Get Motivated: What to Expect from Our Keynote at Rapid7’s Global Cybersecurity Summit
Security teams prepare for incidents every day. Alerts are tuned, playbooks are built, and processes are tested. But when something actually happens, the challenge...
Five defender priorities from the Talos Year in Review
A familiar theme in security right now is that the barrier to entry for attackers is at an all-time low. AI tools can spin...
VECT: Ransomware by design, Wiper by accident
Key Takeaways
Check Point Research discovers that the VECT 2.0 ransomware permanently destroys “large files” rather than encrypting them. A critical flaw in the...
Critical Cursor bug could turn routine Git into RCE
Security researchers have disclosed a high-severity vulnerability affecting the Cursor IDE, allowing arbitrary code execution on a developer’s machine through...
NSA GRASSMARLIN
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to disclose sensitive information.
The following versions of NSA GRASSMARLIN are affected:
GRASSMARLIN vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.5
NSA
NSA GRASSMARLIN
Improper...
The Money Mule Solution: What Every Scam Has in Common
Scams are a $450B–$1T global problem, and unlike card fraud, they don't require a breach; just convincing a victim...
Lazarus Doesn’t Need AGI
Last week’s reporting on unauthorized access to Claude Mythos reads as an AI security story. It is also, structurally, a North Korea (DPRK)...
Pitney Bowes – 8,243,989 breached accounts
In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also...
Spring AI SQL Injection in PgVectorStore and friends
Spring AI SQL Injection in PgVectorStore and friends PgVectorStore, OracleVectorStore, and CouchbaseSearchVectorStore concatenate filter expression output directly into SQL without parameterization, enabling tenant isolation...







