Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.
The Labs team at VMRay actively gathers publicly available data to identify any noteworthy malware developments that demand immediate attention.
Cloudflare is unifying AI Gateway and Workers AI into a single control plane, giving developers observability, billing, and dynamic routing
Cloudflare Radar Researcher is a new AI-powered tool that lets you explore global Internet trends and traffic data using plain
We are launching updated community programs, including Cloudflare Ambassadors and Community Engineers, backed by $1M in open-source funding. Learn how
Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors
Snowflake hacker’s guilty plea covers a 100M-record breach, Mythos 5 spends 34 hours trying to backdoor real code, and ChainDrop’s
By Yarden Porat, Check Point Research Key Points The short version We set out to break Cloudflare Code Mode, and ended
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2
Discover how Akamai AI Professional Services helps enterprises bridge the gap from proof of concept to secure, scalable, and manageable
Day two at Black Hat, and Check Point Research brought two talks to the stage that gave the room plenty
Today we’re launching a developer preview of WebMCP on Cloudflare. With one switch, any site becomes usable by browser AI
The next version of MCP has a rewritten, stateless core that just works on Workers. We cover upgrades to the
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send
Write once, shell everywhere. Sun Microsystems didn’t mean it like this. Talk from today at DEF CON’s Bug Bounty Village.
Before and after shots of Elon’s ejecta snapped by Danuriwww.theregister.com – ArticlesRead More
A vulnerability classified as critical was found in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function
We should be giving all agents tools that excel at what’s important for an AI model. Kitesurf is Cloudflare’s new
More than half of requests now come from machines, not people. Agent Readiness shows how well agents can discover and
Agents are a new kind of visitor. They don’t render CSS or click ads, but they have a paying human
AI Search makes search easier than ever, with no Cloudflare primitives to stitch together. Point it at your data to
Security teams do not need another threat feed. Instead, they need to know which threats matter to their organization, what’s
As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every
Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token
We’re honored to announce that Cloudflare is the only vendor that has been recognized as a Visionary in both the
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change
Cloudflare OS is an open-source platform that lets everyone in your company build apps, automate work, and safely access internal
At Cloudflare, we knew we could not depend on every employee to configure every agent perfectly or watch every tool
Discover top enterprise AI risks — from shadow AI to rogue agents and data leaks — plus practical CISO strategies
Identity-aware AI Gateway is now in open beta. User Insights turns that traffic into a behavioral baseline for every person
We built Cloudflare OS to equip our teams to safely rethink how they get work done with AI. The platform
The Agent Access Model proposes a new architecture to secure task-scoped agents using strict identity brokering, continuous mediation, and stateful
What Cisco data reveals about networks, AI, and the infrastructure powering a changing digital world.More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.htmlCisco Newsroom: Feature
ChongLuaDao protects over 200 million users from cybercrime, having detected more than 1.4 million malicious websites since 2020. Rapid processing
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates.
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and
Launching AI-driven cyberattacks on businesses no longer requires advanced OpenAI models. We analyze a recent breach to build an effective
Defend the entire AI agentic stack across endpoints, identities, cloud, and apps with SentinelOne’s unified platform.SentinelOneRead More
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against
Learn how to build customizable, sandboxed CI/CD pipelines natively on Cloudflare using Workflows, Artifacts, and the CI SDK. We walk
Cloudflare Wallets will provide AI agents with native payments and verifiable identity on the web. Using the x402 protocol, agents
Agents can write code faster than teams can review, deploy, and maintain it. Today we’re introducing the Agent Development Lifecycle
Cloudflare Agents brings all of your deployed agent sessions into a single experience, surfacing key information and insights into how
wrangler dev now produces structured traces for every local request. Your coding agent can hit a single API to pinpoint
By replacing manual issue verification with isolated AI subagents running in GitHub Actions, the Astro maintainers reduced open issue count
We created the Cloudflare Codex, a governed body of engineering standards that AI agents consume across the development lifecycle. By
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply
Cisco’s Amin Karbasi on a new family of open-weight, small-language AI models ready for the big task of pinpointing vulnerabilities
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms
The post Detecting Certighost (CVE-2026-54121): Sigma Coverage Across the Full Attack Chain appeared first on Nextron Systems.Nextron SystemsRead More
July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. ANY.RUN
9 malware analysis platforms and services compared 6 layers of trust in agentic malware analysis 5 critical control points for
We break down CrashStealer — a new macOS infostealer: how it spreads, what data it steals, how it bypasses Apple’s
One coding agent can write a Python Worker and another can write a JavaScript Worker. At runtime, those Workers can
Serving frontier models like Kimi and GLM means fighting for GPU memory. Here’s how we quantize KV caches, compress model
Cloudflare has launched a new Billable Usage API for accounts, giving developers and FinOps teams single-endpoint programmatic visibility into cost
Cloudflare Workers now support inbound TCP connections via Spectrum, allowing direct socket forwarding to Durable Objects and Containers. Developers can
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips
Agents need more than just a container to scale. We’re introducing @cloudflare/computer, an agent runtime that dynamically orchestrates between fast,
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to
Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations
In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working
Discover why open source AI is vital for cybersecurity as we join the Open Secure AI Alliance to build an
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and
Last year we made every Cloudflare server a Media over QUIC (MoQ) relay. Now the new provisioning API lets you
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations
TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to
We moved cdnjs, serving 9 billion requests a day, entirely onto Cloudflare’s Developer Platform. That means we’re running one of
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells,
Ten years of DNS measurements reveal three trends across the Internet’s most popular domains: email continues to consolidate around two
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks
July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. ANY.RUN
Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit
Scale AI by mastering tokenomics. Align high-velocity innovation with budget oversight to mitigate risk and ensure sustainable production.More RSS Feeds:
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The
7 common alert types across SOC deployments 4 structural problems fueling alert fatigue 5 principles that separate effective teams from
We analyze a campaign that leverages ScreenConnect: distribution through fake websites, AsyncRAT deployment, evasion tactics, and organizational defense recommendations.Kaspersky official
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can
Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust
Cyber risk is increasing, but so is the cost of managing it. More than 514,000 cybersecurity job listings appeared in
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026,
Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Fulfilling that mission demands
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced
Learn how Akamai Guardicore Segmentation empowers partners to ease customer AI anxiety and contain machine-speed exploits with automated microsegmentation.BlogRead More
Cloudflare Radar tracked Internet disruptions driven by natural disasters, government-mandated shutdowns, and DNSSEC key rollovers over the last quarter. This
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. NIS2 not yet law in
Email gateways, endpoint controls, and file-centric sandboxing remain essential layers of defense. But many of today’s phishing attacks unfold in
Key Takeaways Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools and services
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead
We break down how ClickFix works on macOS: why attackers trick users into running commands in Terminal, what data the
Microsoft’s External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red
Why security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt
Please stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP
pvcli is a curl-like tool designed to simplify the testing of complex privacy protocols like OHTTP.The Cloudflare BlogRead More
By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic
On some websites, agents can read your messages before you even send them. We explain how these tracking mechanisms work,
An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction.
Authorities arrest Kratos’s developer, HollowGraph hides C2 in 2050 calendar events, and OpenAI’s models breach Hugging Face to steal benchmark
Transform expert SOC analysis into an on-demand AI capability to empower all analysts and accelerate threat resolution.SentinelOneRead More
TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be
OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no
Learn why crypto-agility depends not just on adopting the right standards, but on maintaining a clear, unified view of your