Latest Updates
Security and municipal technology
Recent developments that may affect networks, public services, critical infrastructure, employees, Microsoft environments, and technology planning.
Security News
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
Read the original article →
Data Breach
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Read the original article →
Actively Exploited
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
Read the original article →
Actively Exploited
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
Read the original article →
AI & Technology
Police AI platform uses ‘Easter eggs’ to verify human review
Seldom used words, like "axolotl," a type of salamander, are inserted in Code Four's output, ensuring that law enforcement officers carefully review AI-generated content before submitting it into evidence.
Read the original article →
Security News
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
Read the original article →
Microsoft Security
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
Read the original article →
Government Technology
California’s cybersecurity chief to step down after 7 years
California State Chief Information Security Officer Vitaliy Panych will step down after seven years leading the state's cybersecurity efforts.
Read the original article →
Microsoft Security
Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.
Read the original article →
Microsoft Security
Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security t…
Read the original article →
AI & Technology
Colorado hires former ACF official to serve as principal director for AI architecture
Jane Yang, a former Administration for Children and Families official, is tasked with heading a new role in Colorado's technology bureau.
Read the original article →
AI & Technology
Oklahoma debuts internal AI platform with two ‘lighthouse’ tools for legislators, procurement
Oklahoma's new internal and enterprise artificial intelligence platform is designed to help state agencies build new tools.
Read the original article →
Government Technology
States may need to cut one-third of BEAD satellite awards after broadband data update
Changes to location eligibility, brought on by newly available data, arrive as the federal government's keystone broadband program moves into its final phases.
Read the original article →
Government Technology
Oregon names Nevada’s communications, policy lead as state privacy chief
Michael Hanna-Butros Meyering, Nevada's chief communications and policy officer, will now help Oregon translate privacy principles into practical decisions and repeatable processes, according to a state announcement.
Read the original article →
Microsoft Security
Email threat landscape: Q2 2026 trends and insights
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed…
Read the original article →
Microsoft Security
Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strength…
Read the original article →
Public Sector Security
A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution
A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vuln…
Read the original article →
Microsoft Security
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on M…
Read the original article →