News & Map
1,187 items on Cyberstrategy — showing 201–240 · 1,075 without coordinates · Across the network · RSS
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the Chat...
No location · Sep 19, 2026 · WedgetailBragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Oper...
No location · Sep 19, 2026 · WedgetailNorth Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices...
No location · Sep 19, 2026 · WedgetailShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor sit...
No location · Sep 19, 2026 · WedgetailCan You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that ...
No location · Sep 19, 2026 · WedgetailIdentity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among t...
No location · Sep 19, 2026 · WedgetailSolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if success...
No location · Sep 19, 2026 · WedgetailCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The v...
No location · Sep 19, 2026 · WedgetailGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into ot...
No location · Sep 19, 2026 · WedgetailCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who ha...
No location · Sep 19, 2026 · WedgetailCISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linu...
No location · Sep 19, 2026 · WedgetailVectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use o...
No location · Sep 18, 2026 · WedgetailEarly Scattered Spider member pleads guilty to cybercrime spree
Ahmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million ...
No location · Sep 18, 2026 · WedgetailCisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 o...
No location · Sep 18, 2026 · WedgetailMFA Won't Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocati...
No location · Sep 18, 2026 · WedgetailPublic Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root...
No location · Sep 18, 2026 · WedgetailResearchers use AI to find widespread software decoder flaw
The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production envir...
No location · Sep 18, 2026 · WedgetailThe U.S. Is Highly Vulnerable to Cyber Threats From China. Here’s What It Should Do
Protecting vulnerable infrastructure will require a multipronged approach to make the United States a tougher target.
No location · Sep 18, 2026 · WedgetailNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a cr...
No location · Sep 18, 2026 · WedgetailInternational security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more tha...
No location · Sep 18, 2026 · WedgetailTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a ...
No location · Sep 18, 2026 · WedgetailNew Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two ...
No location · Sep 18, 2026 · WedgetailMicrosoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve...
No location · Sep 18, 2026 · WedgetailAre AIs Still Struggling with CAPTCHAs?
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the tra...
No location · Sep 18, 2026 · WedgetailAI cybersecurity risks explode as Claude used to break into ChatGPT
The effort, part of a bug-hunting program, was the latest in a series of cybersecurity breaches, The Wall Street Journal...
No location · Sep 18, 2026 · WedgetailAn Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down...
No location · Sep 18, 2026 · WedgetailPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agen...
No location · Sep 18, 2026 · WedgetailWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undo...
No location · Sep 18, 2026 · WedgetailCISA Upgrades Vulnerability Reporting Platform with More Automation
The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT
No location · Sep 18, 2026 · WedgetailClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based info...
No location · Sep 18, 2026 · Wedgetail‘Nudify’ apps: What to do if someone makes a fake nude of you
Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images
No location · Sep 18, 2026 · WedgetailManufacturing Accounts for 22% of all Ransomware Victims
Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in ...
No location · Sep 18, 2026 · WedgetailAI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bid...
No location · Sep 18, 2026 · WedgetailRatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based...
No location · Sep 18, 2026 · WedgetailClaiming the Kill: Attribution and False-Flagging in Cyber Offense
Abstract In this article, we highlight the roles of attribution and false-flagging in cyber offense operations. Drawing ...
No location · Sep 18, 2026 · WedgetailResponding to the Risks of Open-Weight AI Models
Open-weight AI models place powerful capabilities beyond any developer’s control. The UK should clarify how its investig...
No location · Sep 17, 2026 · WedgetailTrump’s Risky Hack-Back Plan
The U.S. president wants tech companies to go on the cyber-offensive. Will it work?
No location · Sep 17, 2026 · WedgetailCISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that act...
No location · Sep 17, 2026 · WedgetailCisco alerts customers to second actively exploited zero-day in as many days
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three a...
No location · Sep 17, 2026 · WedgetailCMSSF highlights cyber Guardians’ role in creating joint decision advantage
CMSSF Bentivegna detailed the service's "train, test and trust" approach to developing mission-ready cyber operators cap...
No location · Sep 17, 2026 · Wedgetail1,075 of 1,187 items have no coordinates and so are listed but not mapped.