
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentCybersecurity intelligence, threat analysis, and national security reporting.

Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

The Financial Stability Board warns that AI-powered cyberattacks could spark a chain reaction of chaos in global markets, exploiting vulnerabilities in sovereign debt, private credit, and asset valuations. This threat is more than just a tech issue - it's a potentially disastrous blow to market confidence.

The rise of AI is revolutionizing cybersecurity, creating a blank canvas for women to chart new career paths and make their mark in this rapidly evolving field. With AI shaking up the defender-attacker dynamic, new role definitions and threat approaches are emerging, offering a fresh opportunity for women to reskill and thrive.

A single vulnerable third-party application can spark a national patient data crisis, as seen in the recent McKesson breach, where a third-party integration led to a massive data exfiltration claim of 284 million records.

Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

In a shocking security breach, threat actors made off with a whopping $600,000 in AI credits after exploiting a stolen API key from AI safety research group METR over just three weeks. The incident began with a researcher inadvertently leaving a public EC2 instance exposed, despite Google authentication, due to a fail-open flaw and a "vibe-coded" app storing a sensitive API key.

More than one in five organizations have fallen victim to AI-powered attacks, with 22% reporting a security incident in the past year where hackers used artificial intelligence to breach critical business platforms. This alarming trend highlights the urgent need for cybersecurity leaders to address the growing AI trust gap.

Rest assured, Novocure confirms that the breach didn't compromise their medical treatment devices or disrupt operations, and all systems are fully functional. The company is taking swift action, having discovered the unauthorized access in mid-August and immediately launching an investigation to contain the incident.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

Most enterprises are playing with fire when it comes to AI agents, with a staggering 65% admitting that their AI agents have veered off course, causing measurable impacts in nearly 3 out of 10 cases. As organizations increasingly deploy AI at scale, governance gaps are leaving them vulnerable to risk.

Despite having a robust arsenal of edge controls, security teams are still flying blind to hidden risks lurking in legitimate traffic, leaving them vulnerable to potential threats. The issue lies in the lack of context around underlying infrastructure, causing standard defenses to miss high-risk sessions.

Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

The alarming number of cyber incident reports from water providers - 27 in just seven states - has prompted a swift response from the White House and Texas officials with the launch of Project Watershed 250, a six-month pilot aimed at bolstering water infrastructure cybersecurity. This innovative program will deploy top-notch cyber-defense resources to water and wastewater utilities at no cost, starting with a test run in Texas.

Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.

Cyberattackers are ditching creative tactics for a straightforward, repeatable playbook - and it's surprisingly effective, with a simple trick called ClickFix accounting for 47% of attacks. This sneaky method involves guiding users through a CAPTCHA-style interaction, then tricking them into pasting a command into a terminal, all without needing attachments or vulnerabilities.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Uzbekistan has officially welcomed its new fleet of Chinese J-10CE fighters, with at least six aircraft making a grand entrance in state TV footage on August 28, 2026. The public debut was marked with a ceremonial water-cannon salute, showcasing the country's growing military capabilities.

Meet the Liberator, a game-changing, containerized torpedo launcher designed to be deployed on the ocean floor, capable of firing powerful Mk 48 ADCAP heavyweight torpedoes at enemy ships and subs. This autonomous seabed system is set to revolutionize naval warfare as part of the US Navy's cutting-edge Orca submarine vehicle program.

Russia is now launching jet-powered drones at an astonishing rate, with estimates suggesting a whopping 3,000 units per month, and Ukraine's air defenses are feeling the pressure. In fact, two-thirds of all drones launched in a day can now be jet-powered, according to Colonel Yurii Ihnat of the Ukrainian Air Force.

Pakistan is taking a major leap in its military capabilities with the development of loitering munitions, including a tailless delta design, to enhance its deep-strike ability. This new technology, showcased to the Pakistan Army Chief, promises a scalable and long-range strike posture, with some systems boasting a range of up to 3,000 km.

A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

As Australia and the US celebrate 75 years of the ANZUS treaty, experts are urging both nations to boost their deterrence capabilities by drawing inspiration from the practical cooperation outlined in the recent Australia-New Zealand Defence Guidelines. By following this model, Australia and the US can turn their treaty commitments into tangible, effective deterrence strategies.

Explore real-world examples of democratic technologies in action, from Japan's Team Mirai to Scotland's civic AI initiatives, in a fascinating series of essays on The Renovator. Get inspired by four case studies that showcase the power of tech in promoting democracy and civic engagement worldwide.

Kaspersky's threat research uncovered a sneaky Node.js malware campaign targeting aviation and FinTech organizations in the Middle East and Africa, with victims initially tricked by fake job offers on LinkedIn. The malware, known as NodeRabbit, was delivered through cleverly disguised coding-challenge archives.