Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone (Thu, 17 Sep 2026)
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who
controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along
with
>> Read more
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar (Thu, 17 Sep 2026)
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is
compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
>> Read more
CISO's Expert Guide to Agentic Pentesting for Websites (Thu, 17 Sep 2026)
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how
autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
>> Read more
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America (Thu, 17 Sep 2026)
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin
America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
>> Read more
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads (Thu, 17 Sep 2026)
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking,
investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus
on the
>> Read more