WebNews
Please enter a web search for web results.
NewsWeb
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited
1+ day, 2+ hour ago (1393+ words) Here's an overview of some of last week's most interesting news, articles, interviews and videos: Mimecast makes enterprise email security deployable in minutes Ranjan Singh, Chief Product and Technology Officer at Mimecast, outlines how the company's API-based approach delivers protection…...
FortiClient EMS zero-day exploited, emergency hotfixes available (CVE-2026-35616)
1+ day, 19+ hour ago (241+ words) Defused Cyber has spotted a critical Fortinet FortiClient Endpoint Management Server (EMS) zero-day vulnerability (CVE-2026-35616) being exploited in the wild. This time around, the confirmation of active exploitation came almost immediately from Fortinet, as well. "Fortinet has observed [CVE-2026-35616] to…...
Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)
2+ day, 21+ hour ago (345+ words) Cisco has fixed ten vulnerabilities affecting its Integrated Management Controller (IMC), the most critical of which (CVE-2026-20093) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. Cisco Integrated Management Controller is a built-in…...
Claude Code source leak exploited to spread malware
2+ day, 23+ hour ago (411+ words) A source code leak involving Anthropic's Claude Code tool quickly escalated into a cybersecurity threat, as attackers seized on the exposed files to lure developers into downloading malware disguised as "unlocked" versions of the software. On March 31, 2026, Anthropic accidentally exposed…...
Windows Security app gets Secure Boot certificate status indicators as 2026 expiration approaches
2+ day, 22+ hour ago (412+ words) Microsoft's Secure Boot certificates, issued in 2011, are approaching expiration in 2026. To help IT administrators track whether devices have received replacement certificates, Microsoft has added new status indicators to the Windows Security app, under Device security > Secure Boot. Updated 2023 certificates are…...
APERION releases SmartFlow SDK for secure, on-prem AI governance without cloud reliance
3+ day, 2+ hour ago (324+ words) APERION launched SmartFlow SDK, providing a secure, on-premises path for enterprises migrating away from compromised cloud-based AI gateways. The launch coincides with a 200% increase in web traffic since the March 24 LiteLLM supply chain attack that compromised an estimated 36% of all…...
Trivy supply chain attack enabled European Commission cloud breach
3+ day, 3+ hour ago (468+ words) CERT-EU confirmed that ShinyHunters are behind the recent breach of the cloud infrastructure underpinning websites of the European Commission, and that they stole and subsequently leaked approximately 340 GB of data. "Analysis of the published dataset has so far confirmed the…...
Microsoft releases open-source toolkit to govern autonomous AI agents
3+ day, 4+ hour ago (353+ words) The Agent Governance Toolkit is a seven-package system available in Python, TypeScript, Rust, Go, and .NET. Each package addresses a distinct layer of agent governance: "A governance toolkit is only useful if it works with the frameworks people actually use....
Which messaging app takes the most limited approach to permissions on Android?
3+ day, 5+ hour ago (443+ words) Messaging apps handle sensitive conversations, contacts, and media, and their behavior on a device varies in ways that affect privacy. An analysis of Android versions of Messenger, Signal, and Telegram shows that differences in permissions, background activity, and system exposure…...
Click, wait, repeat: Digital trust erodes one login at a time
3+ day, 5+ hour ago (773+ words) Sign-up forms that drag on, login steps that repeat, and access requests that take longer than expected have become a normal part of using digital services. These moments rarely stand out on their own, and over time they influence how…...