A software developer accidentally accessed and controlled about 7,000 DJI Romo robot vacuums worldwide while trying to connect his own device to a PlayStation controller, exposing serious security vulnerabilities in smart home devices.
Cisco Talos tracks UAT-10027, a malicious campaign targeting U.S. education and healthcare sectors with Dohdoor backdoor using DNS over HTTPS for stealthy command-and-control.
Google, in collaboration with industry partners, has disrupted the infrastructure of UNC2814, a suspected China-linked cyber espionage group using GRIDTIDE malware to target 53 organizations across 42 countries, supporting affected organizations and cutting off malicious access.
North Korea linked Lazarus Group has been observed using Medusa ransomware in attacks targeting a Middle Eastern entity and a U.S. healthcare organization, signaling a tactical shift toward ransomware as a service operations.
Cybersecurity researchers uncover a wormable XMRig cryptojacking campaign using pirated software, BYOVD exploits, and time-based logic bombs to maximize mining and propagate across systems.
Microsoft confirms a bug in Microsoft 365 Copilot allowed sensitive emails with labels to be summarized in Copilot Chat, bypassing DLP controls, fixed on February 3, 2026.
A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.
Researchers disclose critical vulnerabilities in four popular Microsoft Visual Studio Code extensions that could enable file theft and remote code execution across developer environments.
Researchers at ThreatFabric uncover Massiv, a new Android banking trojan spread via fake IPTV apps that enables device takeover attacks and mobile financial fraud.
Apple introduces end to end encrypted RCS messaging in iOS 26.4 developer beta, alongside enhanced Memory Integrity Enforcement and default Stolen Device Protection features.
Microsoft researchers identify more than 50 hidden prompts embedded in Summarize with AI buttons that influence assistants to remember and recommend specific brands without user awareness.
Yair Kuznitsov, CEO of Anecdotes, explains how agentic AI is reshaping Governance, Risk, and Compliance by embedding autonomous decision making into GRC workflows.