FBI Warns Russian Intelligence Is Phishing Signal Users for Backup Recovery Keys
The FBI and CISA have issued an updated warning that Russian intelligence services are actively targeting Signal users through sophisticated phishing campaigns aimed at stealing backup recovery keys. The advisory,…
Linux Kernel Pedit COW Exploit (CVE-2026-46331) Grants Root via Page Cache Corruption
A critical privilege escalation vulnerability in the Linux kernel’s traffic control subsystem, tracked as CVE-2026-46331 and dubbed “Pedit COW,” allows any unprivileged local user to gain root access on affected…
KDDI Breach Exposes Up to 14.2 Million Email Credentials Across Six Japanese ISPs
Japanese telecommunications giant KDDI Corporation has disclosed a data breach impacting an email system it operates for six internet service providers, potentially exposing up to 14.22 million email addresses and…
BreachRx Launches Rex Platform — An Agentic AI Incident Command Center for Simultaneous Breach Response
Summary BreachRx has launched the Rex Platform, an agentic AI incident command center designed to handle multiple simultaneous breaches — a scenario the company argues is now the norm in…
Study Finds 10 of 12 Agentic Red Team Tools Vulnerable to Sandbox Escape and Full Host Compromise
Summary A peer-reviewed security audit by researchers at Cracken has revealed that the vast majority of popular agentic offensive security platforms are themselves critically insecure. The study, published June 23,…
DragonForce Ransomware Gang Hides C2 Traffic Inside Microsoft Teams Relay Infrastructure Using Novel Backdoor.Turn RAT
Summary Researchers at Broadcom’s Symantec and Carbon Black have uncovered a sophisticated new technique used by the DragonForce ransomware group: hiding command-and-control communications inside Microsoft Teams relay infrastructure. The custom…
Linux Foundation Launches Akrites — A Unified Vulnerability Response Framework Backed by AWS, Google, Microsoft, and OpenAI
Summary The Linux Foundation has officially launched Akrites, a new industry-wide initiative to defend critical open-source software against AI-enabled cyber threats. The framework establishes a shared Security Incident Response Team…
OpenAI and Broadcom Unveil Jalapeño — A Custom LLM Inference Chip Designed to Slash AI Costs by 50%
Summary OpenAI and Broadcom have unveiled Jalapeño, OpenAI’s first custom-designed “Intelligence Processor” — an inference accelerator built from scratch specifically for large language model workloads. The chip went from initial…
15 Malicious JetBrains Plugins Caught Stealing AI API Keys — 70,000 Developers Exposed in 8-Month Campaign
Summary Security researchers at Aikido discovered a coordinated supply chain campaign involving 15 malicious plugins on the JetBrains Marketplace, all designed to steal AI provider API keys from developers. The…
NAIC Confirms PeopleSoft Breach — ShinyHunters Exploit Critical Oracle RCE to Hit 100+ Organizations
Summary The National Association of Insurance Commissioners (NAIC) has confirmed a significant cyberattack on its Oracle PeopleSoft systems, exposing portions of its data infrastructure. The breach, attributed to the prolific…
