
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it alongGeneral cybersecurity news and analysis

Android 17 just got a major boost to online privacy with OS-wide Encrypted Client Hello support, making it harder for snoops to see which websites you're visiting. This new standard teams up with private DNS to keep your browsing habits private, shielding the domain names you visit from prying eyes.

Researchers have uncovered a vulnerability in PaperCut that allows an unauthenticated attacker to gain remote control, enabling them to execute arbitrary Java code within the application's process. This flaw can be exploited through a clever two-step chaining technique, putting unpatched PaperCut NG and MF instances at risk.

A 68-year-old UK man, Milan Ibrahim, has been sentenced to over six years in prison for running a massive $1.3 million IPTV piracy ring that sold stolen broadcasts from top brands like the BBC, ITV, and Sky. His illicit operation raked in nearly £1 million over just three years, authorities say.

As AI-driven cyber threats escalate, 100 top tech firms, including OpenAI, Google, and Microsoft, are sounding the alarm, calling for collective action to bolster cyber defenses. It's a wake-up call: defenders must adapt and become AI-native to protect against rapidly advancing threats.

The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

Meet Kibu, an encryption app designed with military-grade security in mind, solving a pressing problem for government execs who rely on personal devices for sensitive conversations. Its cutting-edge verification features combine biometric authentication with organizational identity controls to ensure you're talking to the right person - or entity.

In today's complex hybrid and multi-cloud environments, an Identity Fabric weaves together disparate identity systems, providing a unified layer of visibility into how identities interact across applications, APIs, and infrastructure. By bridging the gap between access intent and runtime execution, it shines a light on hidden risks and vulnerabilities, eliminating the identity dark matter that attackers exploit.

A security researcher has uncovered two critical vulnerabilities in the Unitree G1 EDU robot, allowing hackers to remotely execute code with root access, potentially putting users and systems at risk. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, highlight the importance of robust security measures in robotics and AI technology.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Threat actors are still finding success by exploiting simple, preventable software weaknesses that have been known for years - and it's a problem that CISA says could have been designed out of products from the start. The agency's review reveals that decades-old bugs, like improper input validation, continue to plague the industry.

The world's top tech and security companies are sounding the alarm: AI-driven cyber threats are on the rise and we only have a small window of time to boost our defenses before attacks become more widespread and sophisticated. Over 100 industry giants, including OpenAI, Google, and Microsoft, are urging for AI-powered defenses to protect critical infrastructure like hospitals and water treatment plants.

ServiceNow has released urgent security updates to fix three critical vulnerabilities in its AI Platform, and experts warn customers to act fast to secure their self-hosted instances. Apply the patches now to protect against potential malicious attacks.

A critical cPanel security flaw, tracked as CVE-2026-65643, allows attackers to execute code as the root user, giving them full control of the server, by exploiting domain parking and addon domain functionality. This vulnerability impacts all supported versions of cPanel & WHM and can be triggered by an authenticated account holder.

Microsoft's latest update, KB5120998, is here with 35 fixes and a revamped taskbar, plus a new administrator protection feature that helps shield against elevation-of-privilege attacks by separating profiles. This feature, currently off by default, can be easily enabled through Microsoft Intune or Group Policy.

Despite 97% of S&P 500 companies mentioning AI in their annual reports, a staggering gap exists: only 16% actually document a specific process for managing AI-related cyber risks. This revelation raises crucial questions about corporate transparency and preparedness in the face of emerging threats.

The clock is ticking: over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm that we must urgently boost our AI-powered cyber defenses to avoid a surge in sophisticated attacks. They're calling on us to take action now to reduce risk before it's too late.

The conversation around DevSecOps in federal agencies has officially shifted from "should we?" to "how can we make it work at scale?" Agencies are now focused on turning their DevSecOps pilots into fully-fledged operational capabilities.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
A test site mishap at Intimeros, a company that reviews AI companions, exposed sensitive secrets about their AI girlfriend review process after a temporary change was left in place for three weeks. The incident led to swift action, with measures including restored password protection and blocked search engine indexing.

If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.

Meet Omarchy, a bold new take on Arch Linux, now backed by $10 million in funding and led by tech visionary David Heinemeier Hansson - but beware, its early releases have raised some red flags about security. The project just rolled out Omarchy 4.0.1, a swift security fix for its mid-August "Quattro" release.

A security flaw in Kiro, known as a prompt injection vulnerability, allowed hackers to tap into sensitive data by manipulating the Kiro agent with malicious repository content. This issue, affecting Kiro IDE 0.7.45 on Windows, could send local information to an external endpoint, putting users at risk.

Relying solely on data backup isn't enough - you need to verify that your applications can actually be recovered and restored to working order in the event of a disaster. Simply copying data to storage doesn't guarantee a smooth recovery, and that's a risk many IT professionals are unknowingly taking.

The threat landscape for industrial control systems (ICS) is showing a welcome decline, with only 19.15% of ICS computers encountering blocked malicious objects in Q2 2026 - the lowest level since 2022. However, amidst this positive trend, one sector remains alarmingly vulnerable: biometrics.

The threat landscape has drastically changed: cyber attackers can now exploit vulnerabilities in as little as two days, leaving federal agencies with a shrinking window to defend against threats. To stay ahead, they must shift their focus from reacting to attacks to anticipating and preparing for what's next.

Android 17 just got a major boost to browsing privacy with the addition of Encrypted Client Hello (ECH) support, which teams up with private DNS to keep your online activities under wraps by hiding the domain names you visit. This means you can say goodbye to being profiled by advertisers and hello to a more private browsing experience.