Install
CSO delivers the critical information about trends, practices, and products enterprise security leaders need to defend against criminal cyberattacks and other threats.
- 76articles · 30d
- 3+ day agolatest article
- Aug 17, 2026earliest in window
- 99%with images
- 363avg words
- Science & Technology 57
- Computers & Electronics 44
- Software 28
- News 21
- Software Dev. 19
- Science & Nature 15
- Conflict, War & Peace 9
- Business & Industrial 6
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
3+ day, 4+ hour ago (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...
Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways
3+ day, 18+ hour ago (544+ words) Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post, appears to be…...
MikroTik patches flaws currently being exploited to take over routers
4+ day, 10+ hour ago (649+ words) Networking gear manufacturer MikroTik has released patches for six vulnerabilities in its RouterOS firmware, two of which can be chained together to take over devices without authentication over SSH. The exploit chain, dubbed MikroTrick, is already being used by attackers…...
ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel
4+ day, 18+ hour ago (669+ words) A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT…...
September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows
5+ day, 2+ hour ago (437+ words) Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release. The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require…...
CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production
5+ day, 12+ hour ago (751+ words) On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only…...
Adobe Commerce max-severity bug comes under active attack
5+ day, 18+ hour ago (522+ words) Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused…...
Back-to-back N-able bugs send admins on a patching spree
6+ day, 18+ hour ago (499+ words) A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE…...
OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold
1+ week, 3+ day ago (684+ words) OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. “GPT‑6 Astra is rolling out today to…...
Decade-old PostgreSQL flaw turns backup account into a backdoor
1+ week, 3+ day ago (520+ words) A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication…...