ZeroHour

Source: Dark Reading

6 items in the last 3d

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

Microsoft shipped emergency out-of-band fixes to correct glitches from a record Patch Tuesday covering nearly 1,000 CVEs.

Dark Reading reports that Microsoft issued emergency fixes following a massive Patch Tuesday that addressed nearly 1,000 CVEs. The out-of-band updates correct glitches introduced by the record-sized monthly release. The brief excerpt names no specific CVEs, affected products, or actively exploited flaws.

Dark Reading · 2h agoVulnerability

Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident

OpenAI engineers will reconstruct the OpenAI–Hugging Face incident at Black Hat USA 2026, covering attack paths, safeguards, and autonomous-system risks.

A Black Hat USA 2026 session by OpenAI security engineers and researchers will technically reconstruct the OpenAI–Hugging Face incident and its implications for AI security, cyber resilience, and alignment. The talk will address Black Hat Review Board topics including model safeguards, evaluation and containment practices, and defensive uses of AI. It will trace the attack path involving frontier models and discuss implications of increasingly autonomous systems for cybersecurity practitioners.

VectraRAT Can Hack Windows Enterprises for $250 per Month

VectraRAT malware-as-a-service sells a Windows implant with C2 infrastructure and operator panel for $250 per month.

VectraRAT is a full-service malware-as-a-service platform offering a Windows implant, command-and-control infrastructure, and an operator panel for comprehensive remote access to infected enterprises. Subscriptions cost $250 per month, lowering the barrier for criminal operators. The platform bundles all components needed to run remote-access campaigns.

Dark Reading · 6h agoMalware

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

Russia-linked Sandworm chains Cisco vulnerabilities to deploy an upgraded Cyclops Blink botnet variant the FBI disrupted in 2022.

Dark Reading reports that Sandworm, the notorious Russia-linked threat group, is chaining Cisco vulnerabilities to deploy an upgraded version of the Cyclops Blink botnet malware. The FBI previously disrupted the Cyclops Blink botnet in 2022. The activity signals renewed botnet infrastructure building by the group despite prior law-enforcement action.

Dark Reading · 1d agoThreat actor in the wild

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

GitLab CVE-2026-85706 is a maximum-severity CVSS 10.0 path traversal flaw affecting Community and Enterprise Editions, risking supply chain compromise.

CVE-2026-85706 is a path traversal vulnerability with a CVSS score of 10.0 affecting GitLab Community Edition and Enterprise Edition instances. Exploitation could enable attackers to tamper with repositories, posing software supply chain risks. The report does not mention active exploitation.

Dark Readingupdated · 22h agofirst · 1d agoVulnerability 17 sourcesCVE-2026-857061

Anthropic CEO: Time to Shift From Improving to Controlling AI

Anthropic CEO Dario Amodei calls for slowing frontier AI capability gains so security and risk-control efforts can catch up.

Anthropic CEO Dario Amodei argues the AI industry should shift focus from improving frontier models to controlling them, slowing the pace of capability gains until security and risk-prevention measures mature. The Dark Reading piece examines what this stance means for enterprises deploying AI systems. It signals a major lab leader prioritizing controllability over raw capability progress.

Dark Reading · 1d agoAI safety & security 3 sources