Latest news

  1. Breaches via The Register

    Ministry of Justice apologizes after court staff accessed Southport victims' files

    The Ministry of Justice (MoJ) has apologized after court staff accessed documents relating to victims and survivors of the 2024 Southport murders without authorization…

  2. Vulnerabilities via Malwarebytes Labs

    Google Pixel owners urged to patch actively exploited modem flaw

    Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.” The…

  3. via Wired

    Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works

    A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images…

  4. Vulnerabilities via Cisco Talos

    Securing the unpatchable in an age of AI-driven vulnerabilities

    AI is accelerating vulnerability discovery, leaving unpatchable operational technology (OT) systems at risk. Hoping for the best is not a viable anti-exploitation…

  5. AI Security via SentinelLABS

    Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

    Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research…

  6. Threat Intel via Kaspersky Securelist

    NightEagle targets Russian companies

    Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (also tracked as APT-Q-95). This group…

  7. Threat Intel via Palo Alto Networks Unit 42

    Atomic macOS (AMOS) Stealer Activity

    Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.

  8. Vulnerabilities via Infosecurity Magazine

    Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    OPSWAT researchers find two zero-days in TP-Link cameras

  9. via Infosecurity Magazine

    Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

    A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program

  10. AI Security via ESET WeLiveSecurity

    Cyberthreats are moving faster than SMBs: Readiness must accelerate

    As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts

  11. AI Security via Malwarebytes Labs

    AI helps scammers build convincing antivirus renewal pages

    Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are…

  12. Threat Intel via Infosecurity Magazine

    NCSC and Allies Warn of Iranian Spyware Campaign

    The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents

  13. Vulnerabilities via The Register

    Mythos has made 2026 patching hell. It might make 2027 a breeze

    When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec…

  14. Threat Intel via Group-IB

    The Adversary We Are Fighting Is Now a Full-Force Industry: Inside cybercrime’s new economy

    Attacks now are cheap, fast, and outsourced. The recent research shows what it changes and how organizations should strategy defense.

  15. Vulnerabilities via Zero Day Initiative

    ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in…

  16. Vulnerabilities via Zero Day Initiative

    ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability

    This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit…

  17. Vulnerabilities via Zero Day Initiative

    ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute…

  18. Vulnerabilities via Zero Day Initiative

    ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this…

  19. Vulnerabilities via Zero Day Initiative

    ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required…

  20. Vulnerabilities via Zero Day Initiative

    ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute…