Topic

Security

184 stories, page 5 of 8

Security

Three more vulnerabilities went on the actively exploited list this month

CVE-2026-18577 in N-able N-central joined CISA's exploited list alongside Cisco and Metabase flaws. All three are confirmed in use, not theoretical.

· 2 min read
Security

3.6 million employee records are for sale and Microsoft was never hacked

An Azure employee records breach put 3.6 million staff details up for sale. No zero-day was involved, just valid logins harvested by infostealer ...

· 3 min read
Security

What a privilege escalation attack actually is, and why it keeps happening

A privilege escalation attack is how an intruder turns a small foothold into full control of a machine. What that means, and why the bugs never stop.

· 3 min read
Security

ShieldBreak is a Windows zero day that only works if Defender is switched on

The ShieldBreak zero day gives SYSTEM privileges on fully patched Windows, and it needs Microsoft Defender running to work. There is no patch yet.

· 3 min read
Security

Lazarus used a Windows zero-day to drop a kernel rootkit on aerospace firms

CVE-2026-68820 is a Windows zero day Lazarus used to install the FudModule rootkit at defence and aerospace firms. Here is what it does and who was ...

· 3 min read
Security

The 3-2-1 backup rule, and how to actually do it in 2026

The 3-2-1 backup rule means three copies, two media types, one offsite. Here is how to actually build it in 2026, and why ransomware breaks the lazy ...

· 4 min read
Security

What is vishing, and how to prevent the call that got into Abbott

What is vishing? A voice phishing call captured an SSO login at Abbott and unlocked five connected systems. Here is how the call works and how to ...

· 3 min read
Security

Microsoft patched 421 flaws in one day, and one of them is wormable

Microsoft August 2026 Patch Tuesday shipped 421 CVEs, the largest batch on record, with one exploited zero-day and a DNS Server bug analysts flagged ...

· 3 min read
Security

Hackers are already exploiting the Windows zero-day Microsoft just patched

Microsoft patched Windows zero-day CVE-2026-68820 this week, but attackers are already exploiting it, and a Cisco ASA VPN flaw is under attack too.

· 3 min read
Security

Metabase zero-day exploited in the wild

A maximum-severity flaw in the Metabase business intelligence platform is being actively exploited. Patch immediately.

· 2 min read
Security

A fake VS Code extension was quietly draining developer wallets

A malicious Visual Studio Code extension called Solidity Pro was caught stealing browser wallet credentials and API keys from developers who ...

· 2 min read
Security

Clop just added Shell to its list of victims

Clop's ransomware crew hit Shell on 12 August 2026, exfiltrating engineering drawings and facility photos in its latest mass-extortion campaign.

· 2 min read
Security

The Open Secure AI Alliance's SAFE framework wants to make agentic AI honest about its risks

As AI agents become capable of taking real actions in the world, sending emails, executing code, managing files, making purchases, the question of ...

· 4 min read
Security

A Windows bug Lazarus was already exploiting just got patched

Microsoft's August 2026 Patch Tuesday fixes 421 CVEs including a WinSock zero-day North Korea's Lazarus group used to deploy the FudModule rootkit.

· 2 min read
Security

Malware just learned to steal the login method that was supposed to be unstealable

New malware can now steal Google's synced passkeys, undercutting the pitch that passkeys can't be phished or stolen the way passwords can.

· 2 min read
Security

A firmware flaw in a hardware wallet just cost someone 70 million dollars

A firmware vulnerability in the Coldcard hardware wallet was exploited to drain 70 million dollars in Bitcoin, undermining the case for cold storage ...

· 2 min read
Security

Zoom Zoomsday bug let attackers hijack any device through screen sharing

Critical Zoom Zoomsday vulnerability CVE-2026-53413 allowed zero-click remote code execution through screen sharing on all platforms.

· 2 min read
Security

ShieldBreak zero-day drops hours after Microsoft patches 421 flaws

A hacker released ShieldBreak, a new zero-day targeting Microsoft Defender, hours after Patch Tuesday fixed 421 vulnerabilities including 3 zero-days.

· 3 min read
Security

Ransomware attacks on billion-dollar companies jumped 74 percent in a single quarter

Ransomware groups shifted strategy in Q2 2026, with attacks on companies earning over 1 billion dollars surging 74 percent quarter over quarter.

· 3 min read
Security

A major ransomware attack has hit NHS systems across England

The National Health Service has been targeted by ransomware before.

· 4 min read
Security

Critical VMware and Cisco flaws are under active attack: Patch this week

Two critical flaws in VMware and Cisco are under active attack, letting attackers skip the login screen. Here is what to patch this week and why it ...

· 3 min read
Security

Passkeys explained: Why passwords are finally dying

Passkeys swap your password for a device key unlocked by your face or fingerprint. Here is what they are, why they beat passwords, and how to switch ...

· 3 min read
Security

The crowdstrike fallout report is out and the findings are uncomfortable reading

The July 2024 CrowdStrike Falcon sensor update that took down an estimated 8.5 million Windows devices globally was not, in any meaningful sense, a.

· 4 min read
Security

The EU AI Act's first major enforcement action has arrived and it targets biometric surveillance

The EU AI Act has had its first genuinely consequential enforcement moment.

· 4 min read
Security

Automotive parts platform RevolutionParts breach hits 5 million records

RevolutionParts, an e-commerce platform that thousands of car dealerships use to sell parts and accessories online, has confirmed a data breach ...

· 2 min read