Why secure data movement is the Zero Trust bottleneck that no one talks about

All security programs are based on the same premise: once the system is connected, the problem is resolved. Open a ticket, launch a gateway, and push data through. end. That assumption is wrong. This is also the main reason why Zero Trust programs stall. A new study my team just published shows the numbers. The […]

Unpatched critical flaw exposes Hugface LeRobot to uncertified RCE

Ravi LakshmananApril 28, 2026Vulnerability/Network Security Cybersecurity researchers have detailed a critical security flaw affecting LeRobot, Hugging Face’s open-source robotics platform, which has approximately 24,000 GitHub stars. This could be exploited to lead to remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which is described as a case of untrusted data deserialization […]

A new handbook for the zero window era

When patching isn’t fast enough, NDR helps contain the next generation of threats. If you’ve been following advances in AI, you know that the exploit window, the short buffer that organizations relied on to patch and protect vulnerabilities after they were made public, is rapidly closing. Anthropic’s new model, Claude Mythos and his project Glasswing, […]

Chinese Silk Typhoon hacker extradited to US for coronavirus research cyber attack

Ravi LakshmananApril 28, 2026Cyber ​​espionage/vulnerabilities A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited from Italy to the United States. Xu Zewei, 34, was arrested by Italian authorities in July 2025 on suspicion of ties to a Chinese state-backed threat group and for orchestrating cyberattacks against U.S. […]

Microsoft patches Entra ID role flaw that allowed service principal takeover

Ravi LakshmananApril 28, 2026Vulnerability/Identity Management Administrative roles for artificial intelligence (AI) agents within Microsoft Entra ID could potentially enable privilege escalation and identity takeover attacks, according to new findings from Silverfort. Agent Identity Administrator is a privileged built-in role introduced by Microsoft as part of the Agent Identity Platform to handle all aspects of identity […]

Microsoft confirms active exploitation of Windows Shell CVE-2026-32202

Ravi LakshmananApril 28, 2026Vulnerability/Threat Intelligence Microsoft on Monday revised its advisory for a currently patched high-severity security flaw affecting Windows Shell, acknowledging that the vulnerability is indeed being actively exploited. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow attackers to access sensitive information. This issue was addressed as […]

Checkmarx confirms GitHub repository data posted to dark web after March 23rd attack

Ravi LakshmananApril 27, 2026 Checkmarx has revealed that an ongoing investigation related to a supply chain security incident has revealed that a cybercriminal group had published data related to the company on the dark web. “Based on current evidence, we believe this data comes from Checkmarx’s GitHub repository and that access to that repository was […]

Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

Ravie LakshmananApr 27, 2026Cybersecurity / Hacking Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have […]

Myths have changed the calculus of vulnerability discovery. Most teams are not ready on the repair side.

Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7th announcement. Initial reports describe powerful AI systems focused on cybersecurity that can identify vulnerabilities at scale and raise serious questions about how quickly organizations can verify, prioritize, and remediate discovered vulnerabilities. Subsequent discussions have largely focused on the pertinent question of whether this […]