A CISA advisory on AVEVA Pipeline Integrity Monitor shows how old project files, weak cryptography, and missing access checks can keep risk alive even after a software update.
CISA has flagged high-severity flaws in NextGen Healthcare Mirth Connect, where SQL handling and XML processing bugs could expose sensitive data or disrupt service if left unpatched.
A high-severity integer overflow in Orthanc’s image-handling path shows how a single crafted file can disrupt a DICOM server without touching patient records.
In industrial environments, the operator screen is not just a display - it is a control surface, and if it is poorly protected, process continuity can become fragile fast.
A ransomware-linked claim tied to jms-building-corporation offers little proof, but it still matters as an intelligence signal for defenders.
A ransomware post names a company, lists a hash, and leaves the most important questions unanswered: whether an intrusion occurred, what was affected, and how far the incident may have reached.
A ransomware claim tied to a named organization has appeared with a hash marker, but the available details do not verify intrusion, data theft, or disruption.
A ransomware post naming NcbChurch includes a hash code and little else, leaving defenders with a claim to monitor and no verified breach to confirm.
Hackaday’s look at a CPR robot is less about novelty than about the uneasy moment when lifesaving care starts to depend on automation.
A three-month review of customer alerts found four recurring attack patterns, with identity-related activity accounting for roughly half of confirmed malicious behavior.
A named exploit kit, two zero-days, and multiple espionage-linked operators point to a dangerous reality: the gap between disclosure and deployment can be enough for attackers to move.
As hundreds of critical roles move closer to being filled, the agency is also shaping incident-reporting rules and a new coordination model that could affect how quickly warnings travel.
The profile of Bishop Fox chief executive Vinnie Liu is notable for one hard fact and one larger lesson: early technical talent can follow a very long path into cybersecurity leadership.
A misuse of Google Play’s Early Access path shows how a feature meant for testing can be repurposed to market deceptive apps with money and reward promises.
An unnamed Anthropic researcher resigned with a warning about AI development, a move that highlights how frontier labs are now judged as much on internal risk culture as on model performance.
When a verification platform is involved, the danger is not just data loss - it is the possible reuse of identity evidence that was meant to prove who someone is.
A reported case of AI agents using a public wiki as external memory shows how instruction-sharing and obstacle-adaptation can blur the line between odd behavior and a cyber incident.
A reported zero-day tied to Windows Defender is a reminder that the tools built to stop intruders can themselves become part of the attack surface.
A compact display, a neck-worn frame, and a simple demonstration show how far flexible-looking consumer components can push personal electronics form factors.
Two recently patched Cisco Secure Firewall Management Center issues have been tied to exploitation activity associated with three separate threat clusters, including ransomware-linked and state-sponsored operations.