cPanel’s authentication bypass bug is being exploited in the wild, CISA warns

The agency added the flaw to the KEV list days after hosting providers confirmed active, ongoing attacks.

The post cPanel’s authentication bypass bug is being exploited in the wild, CISA warns appeared first on CyberScoop.

Continue reading cPanel’s authentication bypass bug is being exploited in the wild, CISA warns

Everyone’s building AI agents. Almost nobody’s ready for what they do to identity.

Anthropic recently announced that it would not release Mythos, its most powerful AI model, to the public. The model discovered thousands of previously unknown software vulnerabilities — flaws that had sat undetected in major operating systems and web browsers for as long as nearly three decades. Anthropic said the model was too dangerous to deploy […]

The post Everyone’s building AI agents. Almost nobody’s ready for what they do to identity. appeared first on CyberScoop.

Continue reading Everyone’s building AI agents. Almost nobody’s ready for what they do to identity.

Federal CIO cautious on Anthropic’s Mythos despite planned rollout

Greg Barbaccia told CyberScoop that Anthropic’s Mythos shows real promise for federal cyber defense, but warns that laboratory results and live network conditions are two very different things.

The post Federal CIO cautious on Anthropic’s Mythos despite planned rollout appeared first on CyberScoop.

Continue reading Federal CIO cautious on Anthropic’s Mythos despite planned rollout

US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied

Investigators found the malware, dubbed Firestarter, on a federal agency’s network in a campaign dating back to at least September 2025.

The post US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied appeared first on CyberScoop.

Continue reading US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied

A dozen allied agencies say China is building covert hacker networks out of everyday routers

The joint warning describes a major tactical shift by Chinese-linked hackers and lays out what organizations should do about it.

The post A dozen allied agencies say China is building covert hacker networks out of everyday routers appeared first on CyberScoop.

Continue reading A dozen allied agencies say China is building covert hacker networks out of everyday routers

The AI era demands a different kind of CISO

When attackers can discover and exploit vulnerabilities in minutes, last quarter’s audit doesn’t mean much. CISOs need to shift from static measurement to real-time awareness — and fast.

The post The AI era demands a different kind of CISO appeared first on CyberScoop.

Continue reading The AI era demands a different kind of CISO

Mythos can find the vulnerability. It can’t tell you what to do about it.

Anthropic’s new model can find vulnerabilities faster and cheaper than ever. The hardest part is still everything that comes after.

The post Mythos can find the vulnerability. It can’t tell you what to do about it. appeared first on CyberScoop.

Continue reading Mythos can find the vulnerability. It can’t tell you what to do about it.

Why the Axios attack proves AI is mandatory for supply chain security

Two weeks ago, a suspected North Korean threat actor slipped malicious code into a package within Axios, a widely used JavaScript library. The immediate concern was the blast radius: roughly 100 million weekly downloads spanning enterprises, startups, and government systems. But beyond the sheer scale, the attack’s speed was just as worrisome – a stark […]

The post Why the Axios attack proves AI is mandatory for supply chain security appeared first on CyberScoop.

Continue reading Why the Axios attack proves AI is mandatory for supply chain security

Ghost breaches: How AI-mediated narratives have become a new threat vector

Three incidents. No actual breaches. Full-scale crisis response. AI hallucinations are creating a new threat vector that most organizations have yet to prepare for.

The post Ghost breaches: How AI-mediated narratives have become a new threat vector appeared first on CyberScoop.

Continue reading Ghost breaches: How AI-mediated narratives have become a new threat vector

We’re only seeing the tip of the chip-smuggling iceberg

A string of federal indictments has exposed a pervasive shadow network of data centers and fake products spanning Southeast Asia. To secure national security, the U.S. must move enforcement from the airport gate to the factory floor.

The post We’re only seeing the tip of the chip-smuggling iceberg appeared first on CyberScoop.

Continue reading We’re only seeing the tip of the chip-smuggling iceberg