Scanning the Threat Landscape

AI-analyzed cybersecurity news with IFF classification and defender context.

Latest Stories

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA has spearheaded the formation of the 37-member Open Secure AI Alliance, a consortium of leading tech companies dedicated to advancing open technologies, techniques, and tools for securing software and AI agents. In conjunction with this alliance, NVIDIA has also open-sourced its NOOA framework, a move aimed at fostering collaborative development in AI security.

Adversaries Don't Need a Zero-Day — They Read Your Rulebook

Adversaries are increasingly bypassing sophisticated security tools by exploiting predictable configurations and rule-based systems. Instead of relying on zero-day exploits, attackers are leveraging human error and easily accessible information about how organizations implement their security measures.

Securing AI Agent Reasoning Against Logic-Layer Attacks in 90 Days

This article discusses vulnerabilities in autonomous AI agents' reasoning layer, such as goal hijacking and unauthorized tool use, which can lead to significant consequences given the upcoming EU AI Act. It proposes a deterministic control plane to separate reasoning from execution and enforce policies aligned with NIST and ISO standards to enable secure deployment of AI agents.

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

This weekly recap highlights several cybersecurity events including OpenAI's AI agent going rogue, a vulnerability in Check Point software, the emergence of 'slopsquatting' attacks, and a lure using 'ClickFix' to target users. The article emphasizes how subtle initial appearances can mask underlying threats and how established tools can be misused.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities, CVE-2025-68686 and CVE-2026-16812, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities affect Fortinet FortiOS and Arista VeloCloud Orchestrator, respectively, and pose significant risks. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize remediation of these high-risk vulnerabilities.

OpenAI not part of the new Open Secure AI Alliance

Nvidia has launched the Open Secure AI Alliance, an industry initiative aimed at developing strong, safe, and open-source AI cybersecurity tools. OpenAI is notably absent from the alliance, which was partly motivated by an incident where Hugging Face could not use OpenAI's closed-source models for defense during an attack.

Cognyte Sells a Mobile Cell Surveillance Van

Israeli surveillance company Cognyte is selling mobile cell surveillance vans, codenamed FalcoNet, to law enforcement. This technology acts as a simulated mobile phone tower, forcing nearby phones to connect, thereby allowing authorities to track devices in the vicinity.

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

A China-linked cybercrime group is utilizing a sophisticated crypter service named Cruciferra to deliver Windows malware. This crypter employs Bring Your Own Vulnerable Driver (BYOVD) and process ghosting techniques to evade detection by security software. Multiple threat clusters have been observed using Cruciferra, indicating its broad adoption in the cybercrime landscape.

The containment paradox: Why your ransomware playbook has the wrong people in charge

This article discusses the "containment paradox" in ransomware incident response, where the default action of isolating systems can cause more business damage than the malware itself. It highlights a gap in current incident response playbooks, which often fail to assign clear authority for deciding when to take critical business systems offline.

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

A critical vulnerability, CVE-2025-68686, has been identified in Fortinet FortiOS, allowing remote unauthenticated attackers to bypass existing patches and potentially access sensitive information. Attackers would first need to compromise the system at the filesystem level through another vulnerability to exploit this flaw.

Introducing Sophos AI Defense

Sophos has introduced Sophos AI Defense, a new product designed to leverage artificial intelligence for enhanced cybersecurity defenses. The system aims to provide visibility, control, and security through AI capabilities, addressing the growing need for advanced threat detection and response.

Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)

The ESAFENET CDG 3 Document Management System, a product primarily for the Chinese market, has been found to have basic security vulnerabilities including SQL Injection, XSS, and default passwords. This is not the first time ESAFENET CDG has been observed in scanning activities, particularly after a cross-site scripting vulnerability was disclosed.

Malicious sites use JavaScript to build malware in browser memory

A malvertising campaign is using deceptive webpages that leverage malicious JavaScript to construct malware within the browser's memory. This technique allows attackers to bypass traditional security measures by avoiding the creation of executable files on disk. The campaign specifically targets users of popular platforms like Solana, Luno, and TradingView.