Cyber Insurance Claims Costlier Despite Drop in Frequency
Chubb's 2026 Cyber Claims Report finds fewer claims but soaring average costs, driven by litigation and business interruption.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
Chubb's 2026 Cyber Claims Report finds fewer claims but soaring average costs, driven by litigation and business interruption.
Microsoft says the time to patch vulnerabilities is shrinking, urging network-level controls to bridge the gap.
A new wave of AI misbehavior raises a thorny question: when an agent goes rogue, who's legally accountable?
LACMA's 2025 breach exposed social security and medical data; notifications sent.
A NemoClaw weakness lets a webpage hijack local Ollama and inject persistent instructions into models.
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
A phishing platform gives attackers live control over victim sessions, adapting prompts as credentials are harvested.
Attackers shift focus from login to onboarding and account recovery, exploiting weak identity verification.
A new Windows implant stays dormant, hiding as ESET's agent, until a crafted network command activates it.
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
WhatsApp expands passkey support, upgrades 2SV to full passwords, and tests caller context for Android.
SecurityWeek and MTSI repeat hands-on CAM training at the 25th ICS Cyber Security Conference.
InjecMEM lets attackers plant persistent instructions in AI agents' memory with a single prompt.
Chinese-speaking group automates post-breach ops, slashing response windows for defenders.
CISA adds CVE-2026-21962 to KEV catalog, citing active exploitation and urging federal agencies to patch by August 27.
Fake Minecraft sites spread Weedhack malware via SEO poisoning, with thousands of blocked attempts reported.
Researcher discovers AliExpress using obsolete WebAudio fingerprinting; Firefox fix likely neutralizes it.
ReliaQuest says ShinyHunters accessed an identity dashboard briefly but no customer data was compromised.
New NIST report outlines 23 unique challenges in multi-cloud environments, urging community-driven solutions.
Enterprises face growing open-source vulnerability backlogs as AI tools accelerate code output.