Every industrial organisation now lets someone in from the outside — OEM vendors, system integrators, remote engineers. How they get in determines whether a plant's biggest convenience becomes its biggest breach path. Remote Access Has Become OT's Biggest Front Door Operational technology (OT) environments were designed to be isolated. IT/OT convergence ended that: industrial control systems … [Read more...]
Source-10
You are viewing page 3 of the Source-10 archive. Older tech news, programming trends, and development reports continue below.
Critical Cisco Nexus 9000 Series Switches Vulnerability Enables RCE Attacks
Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of 10 and affects Nexus 9000 models that use a Silicon One ASIC. The security issue, identified as CWE-1327, is detailed in Cisco advisory … [Read more...]
CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added two SonicWall SMA1000 appliance vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming that attackers are exploiting the flaws in real-world attacks. The entries were added on September 2, 2026, with federal civilian agencies required to address the risks by September 5, 2026. The vulnerabilities affect … [Read more...]
Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local privilege escalation, which means it could give unauthorized users higher access rights. The project, named FalconFlank, alleges that the issue abuses … [Read more...]
OpenMatter Network Expands Platform with New Capabilities for Secure AI, Computing and Data Collaboration
Melbourne, Florida, September 2nd, 2026, CyberNewswire Less than three months after its commercial launch, OpenMatter Network today announced a significant expansion of the platform with new capabilities that make it easier for enterprises, developers and researchers to build, deploy and collaborate using sensitive data and AI while maintaining cryptographic control over how information is … [Read more...]
Claude AI Now Controls Your macOS and Windows Computer in the Background
Anthropic has quietly pushed one of its most consequential agentic upgrades yet, letting Claude take control of a user's desktop and complete tasks while they work on something else entirely. The company confirmed this week that computer use inside Claude Cowork and Claude Code can now run in the background, meaning the AI clicks, types, and opens applications the way a human would, without … [Read more...]
WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos
A newly disclosed WhatsApp flaw on Android is raising fresh privacy alarms, allowing anyone holding a locked phone to browse through its entire photo gallery simply by answering an incoming video call. The issue was uncovered by security researcher Jose Rodriguez, known for a string of past lock screen bypass discoveries on both Android and iOS, and has already been reported to Meta and Google. As … [Read more...]
Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities
Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and generate working patches for them. The release arrives just three weeks after Gemini 3.7 Flash, marking Google's third Flash-tier launch in six weeks, and both new models share the … [Read more...]
Firefox on iPhone Can Now Block Ads and Trackers Without Installing an Extension
Mozilla has introduced a built-in Ad Blocker for Firefox on iOS, allowing iPhone users to block many third-party advertisements and ad-related trackers without downloading a separate browser extension. The new feature is designed to reduce visual clutter from pop-ups, overlays, and third-party advertising scripts that can slow down browsing or interrupt users while reading web content. It is … [Read more...]
GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok
A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer's machine the moment it is opened with an AI coding agent, no prompt typed, no approval clicked, and in some cases before the user has even authenticated. Security researchers at Manifold Security found the flaw while investigating what CLI-based coding agents … [Read more...]
Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse
A wave of cyberattacks across the US and Europe in August exploited the trust businesses place in everyday tools, turning Microsoft 365 logins, remote-management software, and routine business documents into entry points for attackers. Security researchers tracked campaigns that combined account takeover, persistent remote access, and credential theft, often disguised as legitimate activity. … [Read more...]
Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw
Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration. The incident highlights the security risks that can arise when cloud platforms trust third-party identity providers without requiring strong, account-level verification before granting access. According to notifications sent to … [Read more...]
Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC
A Russian national has been indicted in the United States over an alleged malware operation that targeted roughly 80,000 freelance workers worldwide. Prosecutors say the campaign used fake accounts and booby-trapped Excel documents to turn ordinary work messages into a route for stealing data and taking control of computers. The case highlights how familiar office files can still be used to reach … [Read more...]
Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections. The discovery links the tool to activity associated with the Gentlemen ransomware operation and shows how one intrusion can combine access theft, surveillance, and defense evasion. Its recovery gives defenders an unusual view of … [Read more...]
BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers
Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as UNC5669, targets the systems that move money instead of individual account holders. Its goal is to gain trusted access and submit fraudulent transfers through legitimate financial channels. The campaign has affected financial services, retail and … [Read more...]
Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token
A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk after security researchers confirmed that remote attackers can escalate privileges by tampering with the software's JWT refresh token mechanism. Tracked as CVE-2026-84115 and rated 8.3 (High) on the CVSS scale, the flaw affects all Cleo Harmony … [Read more...]
FBI and CrowdStrike Disrupt 20-Year-Old Sality Botnet Controlling 15,000+ Infected Systems
The Department of Justice has confirmed a coordinated international takedown of the Sality botnet, a peer-to-peer malware network that has plagued victims worldwide since 2003. The operation spanned the United States, Bulgaria, Hungary, and Romania, bringing together federal law enforcement and private-sector cybersecurity firms to dismantle infrastructure that had quietly powered cryptocurrency … [Read more...]
Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials
Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI can assist with low-level operational technology exploitation. The experiment achieved arbitrary ARM shellcode execution on a WAGO 750-831 PLC without valid credentials. However, it required major human involvement, expensive API usage, and … [Read more...]
FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise applications to connect to Windows Remote Desktop Services. Because it processes network data from remote servers and … [Read more...]
Palo Alto Networks Acquires Console to Build AI Agents for Autonomous Security Operations
Palo Alto Networks has acquired Console, an AI-native platform that will strengthen Cortex by enabling AI-driven security workflows to investigate, prioritize, and remediate threats at machine speed. The acquisition comes as security teams face rising alert volumes, increasingly automated attacks, and pressure to reduce the time required to detect and contain threats. Palo Alto Networks said … [Read more...]
- « Previous Page
- 1
- 2
- 3
- 4
- 5
- …
- 52
- Next Page »


















