A breach at Nelnet Servicing exposed names, addresses, and Social Security numbers for 2.5 million student loan borrowers. Here’s what affected people need to know.
A bipartisan House bill proposes sweeping oversight of frontier AI models, including mandatory third-party audits, $300M for NIST’s CAISI, and open-source security grants. It’s already drawing fire over preemption of state AI laws.
Cisco disclosed its seventh exploited SD-WAN zero-day of 2026. CVE-2026-20245 allows root command execution with no patch available yet. Here’s what defenders need to know.
Password manager Dashlane disclosed that fewer than 20 encrypted vaults were downloaded after a brute-force attack targeting 2FA protections. The vaults are encrypted, but the incident raises questions about how the attackers bypassed two-factor authentication.
Threat actor PCPJack turned 230 hijacked cloud servers across AWS, Google Cloud, and Azure into a covert SMTP relay network. The operation was exposed after the group left their entire toolkit — including source code and Sliver configs — on an open C2 server.
A new malware called IronWorm is spreading through npm by poisoning legitimate packages with a Rust-based stealer that uses stolen credentials to self-replicate. It deploys an eBPF rootkit and targets AI development credentials, making it one of the more sophisticated supply chain attacks in recent memory.
The Great American AI Act is a 269-page bipartisan bill that would regulate frontier AI models, fund open-source security, and preempt state AI laws. It’s ambitious, controversial, and could reshape the entire AI landscape.
A breach at Nelnet Servicing exposed Social Security numbers and personal data for 2.5 million student loan borrowers. With loan forgiveness in the news, phishing attacks using this data are a serious and ongoing threat.
Cisco disclosed its seventh exploited SD-WAN zero-day of 2026. CVE-2026-20245 allows root-level command execution with no patch available yet. Here’s what organizations need to know and do right now.
Password manager Dashlane disclosed that a brute-force attack targeting its device registration system compromised fewer than 20 user accounts. Here’s what actually happened and what it means for you.