A survey by MetaCompliance reveals significant communication gaps between cybersecurity leaders and corporate boards, with three-quarters of CISOs concerned that executives lack understanding of the cyber risks threatening their workforce. The findings highlight a broader disconnect where many board members appear disengaged from the evolving nature of cybersecurity threats facing employees across their organizations.
Operation First Light 2026, a Chinese-government-funded Interpol initiative, has resulted in 5,811 arrests in a coordinated cybercrime crackdown. The operation demonstrates international law enforcement collaboration against cyber threats, with China providing financial backing for the large-scale enforcement action.
Over 70 cybersecurity organizations have endorsed the CREST AI Charter, establishing guidelines for the responsible deployment of artificial intelligence in security operations. The charter represents industry consensus on best practices for leveraging AI capabilities while maintaining ethical standards and security integrity.
Zimperium has discovered RedWing, an Android spyware operation being monetized as a service through Telegram channels, primarily targeting banking applications. The malware-as-a-service model enables threat actors to purchase access to the spyware capabilities for financial fraud and data theft purposes.
Cisco Talos has identified China-linked APT UAT-7810 expanding its infrastructure through the development of new malware designed to augment its proxy relay network. This expansion suggests the threat actor is strengthening its capabilities for obfuscating command-and-control communications and maintaining persistent access to compromised systems.
A Bishop Fox researcher demonstrates that Claude can autonomously crack SonicWall's proprietary firmware encryption—a task previously requiring senior-level expertise—when provided minimal guidance and relevant artifacts. The experiment reveals significant implications for the trajectory of AI-assisted security research and the evolving relationship between human expertise and autonomous AI capabilities in vulnerability discovery.
A cybersecurity startup offering substantial payments for zero-day vulnerabilities is operated by individuals with convictions and a history of deceptive ventures, including fake intelligence firms and a defunct AI-based lobbying platform run under aliases. The operators are identified as far-right conspiracy theorists whose track record raises questions about how acquired vulnerabilities might be used and whether the startup's true intentions align with legitimate security research.
A Sygnia report reveals that threat actors leveraged agentic AI to dramatically accelerate a cloud-focused attack, compressing what would typically take weeks into a 72-hour compromise window. The findings highlight how autonomous AI systems are enabling attackers to execute reconnaissance, exploitation, and lateral movement at unprecedented speed, presenting a significant new threat vector for cloud environments.
Cyber threat actors are executing a coordinated campaign that delivers both the Vidar infostealer and XMRig cryptocurrency miner to compromised systems. The dual-payload approach combines data theft capabilities with unauthorized cryptographic resource consumption, targeting victims' sensitive information and computing resources simultaneously.
Mewt, an open-source mutation-testing engine, now supports DAML smart contracts by deliberately injecting code flaws to expose gaps in test suites that traditional coverage metrics miss. The tool includes two DAML-specific mutations targeting authorization vulnerabilities—the most common bug class in contract development—and can identify missing security tests even when coverage reports show 100%. Early testing on production codebases revealed that standard happy-path tests often fail to verify negative cases like unauthorized party actions, leaving exploitable vulnerabilities undetected.
A suspected Chinese threat group is actively exploiting Roundcube vulnerabilities to breach university networks across the US and Canada with the goal of harvesting user credentials. The campaign targets higher education institutions, leveraging weaknesses in the popular webmail platform to gain initial access to sensitive academic and research environments.
The UK government has launched a Cyber Resilience Pledge with over 60 organizational signatories including major companies like M&S, Microsoft UK, and Vodafone. The initiative is designed to strengthen cyber security and resilience practices across British businesses.
Threat actors are actively exploiting a critical Adobe ColdFusion vulnerability with a maximum CVSS severity score of 10.0. Organizations running ColdFusion should prioritize patching this flaw immediately given the active exploitation and highest possible severity rating.