(Adobe Stock) Over 100 US water utilities had cyberattacks in July, says CISASteve ZurierAugust 26, 2026More than 100 water systems faced attacks in July as CISA urges utilities to reduce OT exposure.
The Taiwan attack was built with two free downloads from vendors nobody rates Rob SmithAugust 21, 2026
FBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructureSC StaffAugust 26, 2026
AI-powered defense strategy: How to find and fix vulnerabilities at machine speedPaul WagenseilAugust 18, 2026
Inside Mythos: A CSO’s technical decoder for Anthropic’s autonomous offensive AIPaul WagenseilAugust 17, 2026
Application securityOWASP updates top 10 security risks for LLM applicationsSC StaffAugust 26, 2026OWASP’s 2026 LLM Top 10 highlights prompt injection, AI agents and emerging RAG security risks.
Application securityMobile banking trojans expand capabilities; 66% now allow full device takeoverLaura FrenchAugust 26, 2026Banking trojans have evolved to include remote control and ransomware capabilities.
Vulnerability ManagementCISA adds Oracle WebLogic bug to its list of exploited vulnerabilitiesSteve ZurierAugust 25, 2026Experts say exploiting WebLogic middleware gives attackers access to an enterprise's core business apps.
MalwareCodex ClickFix installation lure spreads suspected AMOS infostealerLaura FrenchAugust 25, 2026The attack uses iframes embedded in Google Sites to deliver malicious content from a trusted domain.
IdentityMicrosoft says Entra ID identity software not exploited, revises CVESteve ZurierAugust 24, 2026While the urgency has changed, security pros say teams should still review Entra ID logs for anything suspicious before the patch.
Vulnerability ManagementCISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities listSteve ZurierAugust 24, 2026Experts warn that it’s the fifth time Zimbra made the KEV this year.
Active DirectoryWhy Short-Lived Workloads Create Long-Lived Identity RiskSC Media Editorial Intelligence, reviewed by Christopher AshbyAugust 24, 2026Static Governance Cannot Keep Pace with Ephemeral Identities
Vulnerability ManagementTrueConf flaws enabling attacks on meeting participants added to KEV catalogLaura FrenchAugust 21, 2026The flaws have been used by the Head Mare APT hacktivist group to spread PhantomCore malware.