Browsing Category
Security
137 posts
Cybersecurity news, software supply chain risk, privacy threats, and practical security guidance.
Gemini 4 Argon Debuts With 1M-Token Output, but Access Starts With Cyber Defenders
Google's Gemini 4 Argon pairs a one-million-token output limit with low introductory pricing, but only vetted cyber defenders can use it first.
Cloudflare Plans a Post-Quantum Certificate Authority: What Changes for HTTPS
Cloudflare plans to issue free classical and post-quantum certificates in 2027. Here is how Merkle Tree Certificates work and what website teams should prepare now.
NVIDIA’s Open Agent Safety Platform Moves Guardrails Outside the Model
NVIDIA’s OpenShell runtime restricts AI-agent files, networks, processes and credentials, while Sentry adds a BlueField-4 hardware watchdog. Here is how the stack works and where its claims still need proof.
Citrix NetScaler Zero-Days: Patch Now, Then Hunt for Web Shells
Citrix patched two actively exploited NetScaler zero-days that allow unauthenticated remote code execution. Here are the fixed builds, attack path, log hunts and response order.
EvilTokens Disruption Exposes the Device-Code Phishing Gap
Microsoft and partners disrupted EvilTokens after more than 12,000 inbox compromises. Here is how device-code phishing bypasses normal expectations and what Microsoft 365 teams should change now.
Check Point Zero-Day Puts Firewall Management Servers on a Three-Day Patch Clock
Check Point patched an exploited management-server zero-day and confirmed Spark VPN attacks. Here are the fixed hotfix takes, hunt commands, and September 25 deadline.
Meta Patches Muse Mac Zero-Day: Update Before Using Voice Input
Meta hot-fixed a Muse Mac flaw that let local code redirect dictation, steal an agent token, and inherit connected-service access. Here is how it worked and what users should check now.
Palo Alto Launches Always-On AI Pentesting With Mythos 5 and GPT-5.6-Cyber
Palo Alto Networks' Unit 42 now uses Mythos 5, GPT-5.6-Cyber, and open models for continuous attack-path testing. Its own results show why buyers should judge the harness, controls, and remediation workflow, not just the models.
IDScan Breach Shows Why Scanned IDs Need an Expiration Date
IDScan confirmed unauthorized access to customer identity data after a dark-web service advertised more than 153 million driver’s-license records. The breach exposes a larger problem: ID-scanning systems can keep sensitive documents long after the check is finished.