This period saw a flurry of critical security events, highlighted by a 9.8 CVSS vulnerability in Splunk Enterprise enabling unauthenticated RCE. In policy news, the U.S. government ordered Anthropic to restrict foreign access to its advanced AI models over national security fears. Meanwhile, law enforcement made a significant impact by disrupting 'Outsider Enterprise,' a massive China-based Phishing-as-a-Service operation. Other key developments include NPM's move to bolster supply chain security, an actively exploited zero-day in Google Chrome, and a major supply chain attack on the Arch Linux AUR.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.