Aggregator
结合代码分析CVE-2026-33439 OpenAM 反序列化漏洞
Credit card theft campaign abuses Stripe to host stolen payment info
Hill Dems hammer GOP for $250M CISA budget cut
A House Appropriations subcommittee is set to mark up fiscal 2027 DHS funding legislation Friday.
The post Hill Dems hammer GOP for $250M CISA budget cut appeared first on CyberScoop.
Trump considers Palantir exec to lead CISA
Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense
By participating in Project Glasswing and working with Claude Mythos Preview, Tenable can help customers better understand how emerging frontier AI models behave, their evolving risks and benefits for cybersecurity, and the kinds of controls organizations will need as AI adoption accelerates.
Key takeaways- Tenable is also interested in using Mythos Preview to drive new research, strengthen the security of Tenable, and help customers better understand how emerging frontier AI models behave, their evolving risks and benefits, and the kinds of controls organizations will need as they accelerate AI adoption.
- Tenable previously announced the integration of the Tenable One Exposure Management Platform with the Claude Compliance API to give Tenable customers better AI visibility and governance capabilities, along with Claude-powered workflows in Tenable Hexa AI, the agentic engine of the Tenable One platform.
Over the past year, it has become increasingly clear that AI is going to fundamentally reshape cybersecurity.
Not eventually. Now.
The pace of vulnerability discovery is accelerating. Attack surfaces are expanding faster than ever. Security teams are already overwhelmed trying to determine what actually matters.
At the same time, frontier AI models like Claude Mythos Preview are demonstrating that new capabilities in reasoning and agentic workflows are on the horizon and could significantly accelerate cyber offense and challenge cyber defense over the next few years.
Tenable joining Project Glasswing is a strategic step forward for defenders, and an extension of our existing partnership with Anthropic.
We also believe the industry is entering a period where defender advantage will not come from access to any single model. It will come from understanding what matters most, reducing exposure before attackers strike, and coordinating remediation at the speed modern threats demand.
Improving what matters mostThe industry already has more findings than humans can realistically process. The real challenge is understanding what matters most.
Which exposures are actually dangerous? Which combinations create meaningful attack paths? What should be fixed first? What actions will materially reduce risk?
Those are exposure management problems.
We’re working with frontier AI models to evaluate and benchmark how advanced reasoning capabilities may improve exposure analysis, attack path understanding, prioritization, and remediation decision-making to help our customers and partners improve their own security and risk management initiatives.
As part of Project Glasswing, we’re particularly interested in driving new research using Mythos Preview to better understand where it can help reinforce existing security analysis, and strengthen our own defenses by using frontier models to improve the security of Tenable. We also plan to use Mythos alongside other models to help challenge assumptions, and identify relationships and risk patterns faster than traditional approaches alone.
We believe frontier models will increasingly become another important source of security insight and telemetry flowing into exposure management platforms. The long-term differentiator for defenders will not be access to a single model. It will be the ability to combine those signals with authoritative context, asset intelligence, attack path analysis, and coordinated remediation across the enterprise.
Understanding the AI attack surfaceAnother important reality is that organizations are increasingly responsible for AI systems they did not build themselves. That creates a rapidly expanding attack surface.
Our goal is simple: when meaningful advances in AI capabilities arrive, we will be ready to translate them into practical customer value quickly and responsibly.
Participating in frontier AI initiatives like Project Glasswing help us better understand emerging model behaviors, evolving risks, and the kinds of controls organizations will need as AI adoption accelerates.
That learning directly informs both our products and our own internal security practices.
The future of cybersecurityOne thing is becoming increasingly clear: frontier AI capabilities will not remain rare for long.
Capabilities that seem extraordinary today will eventually become widely available across the industry, including to attackers.
In that world, defender advantage will not come from access to any single model. It will come from understanding what matters most, reducing exposure before attackers strike, and coordinating remediation at the speed modern threats demand.
That is the work we’re focused on at Tenable. That is our commitment to our partners and customers.
And we’re excited to be doing it alongside Anthropic and the broader Project Glasswing community.
Hackers Use Malicious Ads to Deliver FlutterShell Backdoor on macOS Systems
A new and rapidly spreading malware campaign is putting macOS users at serious risk. Threat actors are using Google Ads to push fake desktop applications that secretly install a powerful backdoor on infected machines. The campaign, dubbed Operation FlutterBridge, marks a sharp escalation in tactics from financially motivated attackers who have been active since at […]
The post Hackers Use Malicious Ads to Deliver FlutterShell Backdoor on macOS Systems appeared first on Cyber Security News.
Hackers Use Fake Claude Code Install Page to Deliver Fileless .NET Infostealer
Hackers are exploiting the excitement around AI coding tools by targeting users who search for Claude Code installation guides. An active campaign uses fake installer pages to silently steal credentials from unsuspecting victims. The attackers use SEO poisoning to push a spoofed Anthropic install page to the top of search results. Once a user lands […]
The post Hackers Use Fake Claude Code Install Page to Deliver Fileless .NET Infostealer appeared first on Cyber Security News.
CVE-2026-31449 | Linux Kernel up to 6.12.79/6.18.20/6.19.10 ext4 ext4_ext_correct_indexes out-of-bounds (Nessus ID 316948 / WID-SEC-2026-1252)
CVE-2026-31446 | Linux Kernel up to 6.19.10 mb_groups ext4_unregister_sysfs use after free (Nessus ID 313522 / WID-SEC-2026-1252)
CVE-2026-31447 | Linux Kernel up to 6.19.10 ext4 s_first_data_block privilege escalation (Nessus ID 313522 / WID-SEC-2026-1252)
CVE-2026-31448 | Linux Kernel up to 6.19.10 ext4_ext_map_blocks infinite loop (Nessus ID 313522 / WID-SEC-2026-1252)
CVE-2026-31445 | Linux Kernel up to 6.18.20/6.19.10 damon_call null pointer dereference (Nessus ID 310613 / WID-SEC-2026-1252)
CVE-2026-31443 | Linux Kernel up to 6.18.20/6.19.10 dmaengine denial of service (WID-SEC-2026-1252)
CVE-2026-31444 | Linux Kernel up to 6.6.130/6.12.79/6.18.20/6.19.10 smb_grant_oplock use after free (Nessus ID 310603 / WID-SEC-2026-1252)
FTC considers setting aside or modifying $150 million privacy penalty against X
IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets
A newly discovered malware campaign called IronWorm has been silently targeting software developers through poisoned npm packages, stealing credentials, API keys, and even cryptocurrency wallet recovery phrases. The attack is built to spread itself through trusted developer workflows, making it one of the more sophisticated supply-chain threats seen in recent years. The malware travels inside […]
The post IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets appeared first on Cyber Security News.