Skip to main content

Latest Analysis

Cybersecurity intelligence, threat analysis, and national security reporting.

Server room with rows of equipment and one terminal with a blank screen, suggesting a breach.

Langflow vulnerability exploited to harvest OpenAI, AWS keys

Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

Analyst 207
Traders work around a central console on a dimly lit trading floor with cityscape view.

AI Cyberattacks Threaten Global Financial System Stability

The Financial Stability Board warns that AI-powered cyberattacks could spark a chain reaction of chaos in global markets, exploiting vulnerabilities in sovereign debt, private credit, and asset valuations. This threat is more than just a tech issue - it's a potentially disastrous blow to market confidence.

Analyst 207
Woman in modern office setting looks thoughtfully at camera.

AI Reshapes Cybersecurity Career Paths for Women

The rise of AI is revolutionizing cybersecurity, creating a blank canvas for women to chart new career paths and make their mark in this rapidly evolving field. With AI shaking up the defender-attacker dynamic, new role definitions and threat approaches are emerging, offering a fresh opportunity for women to reskill and thrive.

Analyst 207
Hospital supply chain management office with scattered papers and blurred computer screen.

McKesson Breach Exposes Third-Party Risks in Healthcare

A single vulnerable third-party application can spark a national patient data crisis, as seen in the recent McKesson breach, where a third-party integration led to a massive data exfiltration claim of 284 million records.

Analyst 207
Smartphone on cluttered desk in cafe with blurred webpage on screen.

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Seeds

Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with one server's panel slightly open.

Threat Actors Exploit API Key, Drain $600,000 in AI Credits

In a shocking security breach, threat actors made off with a whopping $600,000 in AI credits after exploiting a stolen API key from AI safety research group METR over just three weeks. The incident began with a researcher inadvertently leaving a public EC2 instance exposed, despite Google authentication, due to a fail-open flaw and a "vibe-coded" app storing a sensitive API key.

Analyst 207
Dimly lit industrial control room with unoccupied workstation and blurred laptop screen.

Cybersecurity Leaders Warn of AI Trust Gap

More than one in five organizations have fallen victim to AI-powered attacks, with 22% reporting a security incident in the past year where hackers used artificial intelligence to breach critical business platforms. This alarming trend highlights the urgent need for cybersecurity leaders to address the growing AI trust gap.

Analyst 207
Hospital corridor with medical office door ajar, patient info sheet blurred in foreground.

Novocure Breach Exposes Over 1,400 US Cancer Patient Records

Rest assured, Novocure confirms that the breach didn't compromise their medical treatment devices or disrupt operations, and all systems are fully functional. The company is taking swift action, having discovered the unauthorized access in mid-August and immediately launching an investigation to contain the incident.

Analyst 207
Network operations room with rows of routers, technicians, and a large screen displaying internet infrastructure diagram.

Hackers exploit BGP hijacking to deliver malicious Virtualizor updates

Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

Analyst 207
Dimly lit server room with rows of equipment, empty chairs, and unoccupied workstation.

Enterprises Lag in AI Agent Governance

Most enterprises are playing with fire when it comes to AI agents, with a staggering 65% admitting that their AI agents have veered off course, causing measurable impacts in nearly 3 out of 10 cases. As organizations increasingly deploy AI at scale, governance gaps are leaving them vulnerable to risk.

Analyst 207
Rows of computer servers and networking equipment in a brightly lit server room, with a blurred laptop screen in the…

Edge Security Exposes Hidden Risks in Legitimate Traffic

Despite having a robust arsenal of edge controls, security teams are still flying blind to hidden risks lurking in legitimate traffic, leaving them vulnerable to potential threats. The issue lies in the lack of context around underlying infrastructure, causing standard defenses to miss high-risk sessions.

Analyst 207
Developer workstation with laptop, coding materials, and papers scattered on a desk in a bright, modern office space.

Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

Analyst 207
People in business attire and utility workers stand in front of a small water treatment plant with industrial equipment.

US Bolsters Water Infrastructure with Cybersecurity Pilot

The alarming number of cyber incident reports from water providers - 27 in just seven states - has prompted a swift response from the White House and Texas officials with the launch of Project Watershed 250, a six-month pilot aimed at bolstering water infrastructure cybersecurity. This innovative program will deploy top-notch cyber-defense resources to water and wastewater utilities at no cost, starting with a test run in Texas.

Analyst 207
Dimly lit server room with rows of racks, one foreground rack with a warning sign.

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks

Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

Analyst 207
Network equipment rack with cables and patch cords in a data center interior.

BGP Hijack Targets Softaculous Traffic, Delivers Malware

In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.

Analyst 207
Person in office cubicle looks at laptop with confusion and curiosity.

Cyberattackers Favor Repeatable Playbooks Over Innovative Tactics

Cyberattackers are ditching creative tactics for a straightforward, repeatable playbook - and it's surprisingly effective, with a simple trick called ClickFix accounting for 47% of attacks. This sneaky method involves guiding users through a CAPTCHA-style interaction, then tricking them into pasting a command into a terminal, all without needing attachments or vulnerabilities.

Analyst 207
Multiple J-10CE fighter jets parked on tarmac with water-cannon salute in background.

Uzbekistan Unveils Chinese J-10CE Fighters

Uzbekistan has officially welcomed its new fleet of Chinese J-10CE fighters, with at least six aircraft making a grand entrance in state TV footage on August 28, 2026. The public debut was marked with a ceremonial water-cannon salute, showcasing the country's growing military capabilities.

Analyst 207
Seabed torpedo launcher system on a mock seabed with naval equipment.

US Navy Develops Seabed Torpedo Launcher for Orca Submarine Vehicle

Meet the Liberator, a game-changing, containerized torpedo launcher designed to be deployed on the ocean floor, capable of firing powerful Mk 48 ADCAP heavyweight torpedoes at enemy ships and subs. This autonomous seabed system is set to revolutionize naval warfare as part of the US Navy's cutting-edge Orca submarine vehicle program.

Analyst 207
Rows of jet-powered drones on assembly lines or a concrete apron, surrounded by industrial equipment and personnel.

Russia Surges Jet-Powered Drone Output, Pressures Ukraine Air Defenses

Russia is now launching jet-powered drones at an astonishing rate, with estimates suggesting a whopping 3,000 units per month, and Ukraine's air defenses are feeling the pressure. In fact, two-thirds of all drones launched in a day can now be jet-powered, according to Colonel Yurii Ihnat of the Ukrainian Air Force.

Analyst 207
Technicians surround a tailless delta wing loitering munition on a workbench.

Pakistan Develops Loitering Munitions for Deep-Strike Capability

Pakistan is taking a major leap in its military capabilities with the development of loitering munitions, including a tailless delta design, to enhance its deep-strike ability. This new technology, showcased to the Pakistan Army Chief, promises a scalable and long-range strike posture, with some systems boasting a range of up to 3,000 km.

Analyst 207
Refrigerated case with doors ajar, shelves stocked with food and drinks, digital display blank or out of focus.

DoD Refrigerator Outages Spark Hacking Fears

A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

Analyst 207
Military briefing room with Asia-Pacific map and Australian, US flags.

Australia, US urged to strengthen deterrence with Defence Guidelines

As Australia and the US celebrate 75 years of the ANZUS treaty, experts are urging both nations to boost their deterrence capabilities by drawing inspiration from the practical cooperation outlined in the recent Australia-New Zealand Defence Guidelines. By following this model, Australia and the US can turn their treaty commitments into tangible, effective deterrence strategies.

Analyst 207
Diverse group of people gathered around a table with laptops and tablets in a bright community center.

Democratic Tech Models Proliferate Globally

Explore real-world examples of democratic technologies in action, from Japan's Team Mirai to Scotland's civic AI initiatives, in a fascinating series of essays on The Renovator. Get inspired by four case studies that showcase the power of tech in promoting democracy and civic engagement worldwide.

Analyst 207
Blurred laptop on airport security counter amidst muted colors.

Mirage Kitten Unveils Node.js Malware Targeting Aviation, FinTech

Kaspersky's threat research uncovered a sneaky Node.js malware campaign targeting aviation and FinTech organizations in the Middle East and Africa, with victims initially tricked by fake job offers on LinkedIn. The malware, known as NodeRabbit, was delivered through cleverly disguised coding-challenge archives.

Analyst 207