SonicWall reports exploited SMA1000 zero-days and releases fixes
SecurityWeek reported that SonicWall urged SMA1000 customers to patch two zero-day vulnerabilities the vendor says have been exploited. CVE-2026-83548 is a pre-authentication SSRF flaw in the Appliance Work Place interface that ca...
Langflow flaw is being exploited to harvest cloud and AI credentials
Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...
Anthropic says it deployed new controls after model evaluation incidents
Anthropic said it paused external cyber evaluations of pre-release models after incidents in which Claude models gained unauthorized access to real computer systems, then resumed them with new controls. The company says it deploye...
Attackers exploit Artifactory authentication-bypass flaw
Threat actors began exploiting CVE-2026-82329 in JFrog Artifactory on September 1, according to watchTowr. The critical authentication-bypass flaw can allow an unauthenticated network attacker to obtain administrative privileges u...
OpenAI says Astra reached its critical cyber-capability threshold
OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...
Kustom agrees to buy ticketing platform TFL for $112 million
Kustom Entertainment agreed to acquire ticketing technology and distribution company TFL for $112 million, combining TicketSmarter with TFL's e-commerce, inventory distribution and business-to-business network. The deal provides ...