Four Integrity Failures in UN Preliminary Report on AI

It was 2019 at the RSA Conference in San Francisco, when I presented seven years of AI safety research in “Top 10 Security Disasters in ML: How Laurel and Yanny Replaced Alice and Bob“. It didn’t get much attention. Why would it? I ha…

Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available

CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web […]

AI-Generated Malware Powers New Armored Likho APT Campaign

Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewolf. The group runs two parallel tracks: financially motivated attacks against private individuals […]

The AfD Wolf Cried Not-Sheep and the German Flock Elected the Wolf

The herd is built for one safety, using cohesion against a predator. That instinct is so reliable, ironically it is the easiest for a predator to manipulate and steal. Here is how the theft works, to understand how the AfD seizes power. The predator de…

Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks

Januscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code running inside a guest virtual machine to corrupt host kernel memory. The bug, tracked as […]

Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild

Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that could result in arbitrary code execution without authentication. It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers […]

Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap

A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled.
The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared …

Putin’s Luxury Yachts Spotted, Fleeing Strikes by Ukraine

A luxury yacht of Putin’s, exposed by Alexei Navalny’s team six months before he was poisoned to death in an Arctic prison, is being evacuated. The apparent decision to move the yacht north [to the Northern Fleet’s main naval base at …