China-linked cyber espionage group TA416 targets European and Middle Eastern government entities using PlugX malware, OAuth phishing, and evolving attack chains.
Apple extends iOS 18.7.7 and iPadOS 18.7.7 updates to more devices to block DarkSword exploit, addressing critical vulnerabilities in older iOS versions.
Security researchers reveal critical vulnerabilities in LangChain and LangGraph that could expose files, secrets, and databases, raising concerns for enterprise AI deployments.
Google has accelerated its quantum computing timeline to 2029, urging faster adoption of post quantum cryptography as threats to current encryption standards grow.
A critical Magento vulnerability named PolyShell exposes stores to unauthenticated file uploads, remote code execution, and account takeover risks, with active exploitation now observed.
A supply chain attack linked to Trivy has led to the spread of CanisterWorm malware across dozens of npm packages, exploiting tokens and decentralized infrastructure.
Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.
Awan Distribution conducted a TrendMicro NDR partner enablement session in Karachi, focusing on network detection and response, licensing, and strengthening cybersecurity partnerships.
As enterprises deploy AI agents that read and act on information from internal systems and the internet, prompt injection is emerging as a new cybersecurity risk that can manipulate machine reasoning, expose sensitive data, and influence automated workflows.