F5 CVE-2026-94127 Targeted in Active Attacks
This vulnerability allows for unauthenticated remote code execution and shows how a missing bounds check—a classic programming error.
Editor
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.
This vulnerability allows for unauthenticated remote code execution and shows how a missing bounds check—a classic programming error.
The security and reliability of the code in AI models is a huge question mark, because the models are black boxes that aren’t accessible to outsiders. Matt Fredrikson, professor at Carnegie Mellon University and founder of Gray Swan AI, joins Dennis to talk about the challenge of assessing these models and how a community of […]
Let’s ask a simple question that seems to be getting lost in all of the credulous fervor around AI: How’s this working out for everyone?
September 21, 2026 | 3 min read
Dennis joins from the last LabsCon conference, which featured amazing keynotes from Prof. James Mickens on AI reality and myths, Katie Moussouris on why humans are more vital than ever in security, and Dino Dai Zovi on using hardware to break attack chains,
Active since at least August 2025, the malware represents a functional pivot from the threat actor's existing SparrowDoor backdoor.
Messages delivered through legitimate third-party email infrastructure had C-suite sender display names, custom signatures, and direct approval notes.