A study of 61,500 abandoned IoT apps found broken data flows, dead domains, and outdated libraries still exposing user data ...
MCP credential exposure puts API keys and access tokens at risk as hardcoded secrets remain in public GitHub configuration files.
Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, and more.
HYPR research shows how gaps in hiring and identity checks weaken fraud detection before new employees gain access to corporate systems.
Melapress's WordPress security survey of 319 pros finds 67.7% have had an incident, yet fewer than three in ten have a breach recovery plan.
Cisco confirmed attackers are hitting CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services ...
Google’s Agent Anomaly Detection monitors AI agents for suspicious behavior, policy violations, tool misuse, and operational ...
Intruders will eventually get a foothold, so the smart move is to place cyber decoys in the environment, CISA says in latest ...
Druva adds identity resilience and ransomware detection to validate threats, map attack impact, and guide clean cyber ...
A fake AI trading agent installs Needle Stealer, which swaps browser crypto wallets for fake copies that send wallet passwords to attackers.
On AI and open source, ACM authors warn coding tools add review work for maintainers while many projects lack reliable ...
Tuskira launches Vector, an autonomous red teaming agent that validates exploitable attack paths against real enterprise ...