Microsoft says vulnerability weaponization now takes well below 24 hours
Microsoft says the median time between vulnerability discovery in the wild and weaponization has fallen well below 24 hours, narrowing organizations' window to patch exposed systems. Its 2026 Digital Defense Report says attackers ...
SharePoint attacks spread Warlock ransomware across essential-service networks
A threat actor exploiting Microsoft SharePoint Server compromised at least four organizations over the past two months, including a water utility and a telecommunications provider, according to Symantec research reported by Cybers...
Oregon DOJ reviews McMinnville breach notification timeline
The Oregon Department of Justice is reviewing McMinnville's data breach and notification timeline, KPTV reported. The city sent formal notices on September 29 after detecting unusual network activity on or about July 15. Its inves...
Pentagon notifies millions of exposed personal data
The Pentagon's Defense Manpower Data Center is notifying people that unauthorized users accessed files containing unencrypted personal information. The breach affects 2.76 million living individuals and 294,000 deceased individual...
Kiteworks patches flaw allowing remote takeover of email gateway
Kiteworks released updates addressing 126 vulnerabilities, including a maximum-severity flaw that can let unauthenticated remote attackers take over its Email Protection Gateway. Tracked as CVE-2026-54154, the flaw affects every g...
AWS releases Strands Decider 2B for local workflow decisions
Amazon Web Services released Strands Decider 2B, an open-source model available now that selects among predefined options and returns confidence scores, TechCrunch reported. The model is small enough to run locally and targets wor...
