BlogRead More
Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission
When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to
This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments,
Five Rust-level memory optimizations to the DNS cache layout of Big Pineapple cut per-entry memory by 56%, freeing approximately 100
On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin
Found a bank card that isn’t yours? Here’s who to reach out to, why you shouldn’t try to track down
Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected
Key Findings Proofpoint identified a command and control (C2) framework called PackClient sold on Telegram. It is being used by
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The
At the 2026 Executive Partner Summit, Palo Alto Networks President BJ Jenkins made one thing clear: the AI era is
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge
Autonomous AI security threats aren’t novel super-weapons. They’re relentless, low-tech attacks that never stop. Learn why traditional defenses fail.BlogRead More
If you’re a student, writer, or professional juggling documents, this app can help keep you organized.Latest newsRead More
If you’re a student, writer, or professional juggling documents, this app can help keep you organized.Latest newsRead More
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:LinuxSecurity – Security AdvisoriesRead More
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:LinuxSecurity – Security AdvisoriesRead More
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate
With modern campaigns such as Vercel-hosted RMM attacks, the scale and security impact of phishing in US finance should not
Frontier AI has compressed attack timelines from weeks to minutes. For defenders to gain the upper hand, they need to
A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.SentinelOneRead More
On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with
AI-powered brand abuse is hitting banks hard. Read about the threats, the business impact, and how Akamai Brand Guardian helps
Cisco today launched its Sovereign Critical Infrastructure portfolio in Canada, giving greater control and choice over how organizations run their
As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance,
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP
Evidence suggests that criminals may control a substantial share of new gTLD registrations. Although the precise scale remains contested, the
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls
Cloudflare’s new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training.
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with
Kaspersky experts have discovered a trojan that infects car head units and makes them part of a botnet. Here’s how
This post describes the binary command-and-control (C2) protocol used by CNCMachineRMS, a recently identified remote access trojan (RAT). We cover
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.SentinelOneRead More
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate
Debuts, departures, and danger on the blockchain in this month’s edition of Intelligence Insights.Red CanaryRead More
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive?
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The
The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses
Learn how Akamai uses Masked Autoencoder Transformer models to detect sparse behavioral telemetry from autonomous AI browser agents, such as
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime
We explain how to avoid becoming a victim of IP camera surveillance at home or while traveling, and how to
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack
One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context.
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains
2 detection techniques that split behavioral analysis 6 common evasion techniques attackers use to evade static detection 6 core
RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We
Introducing Akamai Valkey Managed Database: a low-latency, in-memory data layer to optimize AI inference costs, accelerate RAG, and power real-time
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of
How a massive digital transformation is turning the Lindner Family Tennis Center into a year-round, hyper-connected destination.More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.htmlCisco
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. ANY.RUN
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress
Attackers are targeting Steam forums with malicious PowerShell commands disguised as fixes for game launch issues. Here’s how this version
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP
On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin
Courts sentence Com member for sextorting 117 minors, joint advisory warns of Gunra ransomware, and ShieldBreak bypasses MS Defender for
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
Introducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs
Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network
In this field report on IPv6-first Amazon Elastic Kubernetes Service (EKS), the isp6 team shares which dependencies still drag IPv4
As organizations race to deploy agentic AI, legacy network security solutions are ill-equipped to keep up, forcing productivity tradeoffs while
Palo Alto Networks works closely with OpenAI across our product platform and Unit 42, leveraging advanced frontier model capabilities. Furthermore,
Unit 42 is putting the latest frontier cyber models to work across customer environments to find, validate and help remediate
Cloudflare’s data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality
Why — and for whom — artificial intelligence is now churning out books, how they end up on Amazon, and
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of
Cloudflare’s Certificate Transparency Monitoring is now generally available. The biggest change: we no longer email you about certificates Cloudflare issued
In this Akamai FLAME Trailblazer blog post, Suzanne Wheeler describes her journey into cybersecurity and gives advice to women who
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still
The post Why Defensive AI Has a Harder Job Than Offensive AI appeared first on Nextron Systems.Nextron SystemsRead More
Why a feature introduced for a handful of members became one of the RIPE NCC’s most complex operational challenges.RIPE LabsRead
Threat monitoring serves as the vital connective tissue of modern security operations. It ensures that every function from triage to
Threat Intelligence Spotlight Executive Summary VMRay Labs has analyzed a family of malicious WinRAR self-extracting archives that act as droppers.
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily
The Adform platform was briefly hijacked to distribute a crypto-stealing script. Here’s everything we know about the incident, plus tips
In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic
Supply chain vulnerabilities represent a growing attack surface for US and EU organizations. With advanced threat tactics on the rise,
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.
Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets
Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs,
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support
How polyglots are built, real-world cyberattack examples, and tips for detecting and preventing this threat.Kaspersky official blogRead More
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP
Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and
Cloudflare for Government achieves FedRAMP Class D (High) Certified status. We also announce our commitment to pursue DoD IL4 authorization.
The post New in THOR Cloud: SSO, Granular Permissions, and Account API Keys appeared first on Nextron Systems.Nextron SystemsRead More
Every Agent Needs an Oracle Detection rules are increasingly drafted by machines rather than by human engineers. An agent reads
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as
The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.
The Labs team at VMRay actively gathers publicly available data to identify any noteworthy malware developments that demand immediate attention.
Cloudflare is unifying AI Gateway and Workers AI into a single control plane, giving developers observability, billing, and dynamic routing
Cloudflare Radar Researcher is a new AI-powered tool that lets you explore global Internet trends and traffic data using plain
We are launching updated community programs, including Cloudflare Ambassadors and Community Engineers, backed by $1M in open-source funding. Learn how
Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors