Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost https://firewalls.firm.in/wp-content/uploads/2026/07/MAI-Cyber-1-Flash.jpg Swati KhandelwalJul 28, 2026AI Security / Vulnerability Management Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than ...
Read More »Vulnerabilities & Exploits
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available https://firewalls.firm.in/wp-content/uploads/2026/07/fastjson.gif Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked ...
Read More »Security breaches are inevitable, your response is not
Security breaches are inevitable, your response is not https://etimg.etb2bimg.com/thumb/msid-132555659,imgsize-124819,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/security-breaches-are-inevitable-your-response-is-not.jpg Enterprise security leaders have tried to prevent attacks for years. Boards invested in firewalls, perimeter defenses and access restrictions while measuring success by the absence of breaches. Yet, AI is increasing the speed and scale of attacks, causing organizations in India and around the world to reevaluate how they define security ...
Read More »ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories https://firewalls.firm.in/wp-content/uploads/2026/07/th.jpg Ravie LakshmananJul 23, 2026Hacking News / Cybersecurity News Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in ...
Read More »OpenAI says AI models went rogue during testing, triggering ‘unprecedented’ breach at startup
OpenAI says AI models went rogue during testing, triggering ‘unprecedented’ breach at startup https://etimg.etb2bimg.com/thumb/msid-132550729,imgsize-95548,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-at-startup.jpg FILE – The OpenAI logo appears on a mobile phone in front of a screen showing part of the company website in this photo taken on Nov. 21, 2023 in New York. (AP Photo/Peter Morgan, File) OpenAI said on Tuesday that an autonomous agent powered by ...
Read More »FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware https://firewalls.firm.in/wp-content/uploads/2026/07/github.jpg Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. “FakeGit uses copied projects, lookalike developer ...
Read More »New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code https://firewalls.firm.in/wp-content/uploads/2026/07/wordpress-core.jpg Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is ...
Read More »CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV https://firewalls.firm.in/wp-content/uploads/2026/07/sharepoint-cisa.jpg Ravie LakshmananJul 17, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The ...
Read More »Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft https://firewalls.firm.in/wp-content/uploads/2026/07/ms-device-code1.jpg A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains ...
Read More »Govt investigating reported Tata Electronics data leak
Govt investigating reported Tata Electronics data leak https://etimg.etb2bimg.com/thumb/msid-132159400,imgsize-236570,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/govt-investigating-reported-tata-electronics-data-leak.jpg The government has sought an explanation from WhatsApp over its username feature, saying it could facilitate cybercrime, while also investigating the reported data leak allegations involving Tata Electronics, Secretary, Ministry of Electronics and Information Technology (MeitY), S. Krishnan said on Friday. Speaking on the sidelines of a CII Conference, Krishnan responded to ...
Read More »
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India











