Risk & Resilience

Interlock Ransomware Exploits Cisco FMC Zero Day CVE 2026 20131 For Root Access

Interlock ransomware targets Cisco FMC zero day vulnerability CVE 2026 20131, enabling remote root access and highlighting rising risks in firewall security.

AI Security Flaws Discovered In Amazon Bedrock LangSmith And SGLang Raise Data Protection Concerns

Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.

Android 17 Restricts Non‑Accessibility Apps From Accessibility API To Strengthen Security Protections

Google is rolling out an accessibility API restriction in Android 17 Beta 2 under Android Advanced Protection Mode, blocking non‑accessibility apps from using powerful privileges to curb malware abuse while introducing a refined contacts picker for granular data access control.

OpenClaw AI Agent Security Flaws Raise Prompt Injection And Data Exfiltration Concerns

China’s CNCERT warns that OpenClaw AI agent security weaknesses could enable prompt injection attacks, endpoint compromise, and sensitive data exfiltration.

GlassWorm Supply Chain Campaign Targets Developers Through Malicious Open VSX Extensions

Security researchers report an expanded GlassWorm campaign using malicious Open VSX extensions and hidden Unicode code to target developers and steal sensitive data.

When Machines Read the Internet: What Security Champions Need to Know About Prompt Injection

As enterprises deploy AI agents that read and act on information from internal systems and the internet, prompt injection is emerging as a new cybersecurity risk that can manipulate machine reasoning, expose sensitive data, and influence automated workflows.

Microsoft Releases Security Updates For 59 Vulnerabilities Including Six Actively Exploited Zero Day Flaws

Microsoft releases security patches addressing 59 vulnerabilities across its products, including six zero day flaws actively exploited in real world attacks.

Gartner’s Emerging Risk Map: What the Q3–Q4 2025 Reports Signal for Enterprises—and for Pakistan

Gartner’s Q3–Q4 2025 Emerging Risk Reports highlight systemic enterprise risks, including economic stagnation, AI governance gaps, shadow AI, environmental volatility, and geopolitical fragmentation, with direct implications for Pakistan’s technology and digital sectors.

Threat Actors Mass Scan Salesforce Experience Cloud Using Modified AuraInspector Tool

Salesforce warns of large scale scanning attempts targeting misconfigured Experience Cloud sites using a modified AuraInspector tool capable of extracting sensitive data from public endpoints.

Anthropic AI Discovers 22 Security Vulnerabilities In Mozilla Firefox Using Claude Opus 4.6

Anthropic identifies 22 security vulnerabilities in Mozilla Firefox using its Claude Opus 4.6 AI model during a security collaboration with Mozilla, with most issues fixed in Firefox 148.

Transparent Tribe Uses AI To Mass Produce Malware In Campaign Targeting Government Entities

Transparent Tribe, also known as APT36, is using AI assisted coding tools to generate large volumes of malware implants targeting government organizations and diplomatic missions, according to Bitdefender research.

China Linked Hackers Target South American Telecom Infrastructure Using TernDoor PeerTime And BruteEntry

Cisco Talos reports China linked UAT-9244 APT actor using TernDoor, PeerTime, and BruteEntry implants to compromise Windows, Linux, and edge devices in South American telecom networks.

Recent articles

spot_img