Topic

Security

184 stories, page 7 of 8

Security

CISA built its incident response playbook during the actual incident

The US government's own cyber defence agency had to write its incident response playbook mid-crisis after a contractor leaked passwords on a public ...

· 4 min read
Security

PTC Windchill users: attackers are dropping webshells right now

CVE-2026-12569, an unauthenticated RCE flaw in PTC Windchill PDMLink and FlexPLM, is under active exploitation with JSP webshells confirmed on ...

· 2 min read
Security

SimpleHelp RMM zero-day (CVSS 10.0) hits MSP supply chain

CVE-2026-48558 scores a maximum 10.0 and is under active exploitation. Here's who's at risk and what to do about it.

· 2 min read
Security

KDDI's breach hit 14.22 million people, and it's not even all KDDI's fault

Japanese telecommunications giant KDDI has disclosed a breach of its email system that exposed email addresses and, in some cases, passwords ...

· 2 min read
Security

CISA and the UK's NCSC put a name to the covert networks warning

CISA, the UK's National Cyber Security Centre, and a coalition of international partners have issued a joint advisory describing how Chinese.'s NCSC ...

· 2 min read
Security

Ransomware gangs are exploiting a Windows Defender flaw called BlueHammer

CISA has confirmed that ransomware operators are actively exploiting CVE-2026-33825, a privilege-escalation vulnerability in Microsoft Defender ...

· 2 min read
Security

JadePuffer is the first ransomware that thinks for itself mid-attack

Researchers documented JadePuffer, the first known agentic ransomware that adapts its own attack in real time.

· 3 min read
Security

Cloudflare just gave every website a switch to cut AI off from its content

Cloudflare's new AI crawler policy blocks training and agent bots on ad-funded pages by default from September 15, 2026, unless site owners opt out.

· 5 min read
Security

The 'first' AI-run ransomware attack still needed a human to pull it off

Everyone has been bracing for the moment AI goes fully rogue in the cybercrime world.

· 4 min read
Security

A Linux kernel bug called Bad Epoll lets any user become root

CVE-2026-46242, nicknamed Bad Epoll, lets an unprivileged Linux user jump straight to root. No malicious click needed. Here is what to patch.

· 2 min read
Security

World Cup fans are being watched by hundreds of federal drones and cameras

If you are heading to a World Cup match this summer, you might want to know that the experience comes with an invisible extra: a surveillance ...

· 4 min read
Security

AirDrop and Quick Share both have unpatched flaws that let strangers push files at your phone

Six issues were disclosed across Apple AirDrop and Android Quick Share that could let a nearby attacker drop files on a device. Here is the simple ...

· 2 min read
Security

There's a SharePoint bug hackers are already using, and the US just gave itself one day to fix it

CVE-2026-45659 lets attackers run code on SharePoint Server with no login needed. CISA gave US agencies until July 4 to patch it.

· 3 min read
Security

PamStealer is the macOS malware that doesn't want to be found

A newly discovered piece of macOS malware called PamStealer is doing something most credential-stealing software doesn't bother with: being genuinely.

· 4 min read
Security

Kemp LoadMaster command injection under attack

A CVSS 9.6 command injection flaw in Progress Kemp LoadMaster load balancers is seeing active exploitation attempts.

· 2 min read
Security

DHS HSIN breach: Hackers inside a US security Network

DHS confirmed hackers breached the Homeland Security Information Network during an active World Cup security operation.

· 2 min read
Security

Connecticut adds neural data to its privacy law

From 1 July 2026, Connecticut classifies neural data as sensitive personal information under its state privacy law, one of the first US states to do ...

· 2 min read
Security

Cisco Catalyst SD-WAN auth bypass CVE-2026-20182

A critical authentication bypass in Cisco Catalyst SD-WAN Controller scored a perfect 10.0 on the CVSS scale and is already being exploited.

· 2 min read
Security

Adobe patches critical ColdFusion and Campaign Classic flaws

Adobe released patches for critical flaws in ColdFusion and Campaign Classic, both rated at the top of the severity scale.

· 2 min read
Security

Notion breach exposes 110 million user records

A hacker claims to have breached Notion, exposing 110 million user records. Because Notion holds API keys and business plans, the exposure is ...

· 2 min read
Security

Anthropic wants your passport. Here's what's actually happening with Claude's new ID checks

From July 8, Anthropic can demand a government ID and facial scan from consumer Claude users.

· 2 min read
Security

The European Space Agency got hacked. The reason why is embarrassingly preventable.

The ESA data breach 2026 exposed source code, API tokens and hardcoded passwords. A space agency breached by one of the most avoidable mistakes in ...

· 2 min read
Security

Buying World Cup tickets? Watch out for the scam wave

Security firms are warning of phishing, fake ticket sites and fraud targeting the 2026 World Cup across the US, Canada and Mexico. How to stay safe.

· 2 min read
Security

Texas Parks and Wildlife breach may expose three million people

A breach at the Texas Parks and Wildlife Department may have exposed driver's licence, passport and contact details for more than three million ...

· 2 min read
Security

One Medical hit by ransomware, 8.8 TB of data claimed

ShinyHunters claims to have stolen 8.8 TB from One Medical, the Amazon-owned primary care service handling millions of US health records.

· 2 min read