ChainDrop Supply Chain Attack Compromises Hundreds of npm Packages

Security researchers identified a major software supply chain campaign dubbed “ChainDrop,” in which a self-propagating worm compromised hundreds of npm packages and spread malicious updates through…
Microsoft August 2026 Patch Tuesday Addresses Nearly 400 Vulnerabilities

Microsoft released its August 2026 Patch Tuesday security updates on August 11, addressing 421 vulnerabilities, including 62 Critical and 357 Important-severity vulnerabilities. The release covers a…
SonicWall Zero-Day Chain Becomes INC Ransomware’s Go-To Route Into Corporate Networks

On July 14, 2026, SonicWall disclosed two vulnerabilities in its SMA 1000 Series secure remote access appliances, the SSL VPN gateways many mid-size and large organizations use as the front door into…
Anthropic Reveals Claude AI Successfully Compromised Three Real Organizations During Security Testing

Anthropic disclosed that its latest Claude large language models successfully compromised the networks of three real organizations during controlled cybersecurity evaluations designed to measure…
OpenAI Says Its Own AI Models Autonomously Escaped a Test and Hacked Hugging Face

OpenAI disclosed this week what it called an unprecedented cyber incident. An autonomous agent, built on the newly released GPT 5.6 Sol and an unreleased more capable model, broke out of a controlled…
New Dysphoria Botnet Compromises More Than 200,000 Devices Worldwide

Security researchers have identified a rapidly expanding distributed denial of service (DDoS) botnet dubbed Dysphoria, which has compromised more than 200,000 internet connected devices worldwide….
SharePoint Zero-Day Sees Mass Exploitation in Wake of Record-Breaking Patch Tuesday

Microsoft’s July 2026 Patch Tuesday release, published on July 14, set a new record for the largest security update in the company’s history, addressing over 600 vulnerabilities across Windows,…
Ernst & Young Discloses Third Party Data Breach Affecting Client and Employee Information

Global professional services firm Ernst & Young (EY) disclosed a cybersecurity incident after attackers compromised a third party IT support platform used by the company, potentially exposing…
Microsoft Releases Largest Patch Tuesday in Company History, Fixing 570 Vulnerabilities

Microsoft released its July 2026 Patch Tuesday security updates, marking the largest vulnerability remediation effort in the company’s history. The release addresses 570 vulnerabilities across…
CISA Warns of Active Exploitation of Microsoft SharePoint Remote Code Execution Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that threat actors are actively exploiting CVE-2026-45659, a high severity remote code execution vulnerability affecting on…