Topic

Security

184 stories, page 2 of 8

Security

ShinyHunters says a PeopleSoft zero-day opened an FBI server

ShinyHunters FBI PeopleSoft breach claims cover 2 to 3 terabytes via a zero-day, all unconfirmed, with the bureau investigating and no records ...

· 2 min read
Security

Microsoft disrupts AI-powered hacking platform that compromised 12,000 accounts

Microsoft disrupted an AI-powered hacking operation that had compromised twelve thousand accounts across multiple organisations. This is the first ...

· 3 min read
Security

The DIR-822A vulnerability has public exploit code and no patch

The DIR-822A vulnerability CVE-2026-86296 has maximum severity, public exploit code and no patch from D-Link, alongside a CVSS 10.0 flaw in Arista ...

· 3 min read
Security

A cut fibre cable paralysed US aviation, and that's the real problem

A construction crew in New Jersey cut a Verizon fibre cable and took down US air traffic control across multiple regions, causing hundreds of flight ...

· 4 min read
Security

Windows 11 24H2 loses security updates on 13 October

Windows 11 24H2 end of support lands on 13 October for Home and Pro. Here is how to check your version and move to 25H2 in about five minutes.

· 2 min read
Security

Humans still present bigger security risk than rogue AI to energy systems

Despite all the panic about AI destroying critical infrastructure, research shows humans are still the actual biggest security threat to energy ...

· 4 min read
Security

Google's undercover analyst exposed a major supply chain hacking ring

Google embedded an analyst inside TeamPCP, a hacking group that specialises in poisoning software supply chains, gathering months of intelligence on ...

· 3 min read
Security

972 fixes in one Patch Tuesday, and two were already exploited

September 2026 Patch Tuesday covered 972 vulnerabilities, 113 of them critical, with two zero-days under active exploitation. Here is the order to ...

· 3 min read
Security

Google's Gemini hacked three companies and Google didn't tell anyone

Google's Gemini AI successfully hacked into three different companies during testing in May, but Google kept it quiet until a Wall Street Journal ...

· 4 min read
Security

CISA added two actively exploited Linux kernel flaws on Thursday

The CISA KEV September 2026 update adds two Linux kernel flaws under active exploitation, CVE-2025-39682 and CVE-2026-53266. Remediation deadlines ...

· 3 min read
Security

A Pixel bug that needs no click just got a 3 day federal deadline

CVE-2026-58704 is a zero click flaw in the Pixel cellular modem. CISA gave agencies until 19 September. Here is how to check whether you are patched.

· 3 min read
Security

The tool your IT provider uses to fix your PC just got a 10.0

N-able rushed out hotfixes for three N-central flaws including a maximum severity pre-auth RCE after the platform thousands of IT providers rely on ...

· 3 min read
Security

One reused police password opened Florida's entire driver database

ShinyHunters says it broke into Florida's DAVID driver database using credentials a police officer stored on a personal device, exposing around ...

· 3 min read
Security

Cisco's network gatekeeper had a perfect 10 hole in it

CVE-2026-76460 lets an unauthenticated attacker skip Cisco ISE's login entirely and grab root, already exploited before the patch landed

· 3 min read
Security

A Parallels bug hands any Mac user root, and Intel Macs cannot install the fix

Parallels Desktop CVE-2026-90894 lets any local Mac user escalate to root. The fix ships in v27, which will not install on Intel Macs. Here is what ...

· 3 min read
Security

A cyberattack has knocked the world's meteor-tracking nonprofit offline

A nonprofit that runs one of the world's key meteor-tracking networks has been taken offline by a cyberattack, with the group warning it will be ...

· 4 min read
Security

Cisco's email gateway is under attack, and CISA added seven more flaws

CVE-2026-76461 gives unauthenticated attackers root on Cisco Secure Email Gateway. CISA added seven exploited flaws with a 16 September remediation ...

· 2 min read
Security

Boston dumps Flock Safety after firm shared licence plate data nationwide without consent

Boston has cut ties with surveillance firm Flock Safety after discovering the company enabled nationwide licence plate lookups in direct violation of ...

· 4 min read
Security

Six checks that tell you if your phone is being monitored

How to check if your phone is being monitored: six practical checks covering battery drain, the Android Privacy Dashboard, permissions and Apple ...

· 3 min read
Security

CVE-2026-73009 hits the Windows SSTP service and needs no password

CVE-2026-73009 is a CVSS 9.8 RCE flaw in the Windows SSTP service that needs no password. If your server terminates VPN traffic, check this one first.

· 3 min read
Security

Revolut had customer data stolen via fake government requests

Revolut has confirmed a customer data breach caused by attackers submitting fake government emergency data requests, a well-documented but still ...

· 4 min read
Security

GitLab scored a perfect 10 on the vulnerability scale and attackers noticed

CVE-2026-85706 lets unauthenticated attackers read any file on a GitLab server. Exploitation started within 24 hours of the patch.

· 3 min read
Security

Your AI coding assistant can be tricked into running attacker code

Security researchers found sandbox escape vulnerabilities in Cursor, Codex CLI, Gemini CLI, Claude Code, and Antigravity. The files your AI writes ...

· 3 min read
Security

One threat actor used hundreds of AI agents to compromise 440 print servers

A Russian-speaking attacker deployed AI agents built on OpenAI Codex and DeepSeek to exploit PaperCut flaws across 48 countries, reaching domain ...

· 2 min read
Security

153 million drivers licence scans are for sale on the dark web right now

IDScan, the identity verification vendor used by Hertz, Target and FedEx, lost 153 million scanned drivers licences to hackers who had access for ...

· 3 min read