Kiteworks expands runtime data governance with Bonfy.AI acquisition

Kiteworks has acquired Bonfy.AI to integrate runtime data governance directly into its core security control plane. The acquisition allows organizations to govern data exchanges at the exact moment they happen, regardless of... Read more »

IDScan Confirms Data Breach Following Leak of 153 Million Driver’s Licenses on Dark Web

Identity verification firm IDScan.net has confirmed that unauthorized actors accessed customer data hosted on its cloud platform, following reports that over 153 million scanned driver’s licenses appeared on a dark web marketplace.... Read more »

AI Agents Exploited PaperCut Vulnerabilities to Breach 395 Organizations Worldwide

Autonomous AI-driven cyberattack campaign compromises at least 440 PaperCut instances across 48 countries using newly disclosed print management software vulnerabilities. Security researchers at GreyNoise have uncovered an automated attack campaign where autonomous... Read more »

Android now supports direct credential and passkey transfers between password managers

Google has rolled out a new credential transfer capability on Android that enables users to migrate passwords and passkeys directly between supported password managers without relying on insecure export files. The feature... Read more »

Attackers target employees’ personal phones in sophisticated Microsoft 365 cloud compromise campaign

Threat actors are executing a social engineering campaign targeting employees on unmanaged personal phones to compromise Microsoft 365 cloud environments and extract sensitive enterprise data. Tracked by researchers since May 2026, the... Read more »

Cisco FMC Bugs Exploited by Nation-State and Ransomware Operators

State-sponsored groups and ransomware operators are actively exploiting critical vulnerabilities within Cisco Secure Firewall Management Center software. Cisco Talos threat intelligence analysts have confirmed active exploitation targeting two distinct security flaws in... Read more »

Mars Security Launches Real-Time Threat Intelligence Detection Automation

Mars Security has introduced Real-Time Intel-Based Detection, an enterprise security platform designed to automatically convert threat advisories into validated production rules within minutes. The newly unveiled capability translates intelligence reports from sources... Read more »

Threat actors are giving AI agents a bigger role in cyberattacks

According to the Google Threat Intelligence Group Q3 2026 AI Threat Tracker, cybercriminals are increasingly deploying autonomous AI agents to automate reconnaissance, credential harvesting, and vulnerability scanning with minimal human intervention. During... Read more »

Zero-Click WeChat Worm Exposes Vulnerability in VoIP Stack

Researchers have weaponized a zero-click vulnerability in WeChat to create a self-propagating worm capable of hijacking user accounts and spreading via incoming VoIP calls. Security researchers at Calif uncovered the vulnerability within... Read more »

Microsoft Warns of Phishing Campaigns Using Invisible Unicode Characters for Filter Evasion

Threat actors are leveraging ASCII smuggling techniques and invisible Unicode characters from the Tags block (U+E0000–U+E007F) to bypass email security filters in ongoing finance-themed phishing operations. Microsoft threat researchers uncovered a high-volume... Read more »