
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Researchers at Wiz uncovered a vulnerability in Snowflake's GitHub repository, where a flawed GitHub Actions workflow exposed a sensitive Jira API token, putting internal credentials at risk. This security gap allowed attackers to potentially execute commands using a crafted GitHub issue.

Google warns that attackers are exploiting Chrome Remote Debugging to steal cookies, and now researchers have developed a new technique to activate DevTools inside a live browser, allowing for even easier cookie extraction. This technique uses a Beacon Object File to tap into the Chrome DevTools Protocol, posing a new threat to users.

The US has taken a bold step in cyberspace, launching a program that empowers select private companies to launch targeted counterattacks against ransomware gangs and other cybercrime syndicates. This innovative approach aims to disrupt and dismantle these threats, with the government maintaining control and ensuring accountability every step of the way.

Imagine receiving a notification while walking your dog that a live attack is underway - and being able to instantly approve a block, stopping the threat in its tracks in under 10 minutes. Corma's AI agents make it possible, proactively defending networks and giving customers peace of mind.

The traditional attack chain is getting a makeover: instead of starting with a malicious email, attackers now use OAuth apps to breach Google Workspace, exploiting new vulnerabilities in an AI-driven threat landscape. It's time to shift from an inbox-centric to an OAuth-first security approach to stay ahead.

The tide is turning in the world of AI: smaller, more affordable models are suddenly delivering impressive results in hacking and exploitation benchmarks, providing net value at a cheaper price and giving them a competitive edge. This emerging middle class of AI models, including GLM-5.2, Grok 4.5, and Opus 4.7, is crossing a crucial threshold, making them strategic players in the industry.

The US government has just given private cybersecurity firms the green light to hack back against foreign cybercrime groups that threaten American interests, marking a major shift in the country's cyber warfare strategy. This bold move targets transnational crime groups, not nation-states, and paves the way for covert surveillance and cyber operations.

Researchers have discovered a clever way to shut down AI hacking agents by inserting specially crafted prompts alongside sensitive data on Amazon Web Services, effectively triggering the model's internal safety rules and halting attacks. This innovative technique, dubbed "context bombing," has proven to be a simple yet effective defense against AI-powered hacking.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Beware of Chrome VPN extensions that may be putting your online security at risk: over 737 extensions impersonated popular VPN and proxy services, secretly routing users' traffic through unsecured SOCKS5 proxies. This exposed users to potential data breaches and surveillance, as their browsing activity was intercepted by a single, unknown provider.

Imagine a scenario where hackers can gain SYSTEM access to a Windows computer without needing a single click or logged-in user - and even exploit it remotely over RDP with no hardware involved. Researchers have just revealed a chilling new class of attacks, dubbed "Plug and Pwn", that takes advantage of Windows' Plug and Play feature to execute malicious software with alarming ease.

Critical security flaws in Zoom's annotation code, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could have allowed a meeting participant to hijack others' clients without warning. Fortunately, Zoom has patched these vulnerabilities, and no exploitation has been reported.

Delta is cracking down on a sneaky passenger who tried to scam fellow travelers on a Las Vegas-to-Atlanta flight by setting up a fake in-flight WiFi hotspot called "Delta WiFi Fast". The incident caused a delay, and authorities were called in once the plane landed.

Mozilla took swift action to protect its users by revoking a key used to sign Firefox and Thunderbird for Linux, after a security slip-up exposed the private key in a public repository. The move ensures user safety, even if it means some extra work for affected users to update their software.

OpenAI's new GPT-5.6-Cyber model is a game-changer in cybersecurity, capable of completing 95% of sensitive requests in advanced scenarios like exploit-chain development and privilege escalation. This purpose-trained model outperforms its general-access counterpart by a landslide, showcasing its potential to revolutionize cybersecurity.

Imagine a SIM card, typically just a simple piece of tech that connects you to your network, being turned against you - allowing hackers to steal your data and even downgrade your device to a vulnerable 2G connection. Researchers have created a toolkit to test the limits of these malicious SIM attacks, and the results are eye-opening.

Identity security is buckling under the strain of increasingly sophisticated threats, with stolen credentials remaining a top vulnerability - a whopping 44.7% of breaches involve compromised login details. AI is now compressing the time and effort attackers need to launch identity attacks, forcing a urgent reevaluation of device trust.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Royal Navy drones recently raised eyebrows when their cameras started sending signals to a Chinese IP address during a routine cyber vulnerability test, sparking concerns over data security. The Ministry of Defence quickly stepped in to reassure that no sensitive data was compromised, and the transmission was just a harmless "heartbeat" signal.

Researchers at Black Hat USA 2026 revealed a shocking vulnerability in passkey defenses, demonstrating how attackers can bypass FIDO2 cryptography and exploit a flaw in Windows Event Logging Service (CVE-2026-34348) to defeat passkey protections. This security gap was found to allow unauthorized users to access and replay sensitive YubiKey signatures.

Researchers have discovered alarming proof-of-concept techniques that allow attackers to exploit styled HTML in emails, breaking through webmail defenses to steal passwords, tokens, and even hijack trusted actions. This vulnerability affects major email services including Outlook, Gmail, and Yahoo Mail, and public proof-of-concept code is readily available.

Nearly 9 out of 10 cyber incidents involve identity compromise, with attackers exploiting weaknesses in credentials, multifactor authentication, and social engineering to gain access to enterprise environments. Identity has become the new front door for cyber threats, making it a critical area of focus for protecting your organization's security.

Meet HTTP Terminator, an AI-powered research system that generated 30,000 candidate desync vectors and helped uncover novel HTTP desynchronization techniques, including an Apache Traffic Server zero-day. This groundbreaking tech scanned 30,000 websites, pushing the boundaries of vulnerability discovery.

Meet NatJack, a sneaky new attack that exploits NAT tables to hijack TCP sessions, spoof DNS, and more - and the surprising way it's putting your online security at risk. A security researcher just revealed the shocking details at Black Hat USA 2026.

Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

Researchers have discovered a sneaky way for hackers to bypass iCloud Private Relay's protections and expose your real network address, putting your online privacy at risk. This vulnerability lets malicious actors send traffic directly from your device, revealing your hidden IP address.