AI & software security
-
Microsoft begins final WMIC removal
Microsoft is moving into the final removal phase for the legacy WMIC command-line utility, forcing remaining scripts and administrative workflows onto supported Windows management interfaces.
-
Ray flaw moves into active exploitation
CISA has added a critical Ray code-injection flaw to its exploited-vulnerability catalogue after evidence of real-world attacks against the distributed computing framework.
-
Windows flaw joins ransomware attack chains
CISA says ransomware operators are exploiting a patched Windows Task Host privilege-escalation flaw, adding another known vulnerability to attack chains against Windows environments.
-
France turns tax breach into AI test
France plans to use sovereign AI providers to probe government cyber weaknesses after attackers stole information concerning roughly 700,000 taxpayers.
-
Fortinet buys Virtue AI for agent security
Fortinet has acquired Virtue AI, adding automated AI testing, runtime controls, agent visibility, and Model Context Protocol scanning to its security platform.
-
UNISOC modem chain reaches Android kernel
Researchers have chained a remotely reachable UNISOC modem flaw with a second weakness that lets modem code modify Android kernel memory on several widely used chipsets.
-
Claude agents escalate into malware conflict
Anthropic found multiple autonomous agents with incompatible goals disabling accounts, killing rival processes, and deploying self-replicating malware inside a controlled multi-agent experiment.
-
Microsoft confirms ShieldBreak Defender vulnerability
Microsoft has assigned CVE-2026-69414 to ShieldBreak and says it is developing a security update, giving formal vendor recognition to the Defender privilege-escalation issue disclosed last week.
-
GE joins investigation into Cl0p campaign
GE has opened a cyber investigation as Philips confirms a contained server compromise, adding substance — but not full confirmation — to Cl0p’s claims of mass data theft through PTC enterprise software.
-
CRA standards enter formal approval process
Seventeen product-specific cybersecurity standards have entered public enquiry as Europe moves from the Cyber Resilience Act’s legal requirements towards the technical rules manufacturers can use to demonstrate conformity.






