#still


GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Sep 26, 2026 // 17:36

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite […]

Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

Sep 23, 2026 // 14:47

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to […]

Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

Sep 8, 2026 // 17:59

Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin’s public record shows. About […]

Why Even the Best Edge Security Still Misses High-Risk Sessions

Sep 1, 2026 // 19:17

Security teams have more edge controls at their disposal than ever, and each plays an important role. Yet, despite the best request inspection, credential validation, […]

AI Can Find Bugs, But Human Knowledge Still Proves Them

Jul 16, 2026 // 13:42

Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it […]

The Exploit Doesn’t Exist. You Can Still Prove It Works Against You

Jun 23, 2026 // 17:16

For thirty years, vulnerability management has run on what now looks like an impossible luxury: a buffer of months between when a vulnerability was found […]

Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive

Jun 16, 2026 // 14:30

Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence […]

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

May 6, 2026 // 00:48

Every AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind: a persistent OAuth token with […]

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Apr 17, 2026 // 16:24

Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity […]

Compromised Credentials Bypass MFA; Attackers Still Gain Access.

Apr 9, 2026 // 18:37

The data leak at Figure compromised 967,200 email accounts without relying on any software flaws. Understanding the implications of this, and why typical MFA solutions […]

1 2 Next