“In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek.
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities.
The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek.
US and Allies Update SBOM Guidance
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.
The post US and Allies Update SBOM Guidance appeared first on SecurityWeek.
Chrome 151 Patches 370 Vulnerabilities
The major browser update resolves roughly 80 critical- and high-severity security defects.
The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The activity, which began on July 22, 2026, involves the
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use
Cisco Secure FMC Zero-Day Exploited in the Wild
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek.
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
The original Aikido and Wiz reports did not attribute the
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
