GeoServer has shipped emergency releases for a critical SQL injection flaw that its own maintainers describe as a regression of a vulnerability fixed in 2023. The flaw was disclosed publicly on X on 12 August with no vendor coordination, drew scanning within hours, and was patched on 14 August. It still has no CVE identifier, […]
Read MoreKey takeaways The research released around Black Hat USA 2026 agrees on one thing: AI has compressed attacker timelines, but the way intruders get in has not changed. Phishing was the initial access method in more than half of Cisco Talos incident response engagements last quarter, and authentication abuse appeared in 65 percent of them. […]
Read MoreNVIDIA and 36 other companies launched the Open Secure AI Alliance on 27 July 2026, a coalition to build and share open tools for securing AI agents. Founding members include Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Red Hat, Hugging Face and the Linux Foundation. The group released its first open-source project at launch […]
Read MoreErnst & Young (EY), one of the Big Four accounting and advisory firms, is notifying clients of a data breach after an unauthorised party accessed a third-party IT support platform its staff use and downloaded documents. The breach centres not on EY’s audit systems but on a support-ticket tool, where client tax documents had been […]
Read More