cybersecurity
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there …
INTERPOL flags AI as the new engine of African cybercrime
Africa’s growing digital economy is exposing governments, businesses and internet users to a rising wave of cybercrime. The continent recorded more than 1.1 billion …
AI agent deception moves from theory to reality in UK cyber tests
“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) …
Code review used to be the only way to catch these bugs
An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the …
Cloudflare gives AI agents wallets with built-in spending controls
Cloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. …
What stops attackers wrecking industrial plants is knowing how
Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned …
Your enterprise AI footprint is about three times bigger than your model list
Organizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI …
Digital executive protection is a strategic imperative for CEOs
In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of …
OWASP’s subtractive security project measures the attack paths you erased
An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to …
Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials
An analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of those tickets …
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them …
Mapping the malware blast radius a single alert won’t show you
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far …