
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it alongCybersecurity intelligence, threat analysis, and national security reporting.

In a groundbreaking move, North Korean hackers have exploited the Terraform Registry to spread Go-based malware, marking the first time threat actors have used this centralized repository as a distribution vector for malicious payloads. This alarming development was uncovered by security firm Aikido, which identified several malicious Terraform providers and Go modules published to public registries.

Hackers have been actively exploiting two major flaws in Check Point VPNs, including one that allowed for remote code execution and another that enabled script execution, putting customers at risk. The attacks, which began as early as July 23, have now been confirmed by the cybersecurity company itself.

GitLab has a security flaw that exposes a private email token, allowing unauthorized users to push code changes to projects - essentially giving anyone carte blanche to act on your behalf. This token, tied to your account, doesn't expire and grants access to all projects you have permission to open.

A critical zero-day vulnerability in F5 BIG-IP APM is under active attack, putting organizations at risk of remote code execution - and it's essential to take immediate action to protect yourself. This unpatched flaw is being exploited by attackers, making it crucial to act now to safeguard your systems.

Less than five hours after WordPress released a patch for a critical vulnerability, hackers began exploiting the flaw, known as CVE-2026-87902, to execute remote code. This lightning-fast attack highlights the importance of swift updates to protect your site.

To prioritize safety, Spokane Public Schools swiftly took their online systems offline after detecting a network security breach, following established crisis protocols to assess the situation. The district is now working diligently to understand the scope of the incident and minimize its impact.

The US is taking a proactive approach to artificial intelligence, aiming to not only harness its potential but also mitigate risks and maintain a strategic advantage. Recent incidents, including Google's Gemini model's unauthorized access to companies during testing, highlight the pressing need for effective AI management.

NASA is revving up its X-plane ambitions, with Administrator Jared Isaacman teasing a radical new design that echoes the legendary SR-71 Blackbird. The surprise reveal has sparked intense curiosity about the future of high-speed flight.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
A recent gathering of around 200 global thought leaders in Ankara issued a stark warning: the US and Israel are sowing the seeds of a potential Great War, citing aggressive actions like the US-Israeli attack on Iran and Israel's genocide in Gaza. These flashpoints have raised the stakes, prompting urgent calls for a united front to prevent catastrophe.

A Royal Air Force Hawk T2 training jet crashed in a rural area of Anglesey, North Wales, on Wednesday, prompting an investigation after the crew safely ejected from the aircraft. The incident occurred near RAF Valley, a base that hosts fast-jet pilot training, with video footage showing the plane descending into open ground with no reports of wider damage or casualties.

In a powerful move to safeguard national stability, OpenAI is joining forces with Ukraine to deploy cutting-edge AI-powered cybersecurity tools, with a staggering $1 billion pledge to support the initiative. This game-changing partnership is set to bolster Ukraine's defenses, ensuring the country's critical systems stay online and its people protected.

Hackers are exploiting two critical flaws in MikroTik routers, allowing them to gain full control of internet-exposed devices even before patches were available. The "MikroTrick" chain, which combines two vulnerabilities, lets attackers open a privileged console without needing login credentials.

In a massive heist, over 600,000 valid credit card details were stolen from online retailers using open-source AI agent frameworks to compromise at least 119 websites and deliver skimmer malware at scale. The alarming campaign, active since July, saw a concentrated burst of 105 attack waves in just five days, targeting major companies and leaving a trail of digital devastation.

Ukraine's 7th Artillery Brigade is ditching high-tech guided shells for good old-fashioned unguided rounds - and finding accuracy in an unlikely partnership with FPV drones. By shifting the accuracy burden to the gun itself and leveraging drone tech, they're redefining what's possible with traditional artillery.
The National Reconnaissance Office Director emphasizes that leveraging AI is crucial to maintaining the US space-based intelligence advantage, enabling enhanced monitoring of adversary activity and timely intelligence delivery. AI is no longer a choice, but an operational imperative to streamline workflows and unlock insights from the vast amounts of satellite imagery and geospatial data.
A shocking security breach revealed that a Flock Safety camera, meant to enhance public safety, was hacked, exposing a treasure trove of sensitive data, including 1.6 million images and 50,200 vehicle logs collected over just three weeks. The alarming hack highlights the dark side of surveillance technology and the importance of robust security measures.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Students trying to access Elsevier's website were shocked to find themselves redirected to a notorious hacking group's leak page, sparking concerns over a possible security breach. The incident was quickly contained, but not before some users shared their alarming experiences on social media.

The harsh reality is that most organizations are flying blind, with 82% reporting visibility gaps and 96% struggling to pinpoint the root cause of incidents due to incomplete data. Despite using industry-standard observability tools, enterprises are failing to get the insights they need to stay ahead of cyber threats and ensure smooth operations.

Meet CLOSEDQUORUM, a sneaky Windows implant that outsources its decisions to commercial AI services like DeepSeek and Google Gemini, allowing it to adapt and evolve its attacks in real-time. This clever malware sends a snapshot of its host environment to multiple AI models, then executes the action that gets the most votes.

A staggering 474 GitHub App keys remain active, granting hackers persistent access to sensitive data, even after being publicly leaked. These compromised keys, which never expire, put users at risk of long-term unauthorized access.

The notorious cybercriminal group ShinyHunters claims to have hacked the FBI, exposing sensitive employee data, including names, addresses, and phone numbers, in retaliation for a report they say misrepresented their activities. The breach was allegedly achieved by exploiting a zero-day vulnerability in Oracle PeopleSoft.

In a recent surge of cyber threats, 158 security advisories were issued across 17 vendors, exposing 1,699 vulnerabilities, including 42 critical flaws that could be exploited remotely. This alarming trend highlights the growing risk to network management systems, with some vulnerabilities already added to the government's catalog of known threats.

Meet x47.c, a sneaky Windows botnet that's draining AI credits with 18 clever attack methods, targeting paid AI service accounts like OpenAI and xAI by sending repeated billable requests. This malicious tool is even being sold on the darknet marketplace WraithTools, with packages starting from just $200.

Beware: compromised MemTensor packages on npm and PyPI are spreading a sneaky credential stealer called sckit, which can steal your sensitive info. Malicious actors have hijacked these packages to secretly install the sckit malware, putting your credentials at risk.