Latest news
-
Breaches via The Register
Ministry of Justice apologizes after court staff accessed Southport victims' files
The Ministry of Justice (MoJ) has apologized after court staff accessed documents relating to victims and survivors of the 2024 Southport murders without authorization…
-
Vulnerabilities via Malwarebytes Labs
Google Pixel owners urged to patch actively exploited modem flaw
Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.” The…
-
via Wired
Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images…
-
Vulnerabilities via Cisco Talos
Securing the unpatchable in an age of AI-driven vulnerabilities
AI is accelerating vulnerability discovery, leaving unpatchable operational technology (OT) systems at risk. Hoping for the best is not a viable anti-exploitation…
-
AI Security via SentinelLABS
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research…
-
Threat Intel via Kaspersky Securelist
NightEagle targets Russian companies
Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (also tracked as APT-Q-95). This group…
-
Threat Intel via Palo Alto Networks Unit 42
Atomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.
-
Vulnerabilities via Infosecurity Magazine
Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
-
via Infosecurity Magazine
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
-
AI Security via ESET WeLiveSecurity
Cyberthreats are moving faster than SMBs: Readiness must accelerate
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts
-
AI Security via Malwarebytes Labs
AI helps scammers build convincing antivirus renewal pages
Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are…
-
Threat Intel via Infosecurity Magazine
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
-
Vulnerabilities via The Register
Mythos has made 2026 patching hell. It might make 2027 a breeze
When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec…
-
Threat Intel via Group-IB
The Adversary We Are Fighting Is Now a Full-Force Industry: Inside cybercrime’s new economy
Attacks now are cheap, fast, and outsourced. The recent research shows what it changes and how organizations should strategy defense.
-
Vulnerabilities via Zero Day Initiative
ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required…
-
Vulnerabilities via Zero Day Initiative
ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute…
