.9 out of 10, marks a significant moment for the

New Cling Botnet Uses Google STUN Traffic to Hide C2 Activity
Malware & Threats New Cling Botnet Uses Google STUN Traffic to Hide C2 Activity

The sheer volume of internet traffic generated by standard video conferencing and peer-to-peer browser sessions provides a perfect camouflage for modern cyber threats seeking to evade traditional detection. Within this immense sea of legitimate data, the Cling botnet has emerged as a particularly

Microsoft Reissues Exchange Update to Fix Mailbox Flaw
Infrastructure & Network Security Microsoft Reissues Exchange Update to Fix Mailbox Flaw

Security experts warn that the CVE-2026-96940 vulnerability stems from inadequate authorization logic within the Exchange Server framework, necessitating immediate administrative intervention. This flaw allows an attacker who has already authenticated to the network to gain unauthorized access to

AI Agents Transform Modern Security and Compliance Management
Security Operations & Management AI Agents Transform Modern Security and Compliance Management

The transition from passive security tools to autonomous agentic systems represents a fundamental shift in how organizations manage digital accountability and oversight. In the high-velocity environment of 2026, the volume of telemetry data produced by cloud-native infrastructures has exceeded the

How Will Agentic AI Transform the Security Workforce?
Security Operations & Management How Will Agentic AI Transform the Security Workforce?

In the high-stakes environment of Web3, agentic AI serves as a digital circuit breaker capable of pausing smart contracts the moment an exploit is detected. This development signifies a monumental shift in the cybersecurity landscape, where tools are no longer merely passive observers but active

AI Email Summarizers Vulnerable to Indirect Prompt Injection
Malware & Threats AI Email Summarizers Vulnerable to Indirect Prompt Injection

While explicit instructions help an attacker remove legitimate data, the mere presence of forged text is often enough to insert misinformation into a summary. In the current landscape of 2026, professional productivity relies heavily on automated assistants that distill massive communication

Loading

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later