Recent cybersecurity newsletters have highlighted a range of industry developments, including the intersection of artificial intelligence with trust and compliance, the ongoing adoption of enterprise browsers, and the challenges posed by stagnating security budgets. Reports also discuss the rapid integration of AI in security and development, with concerns about the lack of governance and the inefficiency of manual compliance processes compared to automated solutions. Additionally, there is commentary on the state of the National Vulnerability Database (NVD) and the broader CVE ecosystem, as well as the evolving landscape of software supply chain security.
Other industry updates include coverage of major incidents such as critical infrastructure hacks across the US and Canada, nation-state cyber operations, and breaches affecting telecom backbone providers. Notable discussions reference high-profile media coverage of Chinese cyber activity targeting American infrastructure, the use of AI agents in security operations centers, and the ethical implications of zero-day sales to foreign adversaries. These newsletters serve as a comprehensive resource for security leaders seeking to stay informed about current threats, technology trends, and strategic challenges in the cybersecurity domain.

See the reporting duties and controls this puts on the clock.
11 events from the most recent confirmed update back to the earliest known activity.
The Python Software Foundation declined a U.S. National Science Foundation grant because of contract language related to DEI requirements. The decision became a notable governance and funding dispute in the open-source community.
Chrome announced plans to make HTTPS the default protocol in 2026. The change is intended to reduce insecure HTTP usage and improve baseline web security.
Researchers reported a new Android banking malware family called Herodotus. It was notable for simulating human-like typing behavior to evade fraud and bot-detection systems.
A Russia-linked intrusion set using living-off-the-land techniques was reported targeting Ukrainian entities. The activity was attributed to Sandworm or a closely aligned actor.
Officials and reporting warned about Chinese access to U.S. critical infrastructure networks. The warnings underscored ongoing concern about pre-positioning in strategically important sectors.
Reporting said telecom backbone vendor Ribbon Communications was compromised in an operation attributed to a nation-state actor. The incident was presented as part of broader concern over telecom infrastructure targeting.
New research detailed physical attacks branded TEE.fail that undermine trusted execution environments across Nvidia, AMD, and Intel platforms. The disclosure expanded understanding of hardware-level risks to confidential computing protections.
F5 issued statements about a long-running nation-state intrusion that allegedly resulted in source code theft. The reporting also referenced claims involving 44 zero-days tied to the compromise.
News coverage highlighted hacktivist intrusions in Canada that affected industrial control environments. The reporting framed the activity as a notable escalation from typical website defacements or IT-only disruption.
Security reporting described a suspected nation-state supply-chain campaign using new Windows malware dubbed Airstalk. The malware reportedly abused VMware AirWatch/Workspace ONE MDM APIs for command-and-control.
Government contractor Conduent disclosed a major breach affecting over 10 million individuals. The incident was reportedly claimed by the SafePay ransomware group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.