International Cyber Expo International Cyber Expo

News

Pentest-Tools.com Releases Free Scanner for CVE-2026-41940 as cPanel Authentication Bypass Enters Its Third Week of Active Exploitation

Pentest-Tools.com has released a free, no-login scanner for CVE-2026-41940, the critical authentication bypass affecting cPanel & WHM and WP Squared that has been actively exploited in the wild since at least February 2026. The vulnerability, rated CVSS 9.8 Critical and added to CISA's Known Exploited Vulnerabilities catalog, allows an unauthenticated attacker to bypass cPanel's login process entirely by exploiting a CRLF injection flaw in cpsrvd, the cPanel service daemon. By manipulating the whostmgrsession cookie, an...

Read moreDetails
Majority of IT Leaders Struggle to Manage Growing Identity Footprint Amid AI Expansion

New research from Keeper Security reveals that 89% of IT leaders struggle to manage the growing identity footprint amid AI expansion. The Identity Security at Machine Speed Report features insight from 200 cybersecurity decision-makers and senior IT leaders across Europe, the United States, Asia-Pacific and the Middle East. The study examines the challenges cybersecurity decision-makers face as identity ecosystems expand to include humans and a growing number of Non-Human Identities (NHIs), and finds that legacy...

Read moreDetails
Huntress Expands Channel Partnerships to Boost Cybersecurity Reach Across Mid-Market and Public Sector

Global cybersecurity company Huntress has announced a major expansion of its global channel ecosystem, adding four new distribution partners to accelerate growth across the mid-market, public sector, and EMEA regions. The new partnerships with Ingram Micro, Vertosoft, Liquid PC, and QBS Software are designed to broaden access to enterprise-grade cybersecurity tools for organizations increasingly targeted by cybercrime. The announcement comes as cyberattacks continue to rise globally, with mid-sized businesses, schools, healthcare providers, and local governments...

Read moreDetails
Quantum computing: The data security conundrum

Proton Mail has today announced the rollout of post-quantum encryption (PQC) across its email platform, making quantum-resistant key generation available to all users, including those on free plans, in what the company describes as a proactive step ahead of the quantum computing era. The feature, which users can opt into via Proton Mail's encryption key settings, allows the generation of post-quantum-ready keys for newly sent encrypted emails. Proton's existing encryption standards, RSA and Elliptic Curve...

Read moreDetails
cybersecurity-protection

A 2025 study in Communications of the ACM tested 1,276 participants’ ability to spot AI-generated images, audio, and video. Average accuracy was 51.2% – literally no better than a coin flip. Participants scored worse on synthetic content (38%) than on real content (64%).  The problem is that most people default to thinking what they see is real. As synthetic media becomes more common across business, media, and online communication, the need for tools that can...

Read moreDetails
cybersecurity-protection

Global businesses are racing to deploy artificial intelligence, sometimes at the expense of their cybersecurity postures. The rise of “agentic AI” is especially notable, due to its potential to automate business workflows, cloud operations, engineering tasks and cybersecurity. Not only are AI agents getting more capable, but they can also work much faster than humans, without taking breaks or needing days off. Companies can get more work done at lower costs, and in some cases...

Read moreDetails

Bridewell has been accepted as a full member of the Forum of Incident Response and Security Teams (FIRST), marking a significant milestone in the company’s incident response maturity and global collaboration capabilities. The UK-based cyber security services provider, which specialises in supporting critical national infrastructure (CNI) organisations, secured membership following a rigorous, peer-led vetting process and approval by the FIRST CSIRT Board of Directors. The achievement reflects Bridewell’s ability to meet the high operational and...

Read moreDetails
artificial-intelligence

In early April, Anthropic announced the release of Claude Mythos Preview, its most advanced AI model to date. Though trained as a general-purpose large language model, Mythos quickly distinguished itself through a notable capacity for complex, multi-step cybersecurity work – autonomously parsing massive codebases, detecting critical-severity software defects and identifying vulnerabilities that have eluded human researchers for decades. Anthropic describes its cybersecurity capabilities as “substantially beyond those of any model we have previously trained,” including...

Read moreDetails
65% of Organisations Still Detect Unauthorised Shadow AI Despite Visibility Optimism

KnowBe4, the digital workforce security provider, securing both AI agents and humans, has announced new research, Phishing Threat Trends Report Volume Seven. The report finds a seismic shift in the attack vectors utilized to conduct phishing attacks, including touchpoints outside of traditional email communication such as calendar invitations and messaging tools. “The inbox is no longer the only front line for coordinated social engineering attacks,” said Jack Chapman, SVP of Threat Intelligence, KnowBe4. “Cybercriminals are...

Read moreDetails
AI robot using cyber security to protect information privacy

The reported PocketOS incident, in which an AI agent deleted a live production database and its backups in a matter of seconds, has quickly become a defining moment in the conversation around autonomous systems in enterprise environments. An AI-powered coding or operations agent, operating with legitimate access via API tokens, encountered what it interpreted as a configuration or credential issue. It then took it upon itself to resolve the problem, issuing a destructive command that...

Read moreDetails
Page 7 of 394 1 6 7 8 394