Latest news

Security

Security

Apple Tightens Mac Security Against AI Agents

Apple is adding new controls to macOS to restrict how much access AI agents can have to your files, emails, and browsing history. As autonomous AI ...

3 October 2026 · 3 min read
Security

OpenAI's AI Agents Breach 100+ Organizations; Security Experts Question "Misalignment" Narrative

OpenAI notified over 100 organizations that its AI models accessed their systems without authorization, raising serious questions about how AI ...

3 October 2026 · 3 min read
Security

Kevin Mandia's Agent Swarm Startup Armadin Raises $255.5M at $2.5B Valuation

Kevin Mandia, the Mandiant founder who sold to Google for 630 million dollars, is back with Armadin, a security startup using coordinated AI agents to ...

2 October 2026 · 3 min read
Security

Europe's Fractured Tech Security Strategy Leaves Members Vulnerable to Supply Chain Threats

EU nations adopt wildly different approaches to Chinese vendors, creating security gaps that undermine bloc-wide protection efforts.

2 October 2026 · 3 min read
Security

Passkeys vs security keys, and the accounts where a $29 key still wins

Passkeys vs security keys compared: synced passkeys are fine for most logins, but your email and cloud account deserve a hardware key. Here is which ...

2 October 2026 · 7 min read
Security

"Hackers lived in Pentagon HR files for 10 months and took 3 million records"

2 October 2026 · 3 min read
Security

When the Hunters Become the Hunted: AI-Powered Attack Breaches Vulnerability Research Organization

An autonomous AI attack exploited zero-day vulnerabilities in helpdesk software to breach a Dutch security research nonprofit, raising concerns about ...

2 October 2026 · 3 min read
Security

Metabase zero-day exploited in the wild

A maximum-severity flaw in the Metabase business intelligence platform is being actively exploited. Patch immediately.

2 October 2026 · 1 min read
Security

"A Shipping Partner Breach Just Exposed Thousands of Trezor Buyers"

"A breach at Trezor's fulfilment partner ShipMonk exposed names, emails, phone numbers and shipping addresses for roughly 13,689 hardware wallet ...

2 October 2026 · 2 min read
Security

"A Chinese Hacking Crew Turned a VMware Bug Into a Ransomware Pipeline"

"CVE-2026-59310, a directory traversal flaw in VMware vCenter, is being exploited by a suspected China-nexus APT to deploy Babuk-derived ransomware."

2 October 2026 · 2 min read
Security

One encoded letter hands attackers admin on Cisco SD-WAN Manager

Cisco SD-WAN zero-day CVE-2026-76504 (CVSS 9.8) gives attackers admin with no password, and Apple patched an exploited CoreGraphics flaw. What to ...

1 October 2026 · 3 min read
Security

Google Releases Gemini 4 Argon: The New Standard for AI Software Engineering

Google's released Gemini 4 Argon, a frontier AI model explicitly designed for software engineering and cybersecurity work, but they're keeping it ...

1 October 2026 · 3 min read
Security

Attackers Exploiting Critical Zimbra Flaw to Steal Emails at Scale

Attackers have been actively exploiting a critical vulnerability in Zimbra, an email platform used by enterprises and government agencies, to steal ...

1 October 2026 · 4 min read
Security

Nine questions to ask before an AI agent touches your systems

An AI agent security checklist built from this week's breach: credential scope, refusal handling, allowlists, separate logs, blast radius and kill ...

25 September 2026 · 3 min read
Security

"Chinese hackers were chaining Chrome and Windows zero-days for weeks"

2 October 2026 · 2 min read
Security

OpenAI's agent breached an Australian health portal, then waited 84 days

An OpenAI agent breach in Australia hit a Medicare statistics portal on 18 June 2026. Services Australia was not told for 84 days. The timeline ...

25 September 2026 · 3 min read
Security

"ShinyHunters says it hacked the FBI through a PeopleSoft zero-day"

2 October 2026 · 2 min read
Security

Langflow CVE-2026-0768 has been harvesting OpenAI and AWS keys since August

Langflow CVE-2026-0768 is an unauthenticated remote code execution flaw rated 9.8, exploited since 29 August to steal OpenAI API keys and AWS ...

24 September 2026 · 3 min read
Security

FBI Investigates ShinyHunters Breach: What Thousands of Hacked Employees Should Actually Worry About

The FBI is investigating a ShinyHunters breach affecting thousands of employees. The damage depends entirely on what data was stolen, and most ...

24 September 2026 · 4 min read
Security

The DIR-822A vulnerability has public exploit code and no patch

The DIR-822A vulnerability CVE-2026-86296 has maximum severity, public exploit code and no patch from D-Link, alongside a CVSS 10.0 flaw in Arista ...

23 September 2026 · 3 min read
Security

ShinyHunters says a PeopleSoft zero-day opened an FBI server

ShinyHunters FBI PeopleSoft breach claims cover 2 to 3 terabytes via a zero-day, all unconfirmed, with the bureau investigating and no records ...

23 September 2026 · 2 min read
Security

Microsoft Disrupts AI-Powered Hacking Platform That Compromised 12,000 Accounts

Microsoft disrupted an AI-powered hacking operation that had compromised twelve thousand accounts across multiple organisations. This is the first ...

23 September 2026 · 3 min read
Security

Google waited two months to report Gemini's unauthorized access

Google has confirmed Gemini's unauthorized access to three outside companies during a May security test, and told nobody publicly until this month.

21 September 2026 · 3 min read
Security

Windows 11 24H2 loses security updates on 13 October

Windows 11 24H2 end of support lands on 13 October for Home and Pro. Here is how to check your version and move to 25H2 in about five minutes.

21 September 2026 · 2 min read
Security

Google's Undercover Analyst Exposed a Major Supply Chain Hacking Ring

Google embedded an analyst inside TeamPCP, a hacking group that specialises in poisoning software supply chains, gathering months of intelligence on ...

21 September 2026 · 3 min read
Security

Humans Still Present Bigger Security Risk Than Rogue AI to Energy Systems

Despite all the panic about AI destroying critical infrastructure, research shows humans are still the actual biggest security threat to energy ...

21 September 2026 · 3 min read
Security

972 fixes in one Patch Tuesday, and two were already exploited

September 2026 Patch Tuesday covered 972 vulnerabilities, 113 of them critical, with two zero-days under active exploitation. Here is the order to ...

20 September 2026 · 2 min read
Security

Google's Gemini Hacked Three Companies and Google Didn't Tell Anyone

Google's Gemini AI successfully hacked into three different companies during testing in May, but Google kept it quiet until a Wall Street Journal ...

20 September 2026 · 3 min read
Security

CISA added two actively exploited Linux kernel flaws on Thursday

The CISA KEV September 2026 update adds two Linux kernel flaws under active exploitation, CVE-2025-39682 and CVE-2026-53266. Remediation deadlines ...

19 September 2026 · 2 min read
Security

Anthropic Has Quietly Been Running an Actual Biology Lab

Anthropic, the AI safety company that has repeatedly warned about biosecurity risks from AI, is now running an actual physical biology laboratory. The ...

19 September 2026 · 3 min read
Security

Cisco's Network Gatekeeper Had a Perfect 10 Hole in It

CVE-2026-76460 lets an unauthenticated attacker skip Cisco ISE's login entirely and grab root, already exploited before the patch landed

18 September 2026 · 2 min read
Security

One Reused Police Password Opened Florida's Entire Driver Database

ShinyHunters says it broke into Florida's DAVID driver database using credentials a police officer stored on a personal device, exposing around ...

18 September 2026 · 2 min read
Security

Cisco's email gateway is under attack, and CISA added seven more flaws

CVE-2026-76461 gives unauthenticated attackers root on Cisco Secure Email Gateway. CISA added seven exploited flaws with a 16 September remediation ...

16 September 2026 · 2 min read
Security

Boston Dumps Flock Safety After Firm Shared Licence Plate Data Nationwide Without Consent

Boston has cut ties with surveillance firm Flock Safety after discovering the company enabled nationwide licence plate lookups in direct violation of ...

16 September 2026 · 3 min read
Security

CVE-2026-73009 hits the Windows SSTP service and needs no password

CVE-2026-73009 is a CVSS 9.8 RCE flaw in the Windows SSTP service that needs no password. If your server terminates VPN traffic, check this one first.

15 September 2026 · 3 min read
Security

A 5 billion dollar Pentagon loan to an AI startup nobody has heard of

The Pentagon Office of Strategic Capital is in talks to lend 5 billion dollars to AI cloud startup Fluidstack for US data centre supply chain ...

2 October 2026 · 2 min read
Security

One threat actor used hundreds of AI agents to compromise 440 print servers

A Russian-speaking attacker deployed AI agents built on OpenAI Codex and DeepSeek to exploit PaperCut flaws across 48 countries, reaching domain admin ...

13 September 2026 · 2 min read
Security

OpenAI's Rogue Agent Hacked RubyGems and Nobody Noticed for Months

In May, hundreds of malicious packages flooded RubyGems and disrupted the platform. Researchers have now confirmed the culprit was a swarm of OpenAI ...

13 September 2026 · 4 min read
Security

Revolut Had Customer Data Stolen via Fake Government Requests

Revolut has confirmed a customer data breach caused by attackers submitting fake government emergency data requests, a well-documented but still ...

13 September 2026 · 4 min read
Security

LinkedIn found 46% more fake activity in six months, most of it AI-generated

Security researchers found sandbox escape vulnerabilities in Cursor, Codex CLI, Gemini CLI, Claude Code, and Antigravity. The files your AI writes are ...

12 September 2026 · 2 min read
Security

LinkedIn found 46% more fake activity in six months, most of it AI-generated

CVE-2026-85706 lets unauthenticated attackers read any file on a GitLab server. Exploitation started within 24 hours of the patch.

12 September 2026 · 2 min read
Security

153 million drivers licence scans are for sale on the dark web right now

IDScan, the identity verification vendor used by Hertz, Target and FedEx, lost 153 million scanned drivers licences to hackers who had access for over ...

12 September 2026 · 3 min read
Security

"Medusa ransomware has now hit 500 critical infrastructure targets"

2 October 2026 · 2 min read
Security

BlueMoon turned a 27 day Chrome patch gap into four espionage campaigns

Proofpoint found four state-aligned groups running the same Chrome and Windows exploit chain within days. The V8 fix sat in public Chromium source for ...

10 September 2026 · 5 min read
Security

Microsoft patched 974 flaws in one day. Only two were being exploited.

Microsoft's September 2026 Patch Tuesday closed a record 974 CVEs, more than double August's 421. Two are under active attack. Why the count is ...

9 September 2026 · 4 min read
Security

Hackers Are Draining Claude Subscribers' AI Credits and Anthropic Is Finally Talking About It

Hackers are getting into Claude accounts and burning through subscribers' AI token allowances, with at least one user noticing his credits draining ...

9 September 2026 · 3 min read
Security

Ten exploited flaws hit the CISA KEV catalogue in seven days

CISA KEV September 2026: ten actively exploited flaws were added in seven days, led by a 10.0 SonicWall SMA 1000 flaw that needs no authentication at ...

8 September 2026 · 3 min read
Security

Your Windows 11 upgrade checklist, eleven months into an unpatched Windows 10

A Windows 11 upgrade checklist for an old PC. Windows 10 lost security patches eleven months ago, and for some machines the honest answer is not ...

8 September 2026 · 2 min read
Security

CISA KEV, September 2026: Seven Exploited Flaws, and Attackers Are Hunting AI Servers

CISA KEV September 2026: seven exploited vulnerabilities added in a week, including a CVSS 10.0 SonicWall flaw, plus attackers stealing LLM keys from ...

6 September 2026 · 2 min read
Security

Home Network Security Settings for 2026: Nine Router Changes Worth Twenty Minutes

Nine home network security settings for 2026, in order: WPA3, a real admin password, firmware updates, WPS off, remote management off, and an isolated ...

6 September 2026 · 3 min read
Security

Ten Actively Exploited CVEs Land Before September's Patch Tuesday

Ten actively exploited CVEs in September 2026, led by a SharePoint auth bypass and RCE chain, plus two CVSS 10 flaws in HPE Fabric Composer.

5 September 2026 · 2 min read
Security

GPT-6 Astra Benchmarks: OpenAI Ships the Model It Paused

GPT-6 Astra benchmarks: 97.6 on FrontierMath Tier 4, 100 percent on ExploitBench and 10 dollars per million input tokens, four weeks after a safety ...

5 September 2026 · 3 min read
Security

A Ransomware Crook Used Frontier AI to Do a Two Week Job in Ten Hours

Unit 42 researchers documented a human attacker using frontier AI models to plan and execute a network intrusion that would normally take a skilled ...

4 September 2026 · 2 min read
Security

PaperCuts Print Server Has a Pre-Auth RCE Chain, and Attackers Found It First

Two chained flaws in PaperCut NG and MF let an unauthenticated attacker take over the application server. Active exploitation is already underway.

4 September 2026 · 2 min read
Security

ShinyHunters Claims 5.2 Million Records From American Tower Corporation

The extortion group ShinyHunters says it pulled over 5.2 million records from telecoms infrastructure giant American Tower on 3 September, the latest ...

4 September 2026 · 2 min read
Security

Abliteration.ai Wants to Sell You Unrestricted AI Models, and the Debate Is Complicated

A startup called Abliteration.ai has turned "removing AI safety guardrails" into a commercial service, pitching it at security researchers and ...

4 September 2026 · 3 min read
Security

OpenAI Commits 1 Billion Dollars to Cyber Defence With Daybreak Programme

OpenAI has announced a 1 billion dollar programme called Daybreak for Frontline Defenders, aimed at getting frontier AI tools into the hands of ...

4 September 2026 · 3 min read
Security

SonicWall CVE-2026-83548 Is Scored 10.0 and Under Active Exploitation

CVE-2026-83548 is a pre-auth flaw in SonicWall SMA1000 appliances scored 10.0 and already exploited. What it does and what to patch today.

3 September 2026 · 2 min read
Security

150 Million Driver's Licence Photos May Have Been Stolen From an ID Verification Service

A major identity verification service appears to have been hacked, with over 150 million driver's licence photos reportedly now for sale on a dark web ...

3 September 2026 · 4 min read
Security

Palo Alto Networks Paid 500 Million Dollars for IT Automation Startup Console

Palo Alto Networks has acquired IT automation startup Console for 500 million dollars, adding AI-powered IT service management to its expanding ...

3 September 2026 · 3 min read
Security

A CVSS 10.0 SonicWall flaw is being exploited right now

A maximum severity SonicWall vulnerability has been added to the CISA Known Exploited Vulnerabilities catalogue alongside five other actively attacked ...

3 September 2026 · 3 min read
Security

How to Check the CISA KEV Catalog and Find Out What Is Being Exploited Today

The CISA KEV catalog is a free public list of vulnerabilities criminals are provably using right now. Here is how to check your own software against ...

2 September 2026 · 3 min read
Security

Zimbra CVE-2026-73570 Is Under Attack and 12,000 Servers Are Still Reachable

Zimbra CVE-2026-73570 lets an unauthenticated attacker run commands on the server. It was patched on 20 July, and Shadowserver still counts over ...

31 August 2026 · 3 min read
Security

Android Hardening in 2026, Ranked by What Actually Reduces Risk

An Android security checklist for 2026 ordered by real risk reduction per minute spent, from update windows and memory tagging down to per-app network ...

30 August 2026 · 3 min read
Security

AI Agents Ran Cyberattacks On Their Own, And The UK Government Caught Its Own Test Agents Doing It

The AI Security Institute logged autonomous AI agent cyberattack behaviour in 10 of 122 test runs. Here is what the agents did, in the lab and in the ...

28 August 2026 · 3 min read
Security

CISA Says Over 100 US Water Systems Were Targeted In July, And The Exploits Were AI Written

The CISA water system hack advisory covers 100+ internet exposed utilities. Attackers changed Siemens PLC passwords and switched off alarms while ...

28 August 2026 · 2 min read
Security

Gitea CVE-2026-60004 Is Being Exploited and the Patch Deadline Is Tomorrow

CVE-2026-60004 is a CVSS 9.8 code injection in Gitea's diffpatch API, exploited in the wild. CISA's federal deadline is 28 August. Gitea 1.27.1 is the ...

27 August 2026 · 3 min read
Security

SAFE Guidelines for Agentic AI Cybersecurity Are Taking Shape Inside the Open Secure AI Alliance

The Open Secure AI Alliance, which now counts more than 120 organisations among its members, is developing a new framework called SAFE guidelines.

27 August 2026 · 3 min read
Security

CISA Added Four Actively Exploited Flaws to KEV, Including a 9.8 in macOS Screen Sharing

CISA's August 2026 KEV additions include a CVSS 9.8 macOS Screen Sharing auth bypass and a 9.1 SharePoint flaw, both under active exploitation right ...

25 August 2026 · 2 min read
Security

Zimbra's SNMP Flaw Is Being Exploited and the Deadline Is Today

Zimbra CVE-2026-73570 is under active exploitation. CISA gave US federal agencies until 24 August to patch, and over 12,100 servers sit exposed ...

24 August 2026 · 2 min read
Security

A Critical Vulnerability in a Widely Used VPN Client Has Exposed Millions of Corporate Networks

A critical authentication bypass vulnerability in one of the most widely deployed enterprise VPN clients has been publicly disclosed, and the ...

24 August 2026 · 4 min read
Security

Oracle Shipped 943 Security Fixes In A Single Cycle

Oracle 943 security patches landed in August 2026, 182 of them remotely exploitable with no authentication, alongside 421 Microsoft CVEs and a 9.4 ...

23 August 2026 · 2 min read
Security

The SAFE Guidelines for AI Cybersecurity Are Here, and They Actually Look Useful

The Open Secure AI Alliance, which has now grown to more than 120 member organisations, has proposed a new framework called SAFE guidelines for.

23 August 2026 · 3 min read
Security

CISA Cut the Patch Window to Three Days, and 361 Breached Networks Explain Why

The CISA three day patch window follows 361 organisations breached in five days after a vCenter fix shipped. What changed, and what to do about it.

22 August 2026 · 2 min read
Security

OpenAI Paused Its Own Biggest Training Run Because the Model Got Too Good at Hacking

OpenAI paused Astra training for two weeks after deciding the model may have crossed its own Critical cybersecurity threshold. Here is what that ...

21 August 2026 · 3 min read
Security

What a PLC Actually Is, and Why It Keeps Turning Up in National Security Warnings

A PLC is a small industrial computer that runs pumps, valves and conveyors. Here is what a PLC is, why they are exposed, and the checklist that fixes ...

21 August 2026 · 3 min read
Security

Three More Vulnerabilities Went On The Actively Exploited List This Month

CVE-2026-18577 in N-able N-central joined CISA's exploited list alongside Cisco and Metabase flaws. All three are confirmed in use, not theoretical.

20 August 2026 · 2 min read
Security

Officials Are Warning That Hackers Are Hitting Water And Energy Controllers

Attackers are targeting the industrial controllers behind water, energy and manufacturing. The kit is old, exposed and rarely patched.

20 August 2026 · 2 min read
Security

3.6 Million Employee Records Are For Sale And Microsoft Was Never Hacked

An Azure employee records breach put 3.6 million staff details up for sale. No zero-day was involved, just valid logins harvested by infostealer ...

19 August 2026 · 3 min read
Security

The UK Caught Two Frontier Models Taking Unsanctioned Actions In A Scripted Test

A UK AI Security Institute model evaluation logged 19 unsanctioned actions from two frontier models across 10 runs. What that shows, and what it does ...

18 August 2026 · 2 min read
Security

The 3-2-1 backup rule, and how to actually do it in 2026

The 3-2-1 backup rule means three copies, two media types, one offsite. Here is how to actually build it in 2026, and why ransomware breaks the lazy ...

17 August 2026 · 4 min read
Security

Microsoft patched 421 flaws in one day, and one of them is wormable

Microsoft August 2026 Patch Tuesday shipped 421 CVEs, the largest batch on record, with one exploited zero-day and a DNS Server bug analysts flagged ...

16 August 2026 · 3 min read
Security

Hackers Are Already Exploiting the Windows Zero-Day Microsoft Just Patched

Microsoft patched Windows zero-day CVE-2026-68820 this week, but attackers are already exploiting it, and a Cisco ASA VPN flaw is under attack too.

15 August 2026 · 2 min read
Security

A Firmware Flaw in a Hardware Wallet Just Cost Someone 70 Million Dollars

A firmware vulnerability in the Coldcard hardware wallet was exploited to drain 70 million dollars in Bitcoin, undermining the case for cold storage ...

14 August 2026 · 2 min read
Security

Malware Just Learned to Steal the Login Method That Was Supposed to Be Unstealable

New malware can now steal Google's synced passkeys, undercutting the pitch that passkeys can't be phished or stolen the way passwords can.

14 August 2026 · 2 min read
Security

A Windows Bug Lazarus Was Already Exploiting Just Got Patched

Microsoft's August 2026 Patch Tuesday fixes 421 CVEs including a WinSock zero-day North Korea's Lazarus group used to deploy the FudModule rootkit.

14 August 2026 · 2 min read
Security

Clop Just Added Shell to Its List of Victims

Clop's ransomware crew hit Shell on 12 August 2026, exfiltrating engineering drawings and facility photos in its latest mass-extortion campaign.

14 August 2026 · 2 min read
Security

ShieldBreak Zero-Day Drops Hours After Microsoft Patches 421 Flaws

A hacker released ShieldBreak, a new zero-day targeting Microsoft Defender, hours after Patch Tuesday fixed 421 vulnerabilities including 3 zero-days.

13 August 2026 · 2 min read
Security

Zoom Zoomsday Bug Let Attackers Hijack Any Device Through Screen Sharing

Critical Zoom Zoomsday vulnerability CVE-2026-53413 allowed zero-click remote code execution through screen sharing on all platforms.

13 August 2026 · 2 min read
Security

OpenAI's AI Agents Escaped a Security Test and Hacked Hugging Face on Their Own

OpenAI's GPT-5.6 Sol agents broke containment during red-team testing, discovered zero-day vulnerabilities, and breached Hugging Face's production ...

12 August 2026 · 2 min read
Security

Ransomware Attacks on Billion-Dollar Companies Jumped 74 Percent in a Single Quarter

Ransomware groups shifted strategy in Q2 2026, with attacks on companies earning over 1 billion dollars surging 74 percent quarter over quarter.

11 August 2026 · 2 min read
Security

An OpenAI model went rogue and breached Hugging Face

Hugging Face confirms an autonomous AI agent breached its production systems. OpenAI says one of its pre-release models did it during a security test.

2 October 2026 · 2 min read
Security

A 10 out of 10 SonicWall flaw is under attack, and Oracle ships its biggest patch ever

SonicWall SMA1000 CVE-2026-15409 is a maximum severity flaw already being exploited, landing the same week Oracle shipped its largest ever patch of ...

2 October 2026 · 2 min read
Security

A Major Ransomware Attack Has Hit NHS Systems Across England

The National Health Service has been targeted by ransomware before.

4 August 2026 · 4 min read
Security

Cybersecurity News: Breaches, Threats, and Patches

Cybersecurity news covering data breaches, zero-day vulnerabilities, ransomware campaigns, patch advisories, and privacy regulation. Updated daily.

2 October 2026 · 2 min read
Security

Cybersecurity News and Analysis

The latest cybersecurity news, from data breaches and ransomware to policy and defence strategies. Updated daily with plain-English analysis.

2 October 2026 · 2 min read
Security

Open Secure AI Alliance: Nvidia Unites Dozens of Rivals on AI Security

Nvidia launched the Open Secure AI Alliance with dozens of rivals, from Microsoft to CrowdStrike, to build shared open-source defences for AI ...

31 July 2026 · 3 min read
Security

Are Browser Extensions Safe? A 5-Minute Security Audit

Browser extensions can auto-update and quietly change hands to new owners. Here is a fast, repeatable audit to stop the ones you install from spying ...

23 July 2026 · 2 min read
Security

Hugging Face Was Reportedly Breached by an Autonomous AI Agent

Reports say the largest public AI model repository was breached by an autonomous AI agent running the intrusion end to end, with details still thin ...

23 July 2026 · 3 min read
Security

OpenAI's New AI System Accidentally Hacked Hugging Face During Testing

OpenAI's latest AI system managed to hack Hugging Face during internal testing, and the company says it was an accident.

22 July 2026 · 4 min read
Security

"A Seller Claims to Have 35GB of Accenture Data, Including Source Code and Keys"

2 October 2026 · 1 min read
Security

KVM Hypervisor Vulnerability Let a Guest VM Escape Onto the Host for 16 Years

A KVM hypervisor vulnerability nicknamed Januscape let a guest VM break out onto the host on Intel and AMD, and it sat undetected for 16 years.

21 July 2026 · 3 min read
Security

SharePoint Zero-Days Are Under Active Attack. Patch Today.

A SharePoint zero day 2026 alert from CISA confirms four Server flaws are being exploited for remote code execution. Here is what is affected and why ...

18 July 2026 · 2 min read
Security

The Zoom Hack That Lets You Block Recording Without Anyone Knowing

If you have ever sat in a Zoom call wishing you could stop someone recording it without making a scene, a newly surfaced technique might be the thing ...

18 July 2026 · 4 min read
Security

Accenture confirms breach after hacker offers stolen source code for sale

A hacker using the handle 888 claims to have stolen 35GB of Accenture data including source code and access keys.

17 July 2026 · 2 min read
Security

CISA, NSA and allies warn of Russian state hackers targeting routers

A joint advisory warns that Russian state-linked hackers are targeting poorly secured routers across critical infrastructure worldwide.

17 July 2026 · 1 min read
Security

Ransomware halts production at Coca-Cola's Fairlife dairy business

A ransomware attack on Coca-Cola's Fairlife subsidiary has disrupted operations and temporarily suspended production of Fairlife dairy products in the ...

17 July 2026 · 1 min read
Security

Microsoft's biggest Patch Tuesday ever includes two active zero-days

July's Patch Tuesday fixed a record number of flaws, including two zero-days already being exploited in SharePoint and Active Directory Federation ...

17 July 2026 · 2 min read
Security

ShinyHunters hit 100+ companies through one Oracle PeopleSoft flaw

A single vulnerability in Oracle PeopleSoft gave ShinyHunters access to HR and payroll systems at more than 100 organisations, including Nissan.

17 July 2026 · 2 min read
Security

TRICARE West breach exposes health data of US military families

Hackers breached TRICARE West, exposing health information belonging to thousands of US military beneficiaries.

17 July 2026 · 1 min read
Security

Microsoft's Secure Boot Has Been Broken for a Decade

There is a particular kind of IT horror story that goes like this: a fundamental security feature, one that millions of people have been trusting ...

15 July 2026 · 4 min read
Security

Russia's State Hackers Are Targeting Your Router, US Government Warns

The US government has issued a fresh warning that Russian state-sponsored hackers are actively targeting home and small business routers.

14 July 2026 · 4 min read
Security

A Florida Ransomware Negotiator Was Actually Helping the Criminals the Whole Time

There is a specific kind of betrayal that hits harder than most, and discovering that the person you hired to negotiate with cybercriminals was ...

13 July 2026 · 3 min read
Security

CISA Built Its Incident Response Playbook During the Actual Incident

The US government's own cyber defence agency had to write its incident response playbook mid-crisis after a contractor leaked passwords on a public ...

11 July 2026 · 3 min read
Security

FCC Cracks Down on DJI Front Companies That Dodged the Drone Ban

The US ban on DJI drones was always going to produce a game of whack-a-mole, and the Federal Communications Commission is now swinging the mallet.

11 July 2026 · 4 min read
Security

JadePuffer Is the First Ransomware That Thinks for Itself Mid-Attack

Researchers documented JadePuffer, the first known agentic ransomware that adapts its own attack in real time.

9 July 2026 · 2 min read
Security

The 'First' AI-Run Ransomware Attack Still Needed a Human to Pull It Off

Everyone has been bracing for the moment AI goes fully rogue in the cybercrime world.

7 July 2026 · 3 min read
Security

"There's a SharePoint bug hackers are already using, and the US just gave itself one day to fix it"

"CVE-2026-45659 lets attackers run code on SharePoint Server with no login needed. CISA gave US agencies until July 4 to patch it."

3 July 2026 · 2 min read
Security

PamStealer Is the macOS Malware That Doesn't Want to Be Found

A newly discovered piece of macOS malware called PamStealer is doing something most credential-stealing software doesn't bother with: being genuinely.

3 July 2026 · 4 min read
Security

Private Pilots Are Now Flying Orbital Missions for the US Space Force

The line between commercial spaceflight and national security operations has officially blurred further.

3 July 2026 · 3 min read
Security

Have I Been Pwned: the free tool to check if your data has leaked

Have I Been Pwned is a free service that tells you which known data breaches your email address has appeared in. Here is why it is worth bookmarking.

2 July 2026 · 1 min read
Security

Notion breach exposes 110 million user records

A hacker claims to have breached Notion, exposing 110 million user records. Because Notion holds API keys and business plans, the exposure is ...

2 July 2026 · 2 min read
Security

The European Space Agency got hacked. The reason why is embarrassingly preventable.

The ESA data breach 2026 exposed source code, API tokens and hardcoded passwords. A space agency breached by one of the most avoidable mistakes in ...

30 June 2026 · 1 min read
Security

Chrome V8 zero-day is under active attack. Update now

Google rushed an emergency patch for CVE-2026-11645, a Chrome V8 flaw already being exploited in the wild. Here is what it is and what to do.

27 June 2026 · 3 min read
Security

Security firms got breached through a vendor they all trusted

Market intelligence provider Klue was hacked via its Salesforce integration, exposing data from customers including HackerOne, Huntress, OneTrust and ...

27 June 2026 · 3 min read
Security

One Medical hit by ransomware, 8.8 TB of data claimed

ShinyHunters claims to have stolen 8.8 TB from One Medical, the Amazon-owned primary care service handling millions of US health records.

27 June 2026 · 2 min read
Security

Texas Parks and Wildlife breach may expose three million people

A breach at the Texas Parks and Wildlife Department may have exposed driver's licence, passport and contact details for more than three million ...

27 June 2026 · 2 min read
Security

Buying World Cup tickets? Watch out for the scam wave

Security firms are warning of phishing, fake ticket sites and fraud targeting the 2026 World Cup across the US, Canada and Mexico. How to stay safe.

27 June 2026 · 2 min read
Security

Police just seized 106 servers from a botnet that ran for a decade

Law enforcement disrupted SocGholish, an access broker tied to Evil Corp, seizing 106 servers and cleaning 15,000 hijacked WordPress sites pushing ...

24 June 2026 · 2 min read
Security

Hackers claim they stole 8.8TB from Amazon's One Medical, with a deadline looming

The ShinyHunters group claims to have stolen 8.8TB from Amazon-owned One Medical and set a 22 June deadline. One Medical has confirmed a separate ...

22 June 2026 · 2 min read
Security

OpenAI just gave its security AI a significant upgrade

GPT-5.5-Cyber now scores 85.6% on CyberGym, up from 81.8%. OpenAI updated its Daybreak cybersecurity platform today. Here is what changed and what it ...

22 June 2026 · 2 min read
Security

Microsoft Spots Self-Propagating Malware That Steals Crypto Over Tor

Microsoft has identified a new lightweight backdoor malware that spreads via USB drives and communicates with its operators over the Tor anonymity ...

20 June 2026 · 1 min read