Topic
Security
184 stories, page 2 of 8
ShinyHunters says a PeopleSoft zero-day opened an FBI server
ShinyHunters FBI PeopleSoft breach claims cover 2 to 3 terabytes via a zero-day, all unconfirmed, with the bureau investigating and no records ...
SecurityMicrosoft disrupts AI-powered hacking platform that compromised 12,000 accounts
Microsoft disrupted an AI-powered hacking operation that had compromised twelve thousand accounts across multiple organisations. This is the first ...
SecurityThe DIR-822A vulnerability has public exploit code and no patch
The DIR-822A vulnerability CVE-2026-86296 has maximum severity, public exploit code and no patch from D-Link, alongside a CVSS 10.0 flaw in Arista ...
SecurityA cut fibre cable paralysed US aviation, and that's the real problem
A construction crew in New Jersey cut a Verizon fibre cable and took down US air traffic control across multiple regions, causing hundreds of flight ...
SecurityWindows 11 24H2 loses security updates on 13 October
Windows 11 24H2 end of support lands on 13 October for Home and Pro. Here is how to check your version and move to 25H2 in about five minutes.
SecurityHumans still present bigger security risk than rogue AI to energy systems
Despite all the panic about AI destroying critical infrastructure, research shows humans are still the actual biggest security threat to energy ...
SecurityGoogle's undercover analyst exposed a major supply chain hacking ring
Google embedded an analyst inside TeamPCP, a hacking group that specialises in poisoning software supply chains, gathering months of intelligence on ...
Security972 fixes in one Patch Tuesday, and two were already exploited
September 2026 Patch Tuesday covered 972 vulnerabilities, 113 of them critical, with two zero-days under active exploitation. Here is the order to ...
SecurityGoogle's Gemini hacked three companies and Google didn't tell anyone
Google's Gemini AI successfully hacked into three different companies during testing in May, but Google kept it quiet until a Wall Street Journal ...
SecurityCISA added two actively exploited Linux kernel flaws on Thursday
The CISA KEV September 2026 update adds two Linux kernel flaws under active exploitation, CVE-2025-39682 and CVE-2026-53266. Remediation deadlines ...
SecurityA Pixel bug that needs no click just got a 3 day federal deadline
CVE-2026-58704 is a zero click flaw in the Pixel cellular modem. CISA gave agencies until 19 September. Here is how to check whether you are patched.
SecurityThe tool your IT provider uses to fix your PC just got a 10.0
N-able rushed out hotfixes for three N-central flaws including a maximum severity pre-auth RCE after the platform thousands of IT providers rely on ...
SecurityOne reused police password opened Florida's entire driver database
ShinyHunters says it broke into Florida's DAVID driver database using credentials a police officer stored on a personal device, exposing around ...
SecurityCisco's network gatekeeper had a perfect 10 hole in it
CVE-2026-76460 lets an unauthenticated attacker skip Cisco ISE's login entirely and grab root, already exploited before the patch landed
SecurityA Parallels bug hands any Mac user root, and Intel Macs cannot install the fix
Parallels Desktop CVE-2026-90894 lets any local Mac user escalate to root. The fix ships in v27, which will not install on Intel Macs. Here is what ...
SecurityA cyberattack has knocked the world's meteor-tracking nonprofit offline
A nonprofit that runs one of the world's key meteor-tracking networks has been taken offline by a cyberattack, with the group warning it will be ...
SecurityCisco's email gateway is under attack, and CISA added seven more flaws
CVE-2026-76461 gives unauthenticated attackers root on Cisco Secure Email Gateway. CISA added seven exploited flaws with a 16 September remediation ...
SecurityBoston dumps Flock Safety after firm shared licence plate data nationwide without consent
Boston has cut ties with surveillance firm Flock Safety after discovering the company enabled nationwide licence plate lookups in direct violation of ...
SecuritySix checks that tell you if your phone is being monitored
How to check if your phone is being monitored: six practical checks covering battery drain, the Android Privacy Dashboard, permissions and Apple ...
SecurityCVE-2026-73009 hits the Windows SSTP service and needs no password
CVE-2026-73009 is a CVSS 9.8 RCE flaw in the Windows SSTP service that needs no password. If your server terminates VPN traffic, check this one first.
SecurityRevolut had customer data stolen via fake government requests
Revolut has confirmed a customer data breach caused by attackers submitting fake government emergency data requests, a well-documented but still ...
SecurityGitLab scored a perfect 10 on the vulnerability scale and attackers noticed
CVE-2026-85706 lets unauthenticated attackers read any file on a GitLab server. Exploitation started within 24 hours of the patch.
SecurityYour AI coding assistant can be tricked into running attacker code
Security researchers found sandbox escape vulnerabilities in Cursor, Codex CLI, Gemini CLI, Claude Code, and Antigravity. The files your AI writes ...
SecurityOne threat actor used hundreds of AI agents to compromise 440 print servers
A Russian-speaking attacker deployed AI agents built on OpenAI Codex and DeepSeek to exploit PaperCut flaws across 48 countries, reaching domain ...
Security153 million drivers licence scans are for sale on the dark web right now
IDScan, the identity verification vendor used by Hertz, Target and FedEx, lost 153 million scanned drivers licences to hackers who had access for ...