Vulnerabilities
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild — Patch Now
The fifth in-the-wild Chrome zero-day of the year, in the V8 JavaScript engine, is now patched — but the attack pattern shows no sign of slowing.
Cybersecurity writer and analyst. Covering breaches, threats, and vulnerabilities — analysis beyond the headline.
Vulnerabilities
The fifth in-the-wild Chrome zero-day of the year, in the V8 JavaScript engine, is now patched — but the attack pattern shows no sign of slowing.
Artificial Intelligence (AI)
Half a century after Brunner imagined it, researchers publish a prototype — and the defender community gets a new detection-research agenda rather than an immediate operational threat.
Vulnerabilities
An AI proxy that increasingly sits between corporate apps and model providers issues a patch — defenders should verify deployments and review proxy logs.
Vulnerabilities
A patch cycle on the backup-of-record for the enterprise — high-priority, given the ransomware-response context.
Cybersecurity 101
Cyber threat intelligence (CTI) explained — the four types, the CTI lifecycle, where intelligence comes from, and how organizations turn it into action.
Vulnerabilities
A use-after-free in the Linux kernel's nf_tables code — patched in February, exploited publicly in June — shows how a single misplaced character in a critical subsystem becomes the keystone of a privilege-escalation chain.
Vulnerabilities
A logic-flow weakness in Check Point's Remote Access VPN gave a Qilin ransomware affiliate and other attackers a month to operate before a patch arrived.
Supply Chain Attack
For the second time in weeks, Microsoft packages were laced with credential stealers — this time targeting users of AI coding agents, forcing the company to pull more than 70 of its own GitHub repositories.
Threat Intelligence
Mandiant's published findings on a financially motivated campaign give defenders in legal and financial services a sector advisory to act on.
Threat Intelligence
Meta's contempt filing tests whether court-ordered restrictions are effectively binding on a commercial spyware vendor.
Supply Chain Attack
Another package-poisoning incident lands across a language registry, reinforcing the case for default-behavior reform that GitHub has now begun applying to npm.
Cybersecurity 101
A complete guide to threat intelligence and threat actors — the four types of CTI, the major actor categories, the intelligence lifecycle, and the frameworks defenders use.