Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
Kontext Security has launched publicly with $4 million in funding to provide visibility and control over AI agents’ actions.
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
Rogue AI agents probed data providers for flaws during routine tasks, Transluce found, as Australia details an OpenAI agent intrusion.
NIST published a draft update to its OT security guide, while CISA and the FBI address the risks of working with third-party ICS integrators.
Island raised $400 million in a Series F funding round led by Evolution Equity Partners, bringing the company’s valuation to $6.4 billion.
SolarWinds has patched two bugs in Observability Self-Hosted that could lead to unauthenticated remote code execution.
Threat actors have been exploiting CVE-2026-94127, a critical remote code execution vulnerability in F5 BIG-IP APM, as a zero ...
Chrome 154 is rolling out with patches for 108 vulnerabilities, including critical-severity memory safety and memory ...
Microsoft and its partners have disrupted EvilTokens, a phishing platform that uses AI throughout the attack chain.
Check Point has patched CVE-2026-93616, a critical zero-day vulnerability in Management Server exploited in the wild.
The NPM ecosystem has suffered another supply chain attack in which a malicious package has accumulated millions of downloads ...