Topic
Security
184 stories, page 5 of 8
Three more vulnerabilities went on the actively exploited list this month
CVE-2026-18577 in N-able N-central joined CISA's exploited list alongside Cisco and Metabase flaws. All three are confirmed in use, not theoretical.
Security3.6 million employee records are for sale and Microsoft was never hacked
An Azure employee records breach put 3.6 million staff details up for sale. No zero-day was involved, just valid logins harvested by infostealer ...
SecurityWhat a privilege escalation attack actually is, and why it keeps happening
A privilege escalation attack is how an intruder turns a small foothold into full control of a machine. What that means, and why the bugs never stop.
SecurityShieldBreak is a Windows zero day that only works if Defender is switched on
The ShieldBreak zero day gives SYSTEM privileges on fully patched Windows, and it needs Microsoft Defender running to work. There is no patch yet.
SecurityLazarus used a Windows zero-day to drop a kernel rootkit on aerospace firms
CVE-2026-68820 is a Windows zero day Lazarus used to install the FudModule rootkit at defence and aerospace firms. Here is what it does and who was ...
SecurityThe 3-2-1 backup rule, and how to actually do it in 2026
The 3-2-1 backup rule means three copies, two media types, one offsite. Here is how to actually build it in 2026, and why ransomware breaks the lazy ...
SecurityWhat is vishing, and how to prevent the call that got into Abbott
What is vishing? A voice phishing call captured an SSO login at Abbott and unlocked five connected systems. Here is how the call works and how to ...
SecurityMicrosoft patched 421 flaws in one day, and one of them is wormable
Microsoft August 2026 Patch Tuesday shipped 421 CVEs, the largest batch on record, with one exploited zero-day and a DNS Server bug analysts flagged ...
SecurityHackers are already exploiting the Windows zero-day Microsoft just patched
Microsoft patched Windows zero-day CVE-2026-68820 this week, but attackers are already exploiting it, and a Cisco ASA VPN flaw is under attack too.
SecurityMetabase zero-day exploited in the wild
A maximum-severity flaw in the Metabase business intelligence platform is being actively exploited. Patch immediately.
SecurityA fake VS Code extension was quietly draining developer wallets
A malicious Visual Studio Code extension called Solidity Pro was caught stealing browser wallet credentials and API keys from developers who ...
SecurityClop just added Shell to its list of victims
Clop's ransomware crew hit Shell on 12 August 2026, exfiltrating engineering drawings and facility photos in its latest mass-extortion campaign.
SecurityThe Open Secure AI Alliance's SAFE framework wants to make agentic AI honest about its risks
As AI agents become capable of taking real actions in the world, sending emails, executing code, managing files, making purchases, the question of ...
SecurityA Windows bug Lazarus was already exploiting just got patched
Microsoft's August 2026 Patch Tuesday fixes 421 CVEs including a WinSock zero-day North Korea's Lazarus group used to deploy the FudModule rootkit.
SecurityMalware just learned to steal the login method that was supposed to be unstealable
New malware can now steal Google's synced passkeys, undercutting the pitch that passkeys can't be phished or stolen the way passwords can.
SecurityA firmware flaw in a hardware wallet just cost someone 70 million dollars
A firmware vulnerability in the Coldcard hardware wallet was exploited to drain 70 million dollars in Bitcoin, undermining the case for cold storage ...
SecurityZoom Zoomsday bug let attackers hijack any device through screen sharing
Critical Zoom Zoomsday vulnerability CVE-2026-53413 allowed zero-click remote code execution through screen sharing on all platforms.
SecurityShieldBreak zero-day drops hours after Microsoft patches 421 flaws
A hacker released ShieldBreak, a new zero-day targeting Microsoft Defender, hours after Patch Tuesday fixed 421 vulnerabilities including 3 zero-days.
SecurityRansomware attacks on billion-dollar companies jumped 74 percent in a single quarter
Ransomware groups shifted strategy in Q2 2026, with attacks on companies earning over 1 billion dollars surging 74 percent quarter over quarter.
SecurityA major ransomware attack has hit NHS systems across England
The National Health Service has been targeted by ransomware before.
SecurityCritical VMware and Cisco flaws are under active attack: Patch this week
Two critical flaws in VMware and Cisco are under active attack, letting attackers skip the login screen. Here is what to patch this week and why it ...
SecurityPasskeys explained: Why passwords are finally dying
Passkeys swap your password for a device key unlocked by your face or fingerprint. Here is what they are, why they beat passwords, and how to switch ...
SecurityThe crowdstrike fallout report is out and the findings are uncomfortable reading
The July 2024 CrowdStrike Falcon sensor update that took down an estimated 8.5 million Windows devices globally was not, in any meaningful sense, a.
SecurityThe EU AI Act's first major enforcement action has arrived and it targets biometric surveillance
The EU AI Act has had its first genuinely consequential enforcement moment.
SecurityAutomotive parts platform RevolutionParts breach hits 5 million records
RevolutionParts, an e-commerce platform that thousands of car dealerships use to sell parts and accessories online, has confirmed a data breach ...