Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component - CVE-2026-15719, a site isolation in the DOM: Navigation component "We are aware that exploit code for this is public, however we are not aware of any attacks in the wild abusing this flaw," Mozilla said in an advisory. Both vulnerabilities have been addressed in Firefox version 152.0.6. The release comes as Google shipped fixes for 15 security flaws, including two critical use-after-free bugs in Ozone (CVE-2026-15764 and CVE-2026-15765), a cross-platform abstraction layer that allows the browser to interact natively with various display servers and windowing systems. It supports Linux, ChromeOS, and Fuchsia. "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page," according to a description of CVE-2026-15764 in the NIST National Vulnerability Database (NVD). The shortcomings have been patched in Chrome version 150.0.7871.124/.125 for Windows and Mac and 150.0.7871.124 for Linux. In a related development, Adobe has published security updates for 88 vulnerabilities, including multiple critical-severity bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. Of these, eight impact Adobe ColdFusion - - CVE-2026-48318 (CVSS score: 9.9) - A path traversal vulnerability that could lead to arbitrary code execution - CVE-2026-48322 (CVSS score: 9.6) - A code injection vulnerability that could lead to arbitrary code execution - CVE-2026-48284 (CVSS score: 9.6) - An improper input validation vulnerability that could lead to arbitrary code execution - CVE-2026-48321 (CVSS score: 9.3) - An incorrect authorization vulnerability that could lead to privilege escalation - CVE-2026-48325 (CVSS score: 9.3)
Jul 16, 2026 · via thehackernews.com
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning Common Vulnerabilities and Exposures (CVE) identifiers to reported vulnerabilities. The guidance also provides considerations for leveraging third-party intermediaries, like CISA or other national computer security incident response teams, to substitute or supplement a CVD program. By implementing a robust CVD program aligned with this guidance, organizations can work transparently and collaboratively with security researchers to remediate vulnerabilities, build constructive relationships, enhance product security while improving vulnerability management processes, and demonstrate their dedication to protecting customers.
Jul 16, 2026 · via cisa.gov
Important NEW Update Regarding P&A Group Cybersecurity Incident from NCFlex We have collaborated with P&A Group to address our concerns following the recent cybersecurity incident. At this time, we believe data transmission can safely resume. To protect sensitive information moving forward, several safeguards have been implemented. These include a web application firewall (WAF) to block malicious traffic, system hardening—which involves updating software and restricting access to minimize vulnerabilities—increased network segmentation to isolate critical systems, and an investigation into GovRAMP to ensure P&A Group's practices align with state policies for safeguarding sensitive data. Participant organizations are requested to coordinate with P&A Group regarding the transmission of delayed data feeds. The staff at P&A Group will prioritize processing these feeds. We want to thank all participant organizations for their patience and commitment throughout the remediation of this cybersecurity incident with P&A Group. We especially appreciate the prompt responses from participant organizations and the expert guidance provided by the NC Department of Information Technology Enterprise Security and Risk Management Office (ESRMO) and the NC Office of the State Controller during this process. Your understanding and cooperation have been invaluable. We remain dedicated to upholding rigorous cybersecurity standards and will continue to prioritize the safety of all participant data. Thank you again for your partnership. This article has the following tags: Human Resources Benefits
Jul 15, 2026 · via uncw.edu
MADISON, Wis.— TruStage Financial Group shut down its network due to a cybersecurity incident on Wednesday.
In a statement to News 3 Now spokesperson Barclay Pollak said the company activated its incident response and recovery efforts including shutting down the network. Additionally, cybersecurity experts are assisting with investigating, containing and remediating the incident, according to Pollak.
TruStage is an insurance provider based in Madison. The company said the investigation remains ongoing
COPYRIGHT 2026 BY CHANNEL 3000. ALL RIGHTS RESERVED. THIS MATERIAL MAY NOT BE PUBLISHED, BROADCAST, REWRITTEN OR REDISTRIBUTED.
Jul 15, 2026 · via channel3000.com
TruStage announces systems are down following cybersecurity incident
MADISON, Wis. (WMTV) - TruStage announced Wednesday that their systems were down following a cybersecurity incident.
According to a TruStage press release, the company found a cybersecurity incident affecting its environment and immediately activated its incident response and recovery protocols.
“Protecting the trust of the organizations and individuals TruStage serves is a core priority,” TruStage said in the release. “The company is approaching this matter responsibly and transparently, with a focus on supporting business partners, clients and other stakeholders while response efforts continue.”
TruStage is working to understand the facts and will provide updates when appropriate.
Click here to download the WMTV15 News app or our WMTV15 First Alert weather app.
Copyright 2026 WMTV. All rights reserved.
Jul 15, 2026 · via wmtv15news.com
The U.S. will formally bring together AI developers and essential services providers to share information on cybersecurity vulnerabilities identified by advanced AI systems and coordinate responses, according to a White House statement, fulfilling U.S. President Donald Trump’s order from June. Companies including Anthropic and OpenAI have released powerful AI systems capable of identifying software and infrastructure vulnerabilities at scale. U.S. officials worry that bad actors could use them to exploit weaknesses in the software systems underpinning critical services — including those of financial institutions, hospitals and energy networks — relied upon by Americans. The Trump administration set up a coordination group between leading AI developers and the essential services providers so they can share information about vulnerabilities they have discovered in their software and not duplicate efforts. The arrangement includes developers of open-source AI models, said White House cyber director Sean Cairncross. Cairncross did not specify which developers are involved. In the U.S., Nvidia, Meta Platforms and the startup Reflection offer open-source options. Trump in a June executive order directed the Treasury Department, National Cyber Director’s Office, Department of Defense and National Security Agency to set up the collaboration. This is the latest example of the Trump administration playing a more active role in the AI sector. Trump at the beginning of his second term said he would take a hands-off approach to the technology. That has shifted in recent months, with his administration taking a more active role in monitoring AI’s capabilities and considering the national security risks they present. (Reporting by Rozen in Washington; Writing by Bhargav Acharya; Editing by David Ljunggren and Matthew Lewis) Was this article valuable? Here are more articles you may enjoy.
Jul 15, 2026 · via claimsjournal.com
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed to remove before shipping," Palo Alto Networks Unit 42 said. "Although the LLM clearly aided in constructing the botnet, several functions in the analyzed samples failed to work correctly." The cybersecurity company said a manual code review would have resolved these errors and that it's possible more polished iterations of the malware exist out there in the wild. The botnet framework consists of multiple components: a C-based bot agent that cross-compiles for multiple architectures (e.g., ARM, MIPS, MIPSEL, MIPS64, x86_64, PowerPC, and RISC-V), a Go-based command-and-control (C2) server with a DDoS-for-hire panel, a custom exploit virtual machine, Docker-based test infrastructure, and an automated build system. The bot agent is designed to brute-force Telnet access on targeted devices with a set of 1,496 credential pairs, as well as incorporate exploit code targeting more than 30 IoT device families using known vulnerabilities. It communicates with the C2 server over an encrypted TCP channel, while resorting to a SHA512 domain generation algorithm (DGA), peer-to-peer (P2P) gossip protocol with Ed25519-signed commands, Internet Relay Chat (IRC), DNS TXT queries, and HTTP polling as a fallback mechanism. The modular framework's lineage has been traced back to three different botnets, like Mirai, AISURU, and Wuhan, in addition to partially porting some of its functions from the open-source MHDDoS Python DDoS toolkit. At least one sample of the malware was uploaded to the VirusTotal platform on January 20, 2026, indicating it has been around for over six months. Evidence suggests that
Jul 15, 2026 · via thehackernews.com
MADISON (WKOW) -- Insurance, investment and technology provider TruStage announced on Wednesday that it had been impacted by a cybersecurity incident.
According to a news release, the company engaged external cybersecurity experts to support containment, remediation and recovery efforts.
TruStage said it is working to understand the facts and will communicate as its understanding of the situation evolves. "Protecting the trust of the organizations and individuals TruStage serves is a core priority," the news release stated.
27 News reached out to TruStage for more information about the scope of the incident. Spokesperson Barclay Pollak said, "We are working as quickly and diligently as possible to determine the scope and impact of the incident, and do not yet have a confirmed timeline for when more details will be available."
Jul 15, 2026 · via wkow.com
Why Cybersecurity in AMI Networks Demands Open Standards Wi-SUN AllianceWi-SUN Alliance Smart meters are transforming how utilities operate. But every connected endpoint is also a potential point of cyber-attack. Standardized, IT-grade security — the foundation of Wi-SUN Field Area Network (FAN) — is the only durable defense for advanced metering infrastructure. Connecting meters and making them intelligent has driven one of the most consequential operational shifts at utilities over the past decade and a half. Advanced metering infrastructure (AMI) 1.0 has moved utilities from monthly truck rolls to continuous, granular visibility, and the operational gains are hard to overstate: A foundation has been laid for today’s advanced AMI 2.0 use cases. AMI 2.0 networks will place additional edge intelligence demands at the meter for waveform capture and analysis, load disaggregation, EV charging coordination, and distributed energy resource integration. However, the advantages of digitization create new challenges by expanding the cybersecurity attack surface of AMI systems. While much of a utility’s kit is locked within a substation’s physical perimeter or pole-mounted enclosures, an AMI network is the opposite. It’s distributed across an entire service territory, with every single endpoint physically accessible to anyone who can reach a meter base. There is no AMI perimeter to defend in the traditional sense, because the perimeter is everywhere. This accessibility changes the level of required security. Protecting each endpoint from rogue access is critical to protect the network, the system behind it, and the privacy of the consumption data tied to every customer. Compromising one meter cannot, under any circumstance, be allowed to compromise the network of meters or the services that ride on top of it. This is exactly how sophisticated attackers operate. They don’t break down the front door. They find the weakest entry point in the network, get in, and move
Jul 15, 2026 · via iotforall.com
BEIJING – The Chinese Foreign Ministry on Tuesday accused the United States of repeatedly using "cybersecurity" as an excuse to smear China for its geopolitical agenda, saying China is strongly dissatisfied with and firmly opposes this.
Ministry spokesperson Lin Jian made the remarks at a daily news briefing, in response to media reports that the United States and Paraguay had detected infiltration into the Paraguayan government's cyber systems, which they said was linked to China.
READ MORE: US's repeated use of 'cybersecurity' as excuse to smear China firmly opposed
Lin made it clear that China is against hacking and combats it in accordance with the law. Meanwhile, China is firmly against politically motivated disinformation concerning cybersecurity.
The US has long engaged in systemic global cyber attacks and made other countries join it in slandering China on cybersecurity, only to advance its own geopolitical agenda, he said, adding that China strongly deplores and firmly rejects this.
"We urge those countries not to be used as geopolitical tools and accomplices of the US government in spreading the 'Chinese cyber attack' disinformation," said the spokesperson.
Jul 15, 2026 · via chinadailyasia.com
(CNN) — The White House is establishing a new AI cybersecurity clearinghouse to help coordinate cybersecurity defenses across critical infrastructure. Industries and critical infrastructure are racing to catch up with new AI models with increasingly advanced abilities that can find and exploit (but also defend against) cybersecurity vulnerabilities. Some AI companies have even held off widely releasing their most advanced models to allow key partners time to patch vulnerabilities before the models are widely available. The White House’s clearinghouse, dubbed Gold Eagle, is a joint project across the Treasury, the Department of Homeland Security and the Pentagon. AI and cybersecurity companies, along with critical infrastructure providers like utilities and banks, will use the platform to communicate and coordinate their efforts. “These new capabilities make vulnerability discovery at a scale … that we have not seen before,” a senior White House official told reporters during a briefing on Tuesday. The goal of the new clearinghouse is to “deconflict and make sure resources are not being wasted, fixing or scanning for the same vulnerabilities, that those vulnerabilities are validated,” the official added, “and then a team of industry and government engineers are working to triage, prioritize and fix those vulnerabilities.” The White House declined to specify which companies are part of this project, describing them as “open-source software partners and American critical infrastructure companies.” Open-source software’s source code is publicly available, allowing anyone to freely view, use, modify and distribute it. The most well-known AI models from companies like OpenAI, Google and Anthropic, are closed-source. Open-source software is ubiquitous but often run by volunteers who might not have the money and time to secure the code. In 2021, a critical bug in open-source software left hundreds of millions of devices around the world vulnerable to hacking and triggered a frantic response from
Jul 14, 2026 · via news8000.com
The White House is establishing a new AI cybersecurity clearinghouse to help coordinate cybersecurity defenses across critical infrastructure. Industries and critical infrastructure are racing to catch up with new AI models with increasingly advanced abilities that can find and exploit (but also defend against) cybersecurity vulnerabilities. Some AI companies have even held off widely releasing their most advanced models to allow key partners time to patch vulnerabilities before the models are widely available. The White House’s clearinghouse, dubbed Gold Eagle, is a joint project across the Treasury, the Department of Homeland Security and the Pentagon. AI and cybersecurity companies, along with critical infrastructure providers like utilities and banks, will use the platform to communicate and coordinate their efforts. “These new capabilities make vulnerability discovery at a scale … that we have not seen before,” a senior White House official told reporters during a briefing on Tuesday. The goal of the new clearinghouse is to “deconflict and make sure resources are not being wasted, fixing or scanning for the same vulnerabilities, that those vulnerabilities are validated,” the official added, “and then a team of industry and government engineers are working to triage, prioritize and fix those vulnerabilities.” The White House declined to specify which companies are part of this project, describing them as “open-source software partners and American critical infrastructure companies.” Open-source software’s source code is publicly available, allowing anyone to freely view, use, modify and distribute it. The most well-known AI models from companies like OpenAI, Google and Anthropic, are closed-source. Open-source software is ubiquitous but often run by volunteers who might not have the money and time to secure the code. In 2021, a critical bug in open-source software left hundreds of millions of devices around the world vulnerable to hacking and triggered a frantic response from Biden administration
Jul 14, 2026 · via cnn.com
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. "Once deployed, it can profile the host, identify security tools, receive operator commands, move files, capture screenshots, and proxy traffic through the affected system." The implant also supports multiple communication methods, including HTTPS, WebView2, and DNS tunneling, allowing attackers to maintain access to compromised hosts even if one pathway is detected and closed off. There are some signs that LabubuRAT is being offered under a malware-as-a-service (MaaS) model. The starting point of the attack chain is an executable named "nvidia-sysruntime.exe," which impersonates NVIDIA's container runtime toolkit. The sample, instead of hard-coding its command-and-control (C2) information, accepts a runtime configuration through command-line arguments. This allows the campaign operator to define various parameters that are key to establishing communication with the remote server, including the server details ("pipicka[.]xyz") and the polling interval used by the implant. Alternatively, the attacker can also supply these individual values in the form of one single Base64-encoded argument. "Because those values were provided at launch, the same compiled binary could be reused with different infrastructure, organizations, or campaign groupings instead of relying on a hard-coded server," the researchers noted. The configuration is then stored in a local SQLite database, following which it undertakes discovery operations to inventory the list of web browsers and security products installed on the host, specifically checking for the presence of Google Chrome, Mozilla Firefox, Microsoft Edge, Brave, Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, Sophos, Malwarebytes, Bitdefender, ESET, Kaspersky, McAfee, Symantec, and Trend Micro. In addition, it gathers the hostname, RAM size, CPU model, and the Windows
Jul 14, 2026 · via thehackernews.com
Nebraska is ‘taking cybersecurity serious,’ says state’s CISO
Nebraska Chief Information Security Officer Bryce Bailey said he understands why confidence levels are down among state CISOs, but that he’s not backing down.
This video interview was recorded at the National Association of State Chief Information Officers midyear conference in Philadelphia on April 27 and April 28, 2026.
Jul 14, 2026 · via statescoop.com
Nebraska’s ‘whole of state approach’ to cybersecurity
Nebraska Chief Information Security Officer Bryce Bailey said he wants to “hone in” on his state’s “whole of state” approach to cybersecurity.
This video interview was recorded at the National Association of State Chief Information Officers midyear conference in Philadelphia on April 27 and April 28, 2026.
Jul 14, 2026 · via statescoop.com
Search
Media & Resources
© Arc, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
Jul 14, 2026 · via cutimes.com
Technology advisors are increasing their cybersecurity sales as vendors and customers embrace a broker model, but their opportunities may narrow as they court larger businesses. The lion’s share of TA security sales has been through managed services providers. The enterprise market, where firms prefer point solutions they can manage, remains a challenge. “When I run into somebody who says, 'We want to do it all; we're all inside,' that's a tough sell as an advisor,” Cloud Communications Group CISO and AI Practice Lead Mike Stute told Channel Dive. The TA channel has a limited set of unmanaged point solutions. Legacy cybersecurity vendors historically went through resellers rather than brokers. However, the TA vendor line card is loaded with end-to-end managed security service providers for customers who want to hand over control. TAs are left with three options: clamor for tech services distributors to sign security software providers, sign direct agreements with those providers, or wait for big logos to warm to co-managed models. A segmentation problem The self-management barrier is an enterprise problem, as managed and co-managed models dominate among small and even midmarket customers. A recent Cynet survey found that 71% of SMBs use MSPs for security, with co-managed the most common strategy. Team KC Telecom Founder Cynthia Ferrell said the firm almost exclusively recommends MSSPs to its midsize client base. Although clients in the 200- to 250-employee range often balk at MSSPs charging up to $50 per endpoint per month, they lack the staff and expertise to do it themselves. “At best, I have a network sysadmin and an IT manager,” Ferrell said. “Sometimes I just have one person doing all of that. I tell them, 'You absolutely do not have the time to manage this when you're wearing 27 hats. If you're going to pay for managed
Jul 14, 2026 · via channeldive.com
The ACC has a new multiyear deal with ReliaQuest, making the Tampa-based company the official cybersecurity sponsor of the conference. The multiyear deal was struck in conjunction with Disney Advertising and ESPN, and as part of the pact, both sides are committing to help raise awareness of cybersecurity and cybersecurity careers through ReliaQuest’s proven cyber labs program.
The deal covers each of the ACC’s 28 sponsored sports and will begin in the fall. The ACC has now doubled its portfolio of corporate sponsors over the past five years.
ReliaQuest has been involved in college football through a bowl game sponsorship in its home market since 2022 (the former Outback Bowl at Raymond James Stadium, which pits Big Ten and SEC teams). ReliaQuest founder and CEO Brian Murphy is a Florida State alum and member of the FSU BOT. The company also has a sponsorship deal with the PGA Tour.
Jul 14, 2026 · via sportsbusinessjournal.com
White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated system to receive and patch cyber vulnerabilities at a speed and scale never seen before using the existing authorities and resources of the federal government. The White House, the Department of the Treasury (Treasury), the Department of Homeland Security (DHS) through the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of War (DOW) have worked closely with industry partners to enable faster exploit detection and develop a rapid and prioritized response to cyber vulnerabilities across our critical infrastructure sectors. “Under President Trump’s leadership, the Treasury Department is working hand in hand with the private sector to safeguard our financial institutions, close vulnerabilities, and protect the integrity of the U.S. financial system,” said Secretary of the Treasury Scott Bessent. “Treasury, along with our partner agencies, will continue to harness frontier AI capabilities to stay ahead of our adversaries and defend the American people from emerging threats.” GOLD EAGLE, established in President Trump’s June 2, 2026 Executive Order “Promoting Advanced Artificial Intelligence Innovation and Security” (EO 14409), represents a new operational model for cyber defense. This new model will leverage frontier AI capabilities to continue advancing faster than adversaries, reduce duplicative scanning efforts, and deliver prioritized and actionable threat and remediation information to defenders across the Federal government and the private sector. “Under the leadership of President Trump, we are bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities,” said Secretary of War Pete Hegseth. “GOLD EAGLE serves as the vanguard of America’s cyber defense. We
Jul 14, 2026 · via whitehouse.gov
CYBERSECURITY BREAKING: Pentagon’s CMMC Pause Draws Praise, Criticism from Industry By Josh Luckenbaugh iStock illustration The Defense Department on July 13 suspended the Phase 2 requirements for its Cybersecurity Maturity Model Certification program and initiated a review of the effort, drawing both praise and criticism from experts. Phase 2 of the program, which was scheduled to start Nov. 10, would have introduced in applicable Pentagon solicitations requirements for contractors handling controlled unclassified information to be certified by a CMMC third-party assessment organization, or C3PAO. Citing Small Business Administration data, the department in a release said CMMC compliance is forcing innovative companies out of the defense industrial base, which will delay the delivery of critical capabilities to U.S. warfighters. As a result, it is suspending the transition to Phase 2, as well as pending and future CMMC implementation milestones. Pete Sfoglia, co-founder and CEO of Pistos Information Protection, said the suspension of Phase 2 is an overdue admission from the department that after decades of indifference to how small and medium-sized companies safeguarded controlled unclassified information, the Pentagon through CMMC “demanded they become experts in a discipline that was never their core competency.” Full implementation of the security requirements outlined in National Institute of Standards and Technology Special Publication 800-171 “plus the cost of C3PAO assessments was cost-prohibitive on its face, and the predictable outcome was not a more secure industrial base but a smaller one,” Sfoglia said. “The right move now is not to delay the burden but to rethink who bears it." In a statement provided to National Defense, authorized C3PAO Redspin said while the department is exercising existing flexibility allowing it to suspend pending CMMC implementation milestones, it is not rescinding the program. “For organizations in the defense industrial base, this suspension means more time to prepare, not
Jul 14, 2026 · via nationaldefensemagazine.org