Topic
Security
184 stories, page 7 of 8
CISA built its incident response playbook during the actual incident
The US government's own cyber defence agency had to write its incident response playbook mid-crisis after a contractor leaked passwords on a public ...
SecurityPTC Windchill users: attackers are dropping webshells right now
CVE-2026-12569, an unauthenticated RCE flaw in PTC Windchill PDMLink and FlexPLM, is under active exploitation with JSP webshells confirmed on ...
SecuritySimpleHelp RMM zero-day (CVSS 10.0) hits MSP supply chain
CVE-2026-48558 scores a maximum 10.0 and is under active exploitation. Here's who's at risk and what to do about it.
SecurityKDDI's breach hit 14.22 million people, and it's not even all KDDI's fault
Japanese telecommunications giant KDDI has disclosed a breach of its email system that exposed email addresses and, in some cases, passwords ...
SecurityCISA and the UK's NCSC put a name to the covert networks warning
CISA, the UK's National Cyber Security Centre, and a coalition of international partners have issued a joint advisory describing how Chinese.'s NCSC ...
SecurityRansomware gangs are exploiting a Windows Defender flaw called BlueHammer
CISA has confirmed that ransomware operators are actively exploiting CVE-2026-33825, a privilege-escalation vulnerability in Microsoft Defender ...
SecurityJadePuffer is the first ransomware that thinks for itself mid-attack
Researchers documented JadePuffer, the first known agentic ransomware that adapts its own attack in real time.
SecurityCloudflare just gave every website a switch to cut AI off from its content
Cloudflare's new AI crawler policy blocks training and agent bots on ad-funded pages by default from September 15, 2026, unless site owners opt out.
SecurityThe 'first' AI-run ransomware attack still needed a human to pull it off
Everyone has been bracing for the moment AI goes fully rogue in the cybercrime world.
SecurityA Linux kernel bug called Bad Epoll lets any user become root
CVE-2026-46242, nicknamed Bad Epoll, lets an unprivileged Linux user jump straight to root. No malicious click needed. Here is what to patch.
SecurityWorld Cup fans are being watched by hundreds of federal drones and cameras
If you are heading to a World Cup match this summer, you might want to know that the experience comes with an invisible extra: a surveillance ...
SecurityAirDrop and Quick Share both have unpatched flaws that let strangers push files at your phone
Six issues were disclosed across Apple AirDrop and Android Quick Share that could let a nearby attacker drop files on a device. Here is the simple ...
SecurityThere's a SharePoint bug hackers are already using, and the US just gave itself one day to fix it
CVE-2026-45659 lets attackers run code on SharePoint Server with no login needed. CISA gave US agencies until July 4 to patch it.
SecurityPamStealer is the macOS malware that doesn't want to be found
A newly discovered piece of macOS malware called PamStealer is doing something most credential-stealing software doesn't bother with: being genuinely.
SecurityKemp LoadMaster command injection under attack
A CVSS 9.6 command injection flaw in Progress Kemp LoadMaster load balancers is seeing active exploitation attempts.
SecurityDHS HSIN breach: Hackers inside a US security Network
DHS confirmed hackers breached the Homeland Security Information Network during an active World Cup security operation.
SecurityConnecticut adds neural data to its privacy law
From 1 July 2026, Connecticut classifies neural data as sensitive personal information under its state privacy law, one of the first US states to do ...
SecurityCisco Catalyst SD-WAN auth bypass CVE-2026-20182
A critical authentication bypass in Cisco Catalyst SD-WAN Controller scored a perfect 10.0 on the CVSS scale and is already being exploited.
SecurityAdobe patches critical ColdFusion and Campaign Classic flaws
Adobe released patches for critical flaws in ColdFusion and Campaign Classic, both rated at the top of the severity scale.
SecurityNotion breach exposes 110 million user records
A hacker claims to have breached Notion, exposing 110 million user records. Because Notion holds API keys and business plans, the exposure is ...
SecurityAnthropic wants your passport. Here's what's actually happening with Claude's new ID checks
From July 8, Anthropic can demand a government ID and facial scan from consumer Claude users.
SecurityThe European Space Agency got hacked. The reason why is embarrassingly preventable.
The ESA data breach 2026 exposed source code, API tokens and hardcoded passwords. A space agency breached by one of the most avoidable mistakes in ...
SecurityBuying World Cup tickets? Watch out for the scam wave
Security firms are warning of phishing, fake ticket sites and fraud targeting the 2026 World Cup across the US, Canada and Mexico. How to stay safe.
SecurityTexas Parks and Wildlife breach may expose three million people
A breach at the Texas Parks and Wildlife Department may have exposed driver's licence, passport and contact details for more than three million ...
SecurityOne Medical hit by ransomware, 8.8 TB of data claimed
ShinyHunters claims to have stolen 8.8 TB from One Medical, the Amazon-owned primary care service handling millions of US health records.