“The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
“The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires the repository to arrive
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Check Point Research said it has tracked the campaign since mid-2025.
The modules
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The incident window ran from approximately August 28 at 20:57
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek.
