OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
Project CAV3RN uses Google Apps Script as a command-and-control relay to target Israeli systems, leveraging legitimate Google services as cover for malicious traffic. The campaign employs a modular .NET NativeAOT framework paired with DNS-based C2 channel selection, enabling attackers to route commands while blending communications with benign Google traffic to bypass security detection.
Kimwolf v7 represents an updated iteration of the Kimwolf botnet with enhanced capabilities targeting Android IoT devices, leveraging HTTP/2 DDoS fingerprinting for attacks. The malware employs Ethereum ENS for command-and-control resolution alongside Tor-based backup routing to maintain resilience against takedown efforts.
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
A critical unauthenticated SQL injection vulnerability has been discovered in Metabase's password reset functionality, tracked as CVE-2026-72898, with confirmed active exploitation occurring in the wild. Organizations operating self-hosted Metabase instances are urged to take immediate remediation action to protect against this vulnerability, which requires no authentication to exploit.
Minerals become chips. Chips become data centers. Data centers become models, and models are acquiring arms and legs. From Earth to Embodied AI traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link, from mine to machine.
Elastic Security Labs released an analysis of 13 million tool calls from AI coding agents, demonstrating how Cursor hooks and Elastic Agent can capture and log every action including shell commands, file reads, and MCP requests as structured events. This capability enables security teams to hunt through AI agent activities using ES|QL, providing visibility into potentially risky automated actions in development environments. The research highlights the growing need for detailed auditing and threat hunting capabilities as AI coding tools become more prevalent in enterprise workflows.
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 10 (Critical). Affects Metabase Metabase.
Unit 42 has published an analysis of the Aeternum botnet loader, which uses Polygon blockchain smart contracts to establish decentralized command-and-control infrastructure and execute payloads. This approach represents an evolution in botnet evasion tactics, leveraging blockchain technology to distribute and maintain C2 operations outside traditional network chokepoints. The analysis examines how Aeternum's architecture enables resilient malware communications through on-chain smart contracts.
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
A maximum-severity zero-day vulnerability in Metabase allows remote attackers to gain administrator access to the business-analytics platform, potentially exposing both the platform itself and its downstream users to compromise. The flaw remains unpatched and has not yet been assigned a CVE identifier, creating immediate risk for organizations using the affected software.
A growing number of UK venues have decided to act against privacy-busting smart glasses. Read more in my article on the Hot for Security blog.
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Sophisticated iPhone exploit chains that were previously restricted to nation-state actors are now proliferating among organized cybercrime groups globally. The Coruna and DarkSword exploits represent a significant shift in the accessibility of advanced iOS attack capabilities, expanding the threat landscape beyond state-sponsored operations to larger criminal ecosystems.
A public policy expert has developed a five-point framework to address gaps in global cybercrime legislation that currently expose ethical hackers and security researchers to legal risk. The analysis maps existing cybercrime laws across jurisdictions to identify how outdated regulations fail to adequately protect good-faith security research activities. This framework aims to guide policymakers in updating laws to better distinguish between malicious hacking and legitimate security work.
Microsoft has been recognized as a Leader in the 2026 IDC MarketScape for managed detection and response services, reflecting competitive positioning in the enterprise MDR/MXDR market. The company's Defender Experts MDR offering integrates artificial intelligence, threat intelligence, and human security expertise to deliver detection and response capabilities.