116 stories
Wiz Red Agent Breaches Snowflake’s Internal Jira Through a GitHub Actions Flaw Missed by Security ScanningNew
cybersecurityTrendingvia Wiz Research

Wiz Red Agent Breaches Snowflake’s Internal Jira Through a GitHub Actions Flaw Missed by Security Scanning

Wiz says its autonomous Red Agent discovered and exploited a GitHub Actions injection in a Snowflake repository just five days after the flaw went live, reaching internal Jira data during controlled testing.

about 17 hours ago10 min read
Tesla Reportedly Prepares August Cybercab Launch, Starting With Employee RidesNewTrending
tech-industryvia The Information, with reporting from Reuters

Tesla Reportedly Prepares August Cybercab Launch, Starting With Employee Rides

Tesla is reportedly preparing to launch its purpose-built Cybercab in Austin this month, beginning with employee rides before adding the vehicles to its robotaxi service.

about 19 hours ago8 min read
SafePal Discloses Data Breach Affecting Nearly 40,000 CustomersTrending
data-breachesvia SafePal

SafePal Discloses Data Breach Affecting Nearly 40,000 Customers

SafePal says an authorization flaw exposed order information belonging to about 39,798 customers. Wallet credentials and funds were not affected, but the data could enable targeted phishing and impersonation.

1 day ago5 min read
Hackers Raid French Tax Systems, Exposing Data of Nearly 900,000 AccountsTrending
cybersecurityvia AFP, as published by The Star

Hackers Raid French Tax Systems, Exposing Data of Nearly 900,000 Accounts

Hackers breached French tax and land registry systems in separate attacks, exposing data linked to at least 678,000 individuals and professional accounts, plus 200,000 land registry accounts.

2 days ago4 min read
New DRAM Scrambling Attack Challenges CPU Memory Security BoundariesTrending
cybersecurityvia GitHub research project

New DRAM Scrambling Attack Challenges CPU Memory Security Boundaries

Security researcher Christopher Domas has demonstrated a DRAM scrambling technique on AMD Family 16h processors that can remap physical memory addresses and expose protected memory regions beneath conventional CPU security boundaries.

5 days ago9 min read
Google Cloud Brings Measures to BigQuery Graphs for More Trusted Agentic WorkloadsTrending
ai-mlvia Google Cloud Blog

Google Cloud Brings Measures to BigQuery Graphs for More Trusted Agentic Workloads

Google Cloud is adding measures to BigQuery Graphs in preview, combining governed business metrics with relationship-aware graph analysis so AI agents can reason across complex enterprise data with greater consistency.

5 days ago6 min read
Apple Explains Its Threat Notifications for Mercenary Spyware TargetsTrending
cybersecurityvia Apple Support

Apple Explains Its Threat Notifications for Mercenary Spyware Targets

Apple says its threat notifications are high-confidence warnings for users individually targeted by mercenary spyware. The company explains how alerts are delivered, how to verify them, and what users should do next.

5 days ago7 min read

Get this in your inbox every morning

One daily email with the cyber and tech stories that matter, curated by Xcademia editors. No spam, unsubscribe anytime.

City-Forum Campaign Targets Salesforce and ServiceNow Guest AccessTrending
cybersecurityvia Reco.ai

City-Forum Campaign Targets Salesforce and ServiceNow Guest Access

A long-running campaign is targeting Salesforce Experience Cloud and ServiceNow portals by abusing overly permissive guest access. Reco says the activity uses custom tooling to enumerate exposed data across organisations worldwide.

6 days ago8 min read
WordPress 7.0.4 Fixes High-Risk Imagick RCE Vulnerability Through Malicious File UploadsTrending
cybersecurityvia WordPress News

WordPress 7.0.4 Fixes High-Risk Imagick RCE Vulnerability Through Malicious File Uploads

WordPress 7.0.4 addresses CVE-2026-65640, an authenticated remote code execution vulnerability involving Imagick and Ghostscript. Administrators are urged to update, particularly on sites with multiple users who can upload files.

6 days ago4 min read
WindRelay and SpyNote Combine in a New NFC Payment Fraud SchemeTrending
cybersecurityvia Group-IB

WindRelay and SpyNote Combine in a New NFC Payment Fraud Scheme

Group-IB has uncovered WindRelay, an NFC relay malware used with SpyNote RAT in a social-engineering campaign that combines Android remote access with fraudulent card transactions.

6 days ago7 min read
Cisco Firewall Zero-Day CVE-2026-20349 Exploited in the WildTrending
cybersecurityvia Cisco Security Advisory

Cisco Firewall Zero-Day CVE-2026-20349 Exploited in the Wild

Cisco has confirmed active exploitation of a high-severity vulnerability in its Secure Firewall ASA and FTD software that can let unauthenticated attackers remotely force affected devices to reload, causing denial of service.

6 days ago7 min read
Google Cloud Brings Looker’s Governed Data Layer to Gemini EnterpriseTrending
ai-mlvia Google Cloud Blog

Google Cloud Brings Looker’s Governed Data Layer to Gemini Enterprise

Google Cloud is integrating Looker’s governed semantic layer with Gemini Enterprise, helping AI agents deliver trusted business metrics, deterministic SQL, interactive charts, and permission-aware data access.

7 days ago8 min read