Palo Alto Networks recovered a full session log of an AI agent enumerating targets and launching exploits after a single human prompt. It failed, but only because its targets happened to require authentication.
New H1 2026 data shows ransomware attacks on education falling overall while higher education rises, driven largely by a single group. At one university, attackers deleted the files after stealing them.
A subscription malware kit advertises an "AI Profiler" that ranks stolen machines by value. The credentials it prizes, SSH keys, cloud CLI tokens, .env files, are the ones sitting on research and developer laptops.
A vulnerability chain in WordPress core allowed full takeover of a stock installation with one anonymous request. Exploitation began about 90 minutes after the patch shipped, and campuses run more unmanaged WordPress than most central IT shops have mapped.
UT students Jared and Robert share how hands-on training at the RSOC, built on Hack The Box's platform, is preparing them to walk into a cybersecurity career on day one
Fake Google and Cloudflare verification pages are tricking visitors into pasting malicious commands into their own computers — and the campaign has already hijacked 700+ education and tech websites.
A new malware campaign called ChocoPoC hides inside the Python package dependencies of fake GitHub proof-of-concept exploits, targeting the very researchers who test vulnerabilities. Texas IT security teams that clone PoC code should take note.
A newly disclosed macOS flaw, CVE-2026-39118, let standard non-admin users silently disable CrowdStrike and Kandji endpoint protection. Here's what Texas institutions running Mac fleets need to know.
The "Cordyceps" vulnerability let anyone with a free GitHub account hijack CI/CD pipelines at Microsoft, Google and Apache. Texas campuses running their own GitHub Actions workflows should check for the same misconfiguration.