TrendAI expands bug bounty to cover AI vulnerabilities

The New Frontier of Cyber Warfare: AI-Powered Zero Days For years, the cybersecurity world viewed Artificial Intelligence (AI) as a futuristic tool—either a helpful assistant or a distant threat. That illusion has shattered. We are now entering an era where AI is not just the tool being used to attack, but the primary target of … Read more

Microsoft patches major SQL Server flaw in March update

March 2026 Patch Tuesday: A Deep Dive into Microsoft’s Latest Security Updates Microsoft’s March 2026 Patch Tuesday addressed a substantial 77 security vulnerabilities across its product suite, with a notable focus on SQL Server. This release included fixes for two zero-day vulnerabilities that were publicly known before patches were available, though currently, there’s no evidence … Read more

From Physics to Securing the Internet: The Story of FreeRADIUS Founder Alan DeKok

From Physics to Securing the Internet: The Enduring Legacy of FreeRADIUS and the Future of Network Authentication Alan DeKok’s journey from nuclear physics to becoming a leading figure in network security is a testament to the power of adaptability and the often-unforeseen opportunities that arise from pursuing one’s curiosity. His creation, FreeRADIUS, a foundational open-source … Read more

Washington pushes back against EU’s bid for tech autonomy – POLITICO

The Shifting Sands of Tech Sovereignty: Europe and the US Navigate a New Digital Landscape The relationship between the United States and Europe is undergoing a subtle but significant shift, particularly concerning technology. While a transatlantic alliance remains, growing concerns about reliance on both US and Chinese tech are fueling a push for “tech sovereignty” … Read more

Orange Business and Cisco Launch PQC-Secured Network Services

The Quantum Security Race: Orange Business and Cisco Lead the Charge The threat of quantum computing cracking today’s encryption isn’t a distant future concern – it’s driving immediate action. Orange Business and Cisco are at the forefront, launching post-quantum cryptography (PQC)-secured network services designed to protect sensitive data from future attacks. This collaboration marks a … Read more

Shadow AI assistant Clawdbot raises workplace risks

The Rise of ‘Shadow AI’: How Unsanctioned Tools Like Clawdbot Are Reshaping Corporate Security A recent report from Token Security Labs has revealed a startling trend: employees are increasingly adopting personal AI assistants – often without IT’s knowledge. Their analysis found Clawdbot (also known as Moltbot) is currently active within 22% of their customer organizations. … Read more

Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex

Cisco Zero-Days: A Harbinger of Increased Attacks on Collaboration Tools? The recent disclosure of CVE-2026-20045, a critical zero-day vulnerability impacting Cisco’s Unified Communications and Webex Calling platforms, isn’t an isolated incident. It’s a stark reminder of a growing trend: collaboration tools are rapidly becoming prime targets for malicious actors. This vulnerability, already exploited in the … Read more

OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls

The Rise of AI Health Companions: Beyond ChatGPT Health OpenAI’s launch of ChatGPT Health marks a pivotal moment, but it’s just the beginning. The integration of artificial intelligence into personal healthcare is rapidly accelerating, driven by user demand for accessible information and proactive health management. This isn’t simply about chatbots answering medical questions; it’s about … Read more

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

MongoDB Vulnerability: A Harbinger of Future Database Security Challenges A recently disclosed high-severity flaw in MongoDB (CVE-2025-14847) – allowing unauthenticated read access to heap memory – isn’t just a patch-and-move-on situation. It’s a stark reminder of the evolving threat landscape facing database security, and a glimpse into challenges we’ll see amplified in the coming years. … Read more

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

December 22, 2025Ravie LakshmananMalware / Open Source / Supply Chain Security The Rising Tide of Malicious Packages: A Looming Threat to Software Supply Chains The recent discovery of “lotusbail,” a malicious npm package masquerading as a WhatsApp API, and a wave of compromised NuGet packages targeting the cryptocurrency ecosystem, aren’t isolated incidents. They represent a … Read more