Security Spotlight

Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
South Korea's data regulator fined telecom giant KT KRW 53.979 billion after an 11-month breach exposed 16,647 subscribers' data through a rogue femtocell.
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
Cybersecurity
Origin Energy Breach Exposes Data on 900,000 Australian Customers
Origin Energy disclosed a breach affecting 900,000 Australian customers, exposing names, bank account fragments, and addresses amid unconfirmed ransom claims.
Cybersecurity
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
DentaQuest's breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in a network hack.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
Cybersecurity
Coca-Cola Files SEC 8-K After Ransomware Hits Fairlife Dairy
Coca-Cola filed an SEC Form 8-K disclosing a ransomware attack on Fairlife dairy that suspended all U.S. production. No group has yet claimed the attack.
Application Security
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.
Cybersecurity
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide malware from EDR tools.