OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify…
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink. According to…
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and…
AI safety tests reach the internet, Private Relay flaw unmasks IPs, weak telcos invite Salt Typhoon
AI safety tests spill onto the real internet Private Relay flaw unmasks IP addresses Weak telcos left door open for Salt Typhoon Get the show notes here:…
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to…
Microsoft Links Hotel Wi-Fi Attacks Stealing Microsoft 365 Accounts to Russian Hackers
Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard (APT29). Thank you for being…
Explosives-Laden Drone Found At German Airport
Quadcopter fitted with explosive device defused after being found near Ukrainian cargo jet at major air freight hub in Leipzig
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.
ICO Reprimands Met Police After Data Leaks
Data protection regulator tells Met to do more, after officer accidentally sends contact details of stalking victim to defendant
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the…
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy…
250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks
Atomic Stealer is being pushed at Mac users through websites that look harmless. A large ClickFix operation uses more than 250 look-alike domains to steer…
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now
Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical…
OWASP 2026 LLM Top 10: “The model will be fooled”
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by…
Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses
Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in…
250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers
Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures…
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while…
Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records
Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka,…
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access…
Browser security is where software, data, and AI meet
In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not…
Non-human identities are 91% of everything active in production
A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging…
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
It’s just a remote maintenance function, says Zbtlink
Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access…