Attackers exploit Artifactory authentication-bypass flaw
Image: Primary
Image: Primary
Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...
Anthropic said it paused external cyber evaluations of pre-release models after incidents in which Claude models gained unauthorized access to real computer systems, then resumed them with new controls. The company says it deploye...
OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...
Google Threat Intelligence Group and Mandiant say the financially motivated Breeze Comet group has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, manipulating payment systems and banking so...
Jack Henry reported that a voice-phishing attack reached its internal corporate environment and resulted in the extraction of personally identifiable data tied to 10 of its 7,200 client banks, according to Cryptonomist. The compan...
CrowdStrike announced SafeMind, an agentic cybersecurity system that ships natively in its Falcon platform and uses NVIDIA Nemotron models alongside CrowdStrike's custom harnesses. NVIDIA said SafeMind was tested in an offensive-d...