CISA’s Known Exploited Vulnerabilities catalog has flagged thousands of flaws across routers, servers, and enterprise software. Until July 7, 2026, it had never listed a single vulnerability inside an AI agent platform until Langflow CVE-2026-55255 changed that. Security researchers had already caught attackers exploiting the flaw in the wild nearly two weeks before CISA’s confirmation landed. That gap should worry any SOC team, because most vulnerability-management programs still don’t track AI agent platform vulnerability categories the way they track servers and endpoints. Credentials, API keys, and cloud tokens sit inside these workflows in plain sight, and very few teams are…
Author: V Diwahar
This cybersecurity weekly report lands at an uneasy moment. Patch volumes keep breaking records, and quietly, the ransomware ecosystem is starting to automate itself. The week’s biggest story was the fallout from the FortiBleed credential-theft campaign, now formally tied to two active ransomware crews. Right alongside it: continued exploitation of a Microsoft SharePoint flaw that CISA has already added to its Known Exploited Vulnerabilities catalog. Qilin and DragonForce affiliates, for their part, kept up an aggressive pace of victim disclosures across manufacturing, telecom, and professional services. Here’s the strategic piece security leaders shouldn’t scroll past: the emergence of “agentic ransomware,”…
Mobile apps ship faster than most security teams can keep up with. A build that passed review in January might carry a new authentication flow, a new SDK, or a new payment integration by June. Each of those changes reopens the attack surface, whether anyone remembers to retest it or not. That’s the backdrop for mobile app penetration testing 2026, and it looks different from the annual check-the-box audits security teams got used to a few years ago. Regulation is tightening. Attackers have largely moved on from brute-forcing the client and started going after APIs and the third-party code bundled…
AI agents don’t just answer questions anymore. They browse websites, read internal documents, call APIs, and execute commands on behalf of the people who deployed them. That autonomy is what makes them useful. It’s also what’s created an entirely new security problem, and attackers have noticed. CrowdStrike’s researchers recently expanded their prompt injection taxonomy with 18 new techniques, pushing the total past 200 documented methods. Five of these deserve a closer look. They’re quiet by design, built to slip past reviews meant to catch obvious jailbreak attempts. That’s the uncomfortable part: these techniques don’t look like attacks until after they’ve…
Every SOC analyst evaluating the best SIEM tools 2026 has to offer runs into the same problem: the category has split into at least three different product types wearing the same three-letter acronym. There’s the classic log-search-and-correlate platform, the cloud-native pay-as-you-go service, and the newer AI-driven SecOps suite that bundles SIEM with XDR and SOAR. They are not interchangeable, and picking the wrong one means either drowning in per-GB ingestion bills or under-investing in detection depth. 2026 has added real complexity to this SIEM platform comparison. IBM sold QRadar’s SaaS business to Palo Alto Networks, pushing cloud customers toward Cortex…
This Cybersecurity weekly report covers a week where the real risk sat at the perimeter, not on the endpoint. Credential abuse was the theme that tied everything together. Researchers formally linked the FortiBleed campaign against Fortinet firewalls to two active ransomware operations, while Google and the FBI dismantled the NetNut residential proxy botnet that criminal groups had been renting to hide their password-spraying attacks. A new Microsoft SharePoint deserialization flaw landed in the CISA Known Exploited Vulnerabilities catalog with a two-day patch window. And law enforcement notched a genuine win: the extradition of an alleged Scattered Spider member to face…