Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurit…
Critical incident activity dominated the week, some notable market / M&A positioning. Source-linked below.
Breach Reports & Threat Intel
5Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and inst…
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.
Command injection vulns land on exploited list after researchers spot abuse attempts
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials …
AI Security & Governance
4CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception.
On Favicons: From Browser Icons to Attack Surface Intelligence
OpenAI launches the ChatGPT for Small Businesses program, helping entrepreneurs build AI skills, automate work, and grow with ChatGPT Work.
Cloud Security
3Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137).
TL;DR Most of the vulnerabilities in a container environment will never be exploited, the hard part is knowing which ones will.
Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA cod…
AppSec & Technical Deep-Dives
3Today, I loaded the 1,000th data breach into Have I Been Pwned.
NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source.
Why we’re launching the program What it means to be a Burp Ambassador What we’re aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3ri…
Market Moves & M&A
1Drawing on more than a decade spent helping build some of the world's most influential AI systems, including research that later informed the development of ChatGPT, A…
Tools & Open Source
7Open-source XDR/SIEM for threat detection and compliance.
Relevance: Detection & response / compliance
Template-based vulnerability scanner for massive-scale network scanning.
Relevance: Offensive security & recon
Comprehensive scanner for containers, IaC, and dependencies.
Relevance: Cloud & container defenders
Interactive TLS-capable intercepting proxy for traffic analysis.
Relevance: AppSec & traffic inspection
Swiss-army toolkit for network attacks, MITM and recon.
Relevance: Network penetration testing
Passive subdomain enumeration from dozens of sources.
Relevance: Recon & attack-surface mapping
Graph-based Active Directory relationship explorer for attack paths.
Relevance: Red teams & AD assessment
X Trending — Security
5A random YouTube video introduced Ayo to cybersecurity. Now he’s learning ethical hacking, reconnaissance, vulnerability scanning, and network security. The journey from curiosity to career starts with taking the first step. Your future in tech could start today https://t.co/7qOxUqlcpA
Cybercriminals have hijacked over 20 Brazilian government websites in the PhantomEnigma campaign, distributing malware through trusted domains. This sophisticated attack targets banking and public-sector organizations, exploiting legitimate email accounts to bypass security https://t.co/wSLp25eomo
Account Takeover: Protecting Customer Logins on Your Store: Understanding the Threat of Account Takeover In today’s digital commerce landscape, the security of customer accounts is… https://t.co/ahVoWeECxy #AccountTakeover #CyberSecurity #OnlineSafety #FraudPrevention #Ecommerce https://t.co/Zn3hI1xisu
Cruciferra, a sophisticated crypter service, allows cybercriminals to bypass Windows security measures and deploy malware undetected. Utilizing advanced evasion techniques like DLL side-loading and Process Ghosting, it delivers RATs and info stealers such as AsyncRAT and Agent https://t.co/XxCoJJ8Vrh
If this has happened to you, report it at https://t.co/Eg55f4OeIe. #FraudPrevention #ScamAwareness #Cybersecurity #ConsumerProtection
X Security Memes
2Funny how fast the conversation changed. now is about whether people should be allowed to use 🇨🇳 Chinese AI models at all. 🇺🇸 Trump administration is reportedly considering new restrictions on Chinese AI labs, potentially limiting the use of models like Kimi K3 and DeepSeek by https://t.co/QEyCC7oVP9 https://t.co/NubYDzlhHo
Do you guys like the cybersecurity posts or na? I'm attempting to make the nerdy stuff interesting lol.