Penetration testing stories
Patching is urgent for Cudy WR3000 rev 2.0 routers, as public code shows how two flaws can let attackers gain root command execution.
The appointment gives UltraViolet Cyber a CISO who knows its operations from the client side and will steer AI governance and internal security.
Basic security lapses are leaving web apps exposed, with Barracuda saying routine misconfigurations account for most of 20 flaws per site.
Misconfigured models are giving attackers a fresh route into cloud systems, raising the risk of data theft and service compromise.
Owners of certain Cudy WR3000 routers face a root takeover risk unless they update firmware to patch two chained flaws.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
CyberCatch's continuous compliance tools will be folded into Datavault AI's data platforms if the all-cash deal wins approvals.
Realistic-looking security evidence can be fabricated when memory, simulation and model hallucinations blur provenance in AI workflows.
Approved defenders will gain broader access to cyber tools as the new tiered Daybreak programme adds GPT-5.6-Cyber for advanced security work.
Customers in Australia and New Zealand may now see Liverton Security as a lower-risk supplier after the Wellington firm won CREST ANZ membership.
Security teams should treat AI patching with caution after 53.9% of 6,080 model-generated fixes failed or introduced new flaws.
Hong Kong saw a record 15,877 cyber incidents in 2025 as AI speeds attacks and shortens the window to exploit software flaws.
Defenders will test prompt-injection tactics against AI agents as CrowdStrike and AWS offer USD $100,000 in prizes for a virtual red-team contest.
The combined group now serves more than 3,000 customers in 57 countries as Brinqa adds validation tools to close the remediation gap.
Stolen credentials can become an operational foothold within hours, leaving annual assessments too slow to catch the real attack paths.
The move gives the crypto exchange's security team AI help to hunt flaws in critical code as threats to financial infrastructure grow.
Customer demand is helping the Boston and London startup expand as enterprises race to secure AI systems against fresh attack risks.
Up to 85 government accounts were compromised in a four-day campaign that also reached nuclear and energy organisations, researchers said.
Indonesia's digital skills gap is fuelling demand for practical cyber and AI training, as firms struggle to hire workers.