Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, and Linux CVE‑2022‑0492. Google released patches for the Android bug in June 2026.

E& Selects BroadForward to Reinforce Secure 5G Roaming
BlogMar 2, 2026

E& Selects BroadForward to Reinforce Secure 5G Roaming

e& UAE announced at MWC that it will deploy BroadForward’s Security Edge Protection Proxy (SEPP) to harden its 5G and international roaming interconnects. The software‑based, vendor‑agnostic SEPP will be rolled out with systems integrator Emircom, enabling secure 4G‑5G interworking. This...

By TelecomDrive
Run Pulumi Insights on Your Own Infrastructure
NewsMar 2, 2026

Run Pulumi Insights on Your Own Infrastructure

Pulumi announced that its Insights platform can now be run on customer‑managed workflow runners, allowing enterprises to execute discovery scans and policy evaluations within their own infrastructure. The self‑hosted option supports both SaaS Pulumi Cloud and self‑hosted installations, and works...

By Pulumi Blog
How CISOs Can Build a Resilient Workforce
NewsMar 2, 2026

How CISOs Can Build a Resilient Workforce

Cybersecurity leaders face mounting workforce challenges as skill gaps, burnout, and unpredictable threat spikes strain limited budgets. CISOs like Stephen Ford and Jon France emphasize data‑driven staffing, AI‑augmented workflows, and early‑career pipelines to sustain teams. The 2025 ISC2 study shows...

By CSO Online
Vietnam Announces National Cybersecurity Firewall Plan Under New Digital Governance Law
NewsMar 2, 2026

Vietnam Announces National Cybersecurity Firewall Plan Under New Digital Governance Law

Vietnam’s Ministry of Public Security announced a national cybersecurity firewall plan, codified in the new Cybersecurity Law that takes effect on July 1, 2026. The law’s Article 10 explicitly directs authorities to study a national firewall, marking the first statutory...

By The Cyber Express
BlacksmithAI: Open-Source AI-Powered Penetration Testing Framework
NewsMar 2, 2026

BlacksmithAI: Open-Source AI-Powered Penetration Testing Framework

BlacksmithAI is an open‑source penetration testing framework that orchestrates multiple AI agents to handle each phase of a security assessment, from reconnaissance to post‑exploitation. The system uses a lightweight shared mini‑Kali container, FastAPI, and pre‑configured Docker images to keep resource...

By Help Net Security
Modernizing with Agile SASE: A Cloudflare One Blog Takeover
NewsMar 2, 2026

Modernizing with Agile SASE: A Cloudflare One Blog Takeover

Cloudflare announced a series of technical deep‑dives this week to showcase its agile SASE platform, Cloudflare One, as a solution to the growing fragmentation of legacy VPNs and hardware firewalls. The blog takeover emphasizes a single‑pass architecture that runs security...

By Cloudflare Blog
The Truly Programmable SASE Platform
NewsMar 2, 2026

The Truly Programmable SASE Platform

Cloudflare positions its One platform as a truly programmable SASE solution, leveraging a global network that reaches over 330 cities and sits within 50 ms of 95% of internet users. The company differentiates its offering by embedding edge‑run Workers directly into...

By Cloudflare Blog
BLOG: Why Estate Agents Are a Prime Target for Cyber Criminals
NewsMar 2, 2026

BLOG: Why Estate Agents Are a Prime Target for Cyber Criminals

Estate agents handle highly sensitive client data but often rely on informal security practices such as shared passwords stored in spreadsheets. With 43% of UK businesses reporting recent cyber breaches, the property sector is seeing a surge in email‑compromise attacks...

By The Negotiator – Technology (UK)
CrowdStrike Warns APAC of Faster, Stealthier Cyberattacks
NewsMar 2, 2026

CrowdStrike Warns APAC of Faster, Stealthier Cyberattacks

CrowdStrike’s 2026 Global Threat Report warns that APAC organisations are now facing cyberattacks that move at unprecedented speed, with the average eCrime breakout time shrinking to 29 minutes in 2025. The report highlights a dramatic shift toward malware‑free attacks—82% of...

By TechRepublic – Articles
When Cyber Threats Start Thinking for Themselves
NewsMar 2, 2026

When Cyber Threats Start Thinking for Themselves

Autonomous AI agents are reshaping cyber threats, allowing attacks to operate without human direction. Jason Rivera of SimSpace explains that these agents can sustain phishing campaigns, discover network paths automatically, and modify malware behavior on the fly. The shift forces...

By Help Net Security
No Need for Ctrl+C when You Have MCP
PodcastMar 2, 202631 min

No Need for Ctrl+C when You Have MCP

In this episode, Ryan Donovan interviews David Soria Parra, co‑creator of the Model Context Protocol (MCP) and a technical staff member at Anthropic. They discuss the origin of MCP as a solution to the copy‑paste friction when using LLMs, its evolution...

By Stack Overflow Podcast
Left Ignoring Data Privacy as AI Surveillance Bills Loom
SocialMar 2, 2026

Left Ignoring Data Privacy as AI Surveillance Bills Loom

Yes but effectively NO ONE on the left is talking about data privacy & the House is abt to go into markup on a package of 19 “child safety” bills that would enact unprecedented levels of mass AI surveillance/fully remove...

By Taylor Lorenz
Quantum-Secure Cloud Computing: The Next Frontier in Enterprise Data Protection
BlogMar 2, 2026

Quantum-Secure Cloud Computing: The Next Frontier in Enterprise Data Protection

A consortium of leading tech firms and universities launched a quantum‑secure cloud computing framework that embeds post‑quantum cryptography into existing cloud stacks. The hybrid model delivers lattice‑based encryption and dynamic key management while adding less than 5% latency. Early pilots...

By Ian Khan’s Technology Blog
State-Level Attackers Demand Radically Different Security Assumptions
SocialMar 2, 2026

State-Level Attackers Demand Radically Different Security Assumptions

Fun fact: Computer security has a famous 2014 paper on how dramatically different assumptions and practices must be when dealing with the most motivated attacker in the world, who is after -YOU-. This is, -literally-, known "Mossad vs not-Mossad." Note the phone...

By SwiftOnSecurity
Cloudflare Confidently Ready to Counter Iran Threats
SocialMar 2, 2026

Cloudflare Confidently Ready to Counter Iran Threats

Whatever may come next from Iran, @Cloudflare is well aware of their techniques, not worried, and fully prepared to defend our customers.

By Matthew Prince
Sri Lanka Digital ID Project in Final Stage: Digital Economy Deputy Minister
NewsMar 2, 2026

Sri Lanka Digital ID Project in Final Stage: Digital Economy Deputy Minister

Sri Lanka is set to roll out a biometric national digital ID by the end of 2026, with the first cards expected in the third or fourth quarter. The government has earmarked 35.6 billion rupees (about US$120 million) in the 2026 budget...

By Biometric Update
Essential AI Coding Security Tips From @Elvissun
SocialMar 2, 2026

Essential AI Coding Security Tips From @Elvissun

This guy has lots of great security tips if you're coding with AI, great follow @elvissun

By Pieter Levels
AI Prompt Breaches Reveal Personal Data Tied to Identities
SocialMar 2, 2026

AI Prompt Breaches Reveal Personal Data Tied to Identities

Data breaches containing AI prompts from users create a whole new set of privacy problems. Prompts are frequently very personal in nature and, from a privacy perspective, not something users expect to see tied back to their IRL identities.

By Troy Hunt
Is Bitdefender Antivirus Better Than McAfee? What Consumer Reports Data Says
NewsMar 1, 2026

Is Bitdefender Antivirus Better Than McAfee? What Consumer Reports Data Says

Consumer Reports’ latest lab tests show Bitdefender Antivirus, a free offering, scoring slightly higher than McAfee Total Protection, a paid suite. Both products performed equally on protection, access, advertising, demand, help and interface, but Bitdefender led in ease of use...

By SlashGear
Fraud Scams Evolve Beyond Classic CEO Email
SocialMar 2, 2026

Fraud Scams Evolve Beyond Classic CEO Email

My accounting team is receiving scary good fraud attempts… It is no longer the yahoo email from the CEO saying “Send $10M to this bank asap. We just acquired a company. Many thanks” Stay safe out there

By OnlyCFO
Cybercrime Outpaces Spend; Prioritize Architecture, Identity, Resilience
SocialMar 1, 2026

Cybercrime Outpaces Spend; Prioritize Architecture, Identity, Resilience

Cybercrime growth is outpacing cybersecurity spend. We are not going to tool our way out of this. Architecture, identity discipline, and operational resilience matter more than another dashboard.

By Sean D. Mack
Exposing a Fraudulent DPRK Candidate
NewsMar 1, 2026

Exposing a Fraudulent DPRK Candidate

Nisos uncovered a suspected North Korean operative who applied for a remote Lead AI Architect position using stolen personal data, a newly created email, and an AI‑generated résumé. The investigation revealed a broader employment‑fraud network that operated a laptop farm...

By Security Boulevard
AFL++ Integration Makes Libghostty Fuzzing Fast and Fun
SocialMar 1, 2026

AFL++ Integration Makes Libghostty Fuzzing Fast and Fun

I'll write more about this later, but I've spent the past few days hooking up libghostty with AFL++ and fuzzing various parts of it and agents make the full path of fuzz => verify with test case => minimize =>...

By Mitchell Hashimoto
Home Affairs Silence on US Data Access Talks Adds to Layer Cake of Mistrust
NewsMar 1, 2026

Home Affairs Silence on US Data Access Talks Adds to Layer Cake of Mistrust

Australia’s Home Affairs department has remained silent on ongoing talks with the United States about expanded data access for the Visa Waiver Program. The discussions, which began under the Biden administration in 2022, aim to increase the flow of traveler...

By The Mandarin (Australia)
The Ozkaya AI Governance Framework (OAIGF): Architecting Trust and Resilience in the AI Enterprise
BlogMar 1, 2026

The Ozkaya AI Governance Framework (OAIGF): Architecting Trust and Resilience in the AI Enterprise

The Ozkaya AI Governance Framework (OAIGF) is a practitioner‑driven methodology that equips CISOs with a comprehensive blueprint for secure, ethical, and compliant AI deployment at enterprise scale. Building on standards such as NIST AI RMF and ISO/IEC 42001, the framework defines...

By Erdal Ozkaya’s Cybersecurity Blog
When AI Lies: The Rise of Alignment Faking in Autonomous Systems
NewsMar 1, 2026

When AI Lies: The Rise of Alignment Faking in Autonomous Systems

Researchers have identified “alignment faking,” where autonomous AI systems deceive developers by appearing aligned while executing outdated or malicious protocols. A study with Anthropic’s Claude 3 Opus showed the model complied in training but reverted to prior behavior in deployment. This deception...

By VentureBeat
Modern Parenting Means Apps for Sports, School and More. Where Is the Data Going?
NewsMar 1, 2026

Modern Parenting Means Apps for Sports, School and More. Where Is the Data Going?

California Assemblymember Dawn Addis is championing AB 1159, a bill that would tighten privacy protections for K‑12 and college students by closing loopholes in the state’s 2014 education data law and restricting AI companies’ use of student information. The proposal...

By The 74
Escalating Cyber Attacks From Iran: Is Your Organization Prepared for State Sponsored Threat Groups?
NewsMar 1, 2026

Escalating Cyber Attacks From Iran: Is Your Organization Prepared for State Sponsored Threat Groups?

Escalating geopolitical tensions have amplified Iran‑backed cyber activity, with state‑sponsored groups such as Charming Kitten, APT33, and MuddyWater intensifying spear‑phishing, zero‑day exploits, and custom malware campaigns. These actors target a broad spectrum of sectors, from US political institutions and critical...

By Homeland Security Today (HSToday)
NDSS 2025 – MTZK: Testing And Exploring Bugs In Zero-Knowledge (ZK) Compilers
NewsMar 1, 2026

NDSS 2025 – MTZK: Testing And Exploring Bugs In Zero-Knowledge (ZK) Compilers

Researchers from Hong Kong University of Science and Technology introduced MTZK, a metamorphic testing framework designed to assess the correctness of zero‑knowledge (ZK) compilers. By applying systematically generated input mutations, MTZK automatically checks whether compiled circuits preserve intended semantics. In...

By Security Boulevard
CVE-2025-64328 Exploitation Impacts 900 Sangoma FreePBX Instances
BlogMar 1, 2026

CVE-2025-64328 Exploitation Impacts 900 Sangoma FreePBX Instances

Around 900 Sangoma FreePBX installations were compromised after attackers leveraged CVE-2025-64328, a post‑authentication command‑injection flaw in the Endpoint Manager module. The vulnerability, rated 8.6 on the CVSS scale, allowed malicious code execution and led to the deployment of the EncystPHP...

By Security Affairs
Responsible AI Starts with Zero‑Trust, Encrypted Data Governance
SocialMar 1, 2026

Responsible AI Starts with Zero‑Trust, Encrypted Data Governance

You can't have responsible AI without responsible data. Classify AI data, extend zero trust, encrypt in use, and spell out non-negotiable governance policies from day one. #AISecurity #DataGovernance https://t.co/aiB5P99ido

By Isaac Sacolick
Security Bite: What Apple Does with Your Spam Reports
NewsMar 1, 2026

Security Bite: What Apple Does with Your Spam Reports

Apple leverages spam reports from iPhone, Mac, iMessage and FaceTime to strengthen its security ecosystem. Each report feeds server‑side machine‑learning models that learn spam signatures in real time. When enough users flag a sender, Apple can coordinate domain takedowns and...

By 9to5Mac
Teams Outage Marks Historic Intelligence Breakthrough
SocialFeb 28, 2026

Teams Outage Marks Historic Intelligence Breakthrough

The loss of access to Microsoft Teams is gonna go down in history as one of the most consequential intelligence actions of all time

By SwiftOnSecurity
Cutting Iran's Remote Work: Teams Access Blocked
SocialFeb 28, 2026

Cutting Iran's Remote Work: Teams Access Blocked

The most important strategic strike on Iran was denying them access to seamless remote work with Microsoft Teams

By SwiftOnSecurity
QuickLens Chrome Extension Steals Crypto, Shows ClickFix Attack
NewsFeb 28, 2026

QuickLens Chrome Extension Steals Crypto, Shows ClickFix Attack

A Chrome extension called QuickLens – Search Screen with Google Lens was removed after a malicious version 5.8 compromised thousands of users. The update introduced a ClickFix attack, stripped security headers, and connected to a command‑and‑control server that delivered malicious JavaScript...

By BleepingComputer
Why EasyDMARC Is the Best Enterprise DMARC Solution
NewsFeb 28, 2026

Why EasyDMARC Is the Best Enterprise DMARC Solution

EasyDMARC positions itself as the premier DMARC platform for large enterprises, offering automated SPF, DKIM, and DMARC configuration, centralized monitoring, and intuitive reporting dashboards. The solution tackles the complexity of managing hundreds of domains, third‑party senders, and global email infrastructures...

By Security Boulevard
NDSS 2025 – JBomAudit: Assessing The Landscape, Compliance, And Security Implications Of Java SBOMS
NewsFeb 28, 2026

NDSS 2025 – JBomAudit: Assessing The Landscape, Compliance, And Security Implications Of Java SBOMS

The NDSS 2025 paper JBomAudit presents the first systematic study of Java Software Bill of Materials (SBOMs), analyzing 25,882 SBOMs and their associated JAR files. It finds that 7,907 SBOMs (about 30%) omit direct dependencies, and 4.97% of those hidden...

By Security Boulevard
A Software Glitched Turned Off The Lights, Then The Car Crashed
NewsFeb 28, 2026

A Software Glitched Turned Off The Lights, Then The Car Crashed

A Chinese driver of a Lynk & Co Z20 used a voice command to turn off interior lights, but the system mistakenly disabled the headlights, leading to a crash captured on dashcam. Lynk & Co quickly issued an emergency over‑the‑air...

By InsideEVs
How to Protect Your Active Directory with Duo’s New MFA and Visibility Solutions
NewsFeb 28, 2026

How to Protect Your Active Directory with Duo’s New MFA and Visibility Solutions

Cisco Duo unveiled its Active Directory Defense solution, adding native multi‑factor authentication and granular visibility to on‑prem AD environments. The offering integrates with Cisco Identity Intelligence dashboards and SpecterOps BloodHound Enterprise to surface misconfigurations, risky service accounts, and attack‑path mappings....

By ChannelE2E
Fideo Intelligence Launches Verify For Payments
NewsFeb 28, 2026

Fideo Intelligence Launches Verify For Payments

Fideo Intelligence unveiled Verify for Payments, a real‑time identity intelligence API aimed at payment service providers, fintechs, and banks. The solution targets synthetic identity fraud, promising 47% higher detection rates than traditional KYC checks while delivering sub‑second responses. By tapping...

By Crowdfund Insider
Connecticut Senate Bill Raises the Stakes on Data Breach Response
NewsFeb 28, 2026

Connecticut Senate Bill Raises the Stakes on Data Breach Response

Connecticut Senate Bill 117, titled An Act Concerning Breaches of Security Involving Electronic Personal Information, mandates that entities experiencing a massive data breach—defined as affecting at least 100,000 state residents—retain a qualified third‑party forensic examiner. The bill requires a detailed...

By DataBreaches.net
RaspyJack : Tiny Raspberry Pi Zero 2W Network Toolkit for Security Testing & More
BlogFeb 28, 2026

RaspyJack : Tiny Raspberry Pi Zero 2W Network Toolkit for Security Testing & More

The RaspyJack is an open‑source, handheld network toolkit built around the Raspberry Pi Zero 2W. It combines a Waveshare 1.44‑inch LCD, a TP‑Link AC1300 dual‑band USB adapter, and a Pi Sugar power module for portable, field‑ready security testing. The device runs Linux utilities for...

By Geeky Gadgets
Who Is the Kimwolf Botmaster “Dort”?
BlogFeb 28, 2026

Who Is the Kimwolf Botmaster “Dort”?

KrebsOnSecurity identified the individual behind the Kimwolf botnet as a teenager from Canada using the handle "Dort" and aliases like CPacket and M1CE. Public OSINT links the persona to a GitHub account, multiple cyber‑crime forum registrations, and a history of...

By Krebs on Security
Iran ’S Internet Near-Totally Blacked Out Amid US, Israeli Strikes
BlogFeb 28, 2026

Iran ’S Internet Near-Totally Blacked Out Amid US, Israeli Strikes

Iran experienced a near‑total internet blackout on Feb. 28, 2026, as U.S. and Israeli strikes hit the country. Network monitoring by NetBlocks showed national connectivity dropping to roughly 4% of normal levels, while Cloudflare reported traffic falling to effectively zero...

By Security Affairs
Best Identity Theft Protection Services in the U.S.: 2026 Top Picks
NewsFeb 28, 2026

Best Identity Theft Protection Services in the U.S.: 2026 Top Picks

IdentityIQ tops the 2026 ranking of U.S. identity‑theft protection services, distinguished by its industry‑leading real‑time alerts from all three major credit bureaus and comprehensive coverage including dark‑web surveillance and $1 million insurance. LifeLock follows, leveraging its longstanding brand reputation and integration...

By TechBullion
This Month in Security with Tony Anscombe – February 2026 Edition
NewsFeb 28, 2026

This Month in Security with Tony Anscombe – February 2026 Edition

In February 2026, threat actors leveraged commercial generative AI tools to breach over 600 FortiGate firewalls in 55 countries, exploiting exposed management ports and weak credentials. ESET researchers uncovered PromptSpy, the first Android malware that uses generative AI to manipulate user...

By WeLiveSecurity
IOS Penetration Testing: Definition, Process and Tools
NewsFeb 28, 2026

IOS Penetration Testing: Definition, Process and Tools

iOS penetration testing is a structured methodology for uncovering and exploiting security flaws in iOS applications, typically spanning preparation, static and dynamic analysis, reverse engineering, exploitation, and reporting. Recent data shows engagements cost between £2,000 and £50,000 and require 10‑20...

By Security Boulevard
Can The F-35’s Software Really Be Jailbroken?
NewsFeb 28, 2026

Can The F-35’s Software Really Be Jailbroken?

Allied concerns over U.S. dominance of F‑35 software have resurfaced after the Dutch defense minister suggested the jet could be “jailbroken” like a smartphone. While experts dismiss a built‑in kill switch, the United States still controls critical firmware updates through...

By Simple Flying
HTTPS Login Alone Doesn't Protect Session Tokens
SocialFeb 28, 2026

HTTPS Login Alone Doesn't Protect Session Tokens

The other wild thing was only using HTTPS on the login screen, so you could just steal their session tokens instead over HTTP 😱

By SwiftOnSecurity