SonicWall reports two major security holes under active exploit
SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each.…
Consultants called the holes, one of which permits remote attacks that…
In its security alert, SonicWall described the first hole, tracked as …
Anthropic introduces zero-retention AI safety monitoring for enterprises
Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements.…
The company announced a new solution called Enterprise Frontier Safegu…
Under the approach, activity data used for monitoring will be stored i…
Exploited JFrog Artifactory bug puts software supply chain on alert
A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.…
The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August …
By September 1, watchTowr said its Attacker Eye honeypot was already s…
How China industrialized the infrastructure behind state hacking
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networks.…
A People’s Republic of China (PRC) state-sponsored group known as “QTF…
Among the targets of QTFY are the National Aeronautics and Space Admin…
Anthropic makes changes to stop AI agents running amok again
Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices.…
The company has established controls that flag when a model attempts t…
” Anthropic conceded that three recent security incidents involving Cl…
CrowdStrike launches cyber frontier AI models, agentic security system
CrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.…
Con conference in Las Vegas.
At the heart of SafeMind are two purpose-built cybersecurity models, t…
OpenClaw rolls out system-wide overhaul, updates security controls across agent platform
OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments.…
“This update touches every part of OpenClaw, including installation, m…
The project said that the scope of the release expanded during develop…
Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organization.…
Microsoft Threat Intelligence said a campaign it calls TerminalFix, a …
Victims are tricked into copying and running a malicious PowerShell co…
China-linked hackers turn Cisco routers into covert attack infrastructure
A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia.…
The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR…
The attackers also compromised TACACS authentication infrastructure an…