Cybersecurity
Data breaches, zero-day exploits, ransomware campaigns, patch advisories, and privacy regulation. We cover the threats, the fixes, and the policies that shape digital security, written so you do not need a CISSP to follow along.
Latest Stories
A Major Ransomware Attack Has Hit NHS Systems Across England
A ransomware attack on NHS systems across England disrupted patient record access, appointment scheduling, and internal communications at multiple trusts in lat
SecurityCritical VMware and Cisco Flaws Are Under Active Attack: Patch This Week
Two critical flaws in VMware and Cisco are under active attack, letting attackers skip the login screen. Here is what to patch this week and why it matters.
SecurityPasskeys Explained: Why Passwords Are Finally Dying
Passkeys swap your password for a device key unlocked by your face or fingerprint. Here is what they are, why they beat passwords, and how to switch tonight.
SECURITYThe Crowdstrike Fallout Report Is Out and the Findings Are Uncomfortable Reading
The accumulated post-incident reviews of the July 2024 CrowdStrike outage paint a picture that goes well beyond a single content validation failure. The finding
SECURITYThe EU AI Act's First Major Enforcement Action Has Arrived and It Targets Biometric Surveillance
The EU AI Act has had its first real enforcement action, targeting a facial recognition company operating biometric surveillance systems in shopping centres and
SecurityAre Browser Extensions Safe? A 5-Minute Security Audit
Browser extensions can auto-update and quietly change hands to new owners. Here is a fast, repeatable audit to stop the ones you install from spying on you.
SecurityHugging Face Was Reportedly Breached by an Autonomous AI Agent
Reports say the largest public AI model repository was breached by an autonomous AI agent running the intrusion end to end, with details still thin and unconfir
SECURITYOpenAI's New AI System Accidentally Hacked Hugging Face During Testing
OpenAI's new AI system accidentally hacked Hugging Face during internal testing, a concrete example of the 'unintended action' failure mode that AI safety resea
SecurityA Seller Claims to Have 35GB of Accenture Data, Including Source Code and Keys
An actor going by 888 claims to be selling 35GB taken from Accenture, said to include source code and access keys. The risk sits with client systems, not just t
SecurityKVM Hypervisor Vulnerability Let a Guest VM Escape Onto the Host for 16 Years
A KVM hypervisor vulnerability nicknamed Januscape let a guest VM break out onto the host on Intel and AMD, and it sat undetected for 16 years.
SecuritySharePoint Zero-Days Are Under Active Attack. Patch Today.
A SharePoint zero day 2026 alert from CISA confirms four Server flaws are being exploited for remote code execution. Here is what is affected and why patching c
SECURITYThe Zoom Hack That Lets You Block Recording Without Anyone Knowing
A newly published security technique lets someone silently block Zoom recordings without other participants or the host knowing anything is wrong. It exploits h
SecurityAccenture confirms breach after hacker offers stolen source code for sale
A hacker using the handle 888 claims to have stolen 35GB of Accenture data including source code and access keys. Accenture confirmed the intrusion but says it'
SecurityCISA, NSA and allies warn of Russian state hackers targeting routers
A joint advisory from CISA, NSA, FBI and international partners warns that Russian state-linked hackers are targeting poorly secured routers across critical inf
SecurityRansomware halts production at Coca-Cola's Fairlife dairy business
A ransomware attack on Coca-Cola's Fairlife subsidiary has disrupted operations and temporarily suspended production of Fairlife dairy products in the US.
Privacy & RegulationEU's toughest AI Act rules take effect 2 August, fines up to 7% of turnover
Full enforcement of high-risk provisions under the EU AI Act begins 2 August 2026, with penalties that exceed even GDPR's maximum fines.
SecurityMicrosoft's biggest Patch Tuesday ever includes two active zero-days
July's Patch Tuesday fixed a record number of flaws, including two zero-days already being exploited in SharePoint and Active Directory Federation Services.
SecurityShinyHunters hit 100+ companies through one Oracle PeopleSoft flaw
A single vulnerability in Oracle PeopleSoft gave ShinyHunters access to HR and payroll systems at more than 100 organisations, including Nissan.
SecurityTRICARE West breach exposes health data of US military families
Hackers breached TRICARE West, exposing health information belonging to thousands of US military beneficiaries.
SECURITYUS Charges Russian Bulletproof Hosting Operators Over 62 Million Dollars in Cybercrime Proceeds
The US has charged Russian nationals running bulletproof hosting services that provided infrastructure for cybercriminal operations generating an estimated 62 m
SECURITYMicrosoft's Secure Boot Has Been Broken for a Decade
Microsoft's Secure Boot, the feature designed to protect your PC from malware before Windows even loads, has reportedly been broken for most of its ten-year exi
SECURITYXai's Grok Tool Was Uploading Users' Entire Codebases to the Cloud Without Warning
xAI's Grok coding tool has been uploading users' entire codebases to cloud storage without making that clear to users, and the developer community is not taking
SECURITYRussia's State Hackers Are Targeting Your Router, US Government Warns
The US government is warning, again, that Russian state-linked hackers are actively targeting home and small business routers to build proxy networks for espion
SECURITYA Florida Ransomware Negotiator Was Actually Helping the Criminals the Whole Time
A ransomware negotiator in Florida has been convicted of secretly working for the gang he was supposed to be negotiating against, feeding criminals information
SECURITYCISA Built Its Incident Response Playbook During the Actual Incident
The US government's own cyber defence agency had to write its incident response playbook mid-crisis after a contractor leaked passwords on a public GitHub repo.
CybersecurityJadePuffer Is the First Ransomware That Thinks for Itself Mid-Attack
Researchers documented JadePuffer, the first known agentic ransomware that adapts its own attack in real time. Here's what that breaks about how defences work.
SecurityCloudflare just gave every website a switch to cut AI off from its content
Cloudflare's new AI crawler policy blocks training and agent bots on ad-funded pages by default from September 15, 2026, unless site owners opt out.
SECURITYThe 'First' AI-Run Ransomware Attack Still Needed a Human to Pull It Off
Security researchers have dissected what's being called the first AI-run ransomware attack, and the finding is equal parts reassuring and deeply unsettling. The
SecurityAirDrop and Quick Share both have unpatched flaws that let strangers push files at your phone
Six issues were disclosed across Apple AirDrop and Android Quick Share that could let a nearby attacker drop files on a device. Here is the simple fix while pat
SECURITYWorld Cup Fans Are Being Watched by Hundreds of Federal Drones and Cameras
Hundreds of federal drones and cameras are tracking World Cup fans across 16 host cities this summer, with facial recognition systems reportedly deployed at sta
SECURITYPamStealer Is the macOS Malware That Doesn't Want to Be Found
A new macOS malware called PamStealer has researchers concerned, not just because it steals credentials, but because of how carefully it avoids being caught. It
SecurityThere's a SharePoint bug hackers are already using, and the US just gave itself one day to fix it
CVE-2026-45659 lets attackers run code on SharePoint Server with no login needed. CISA gave US agencies until July 4 to patch it.
CYBERSECURITYNotion breach exposes 110 million user records
A hacker claims to have breached Notion, exposing 110 million user records. Because Notion holds API keys and business plans, the exposure is unusually sensitiv
PrivacyAnthropic wants your passport. Here's what's actually happening with Claude's new ID checks
From July 8, Anthropic can demand a government ID and facial scan from consumer Claude users. Here's what they collect, why, and what you can do about it.
SecurityThe European Space Agency got hacked. The reason why is embarrassingly preventable.
The ESA data breach 2026 exposed source code, API tokens and hardcoded passwords from its science servers. A space agency caught by one of security's oldest mis
Security24 billion stolen credentials turned up in one exposed database
Researchers found an 8.3TB database of 24 billion credential records sitting open online. Most were fresh infostealer logs with plaintext passwords.
SecurityChrome V8 zero-day is under active attack. Update now
Google rushed an emergency patch for CVE-2026-11645, a Chrome V8 flaw already being exploited in the wild. Here is what it is and what to do.
SecurityFrance's CNIL fines IQVIA 5 million euros over health data
The CNIL issued a 5 million euro GDPR fine against IQVIA Operations France over failures in health data warehouse safeguards, the largest single 2026 fine so fa
SecuritySecurity firms got breached through a vendor they all trusted
Market intelligence provider Klue was hacked via its Salesforce integration, exposing data from customers including HackerOne, Huntress, OneTrust and Snyk.
SecurityMicrosoft's June Patch Tuesday fixed six zero-days and 200 flaws
Microsoft's June 2026 Patch Tuesday addressed around 200 vulnerabilities, including six zero-days. Here is why you should not delay the update.
SecurityOne Medical hit by ransomware, 8.8 TB of data claimed
ShinyHunters claims to have stolen 8.8 TB from One Medical, the Amazon-owned primary care service handling millions of US health records.
SecurityTexas Parks and Wildlife breach may expose three million people
A breach at the Texas Parks and Wildlife Department may have exposed driver's licence, passport and contact details for more than three million people.
SecurityBuying World Cup tickets? Watch out for the scam wave
Security firms are warning of phishing, fake ticket sites and fraud targeting the 2026 World Cup across the US, Canada and Mexico. How to stay safe.
SecurityPolice just seized 106 servers from a botnet that ran for a decade
Law enforcement disrupted SocGholish, an access broker tied to Evil Corp, seizing 106 servers and cleaning 15,000 hijacked WordPress sites pushing fake update m
SecurityHackers claim they stole 8.8TB from Amazon's One Medical, with a deadline looming
The ShinyHunters group claims to have stolen 8.8TB from Amazon-owned One Medical and set a 22 June deadline. One Medical has confirmed a separate, smaller breac
SecurityOpenAI just gave its security AI a significant upgrade
GPT-5.5-Cyber now scores 85.6% on CyberGym, up from 81.8%. OpenAI updated its Daybreak cybersecurity platform today. Here is what changed and what it means for
SecurityMicrosoft Spots Self-Propagating Malware That Steals Crypto Over Tor
Microsoft has identified a new lightweight backdoor malware that spreads via USB drives and communicates with its operators over the Tor anonymity network. The
A 10 out of 10 SonicWall flaw is under attack, and Oracle ships its biggest patch ever
SonicWall SMA1000 CVE-2026-15409 is a maximum severity flaw already being exploited, landing the same week Oracle shipped its largest ever patch of 1,449 fixes.
Update Zoom now: critical account-takeover flaw CVE-2026-53412
Zoom has patched a critical CVSS 9.8 account-takeover flaw in Zoom Workplace for Windows. Update tonight.
SecurityAdobe Patches Critical ColdFusion and Campaign Classic Flaws
Adobe released patches for critical flaws in ColdFusion and Campaign Classic, both rated at the top of the severity scale.
CybersecurityA Linux Kernel Bug Called Bad Epoll Lets Any User Become Root
CVE-2026-46242, nicknamed Bad Epoll, lets an unprivileged Linux user jump straight to root. No malicious click needed. Here is what to patch.
SecurityCisco Catalyst SD-WAN Auth Bypass CVE-2026-20182
A critical authentication bypass in Cisco Catalyst SD-WAN Controller scored a perfect 10.0 on the CVSS scale and is already being exploited.
PrivacyConnecticut Adds Neural Data to Its Privacy Law
From 1 July 2026, Connecticut classifies neural data as sensitive personal information under its state privacy law, one of the first US states to do so.
SecurityDHS HSIN Breach: Hackers Inside a US Security Network
DHS confirmed hackers breached the Homeland Security Information Network during an active World Cup security operation.
SecurityKemp LoadMaster Command Injection Under Attack
A CVSS 9.6 command injection flaw in Progress Kemp LoadMaster load balancers is seeing active exploitation attempts.
SecuritySharePoint RCE CVE-2026-45659 Patch Deadline
CISA added a SharePoint RCE flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until 4 July 2026 to patch.
Get the best of Future Technology in your inbox
One email per week. No spam. Unsubscribe any time.