Two young members of the Scattered Spider cybercrime group have been jailed for a 2024 attack that knocked out 148 Transport for London (TfL) systems, forced all 27,000 staff to reset passwords in person, and cost the organization about £29…
Tag: Cyber Security News
7-Zip Vulnerability Exposes Millions of Users to Remote Code Execution Risk
A newly disclosed vulnerability in 7-Zip, one of the most widely used open-source file archiving tools, could allow remote attackers to execute arbitrary code on affected systems. Tracked as CVE-2026-14266, the flaw stems from improper handling of XZ chunked data…
Two Hackers Jailed for Hacking 148 TfL Systems, Forcing Password Reset for 27,000 staffs
Two young members of the Scattered Spider cybercrime group have been jailed for a 2024 attack that knocked out 148 Transport for London (TfL) systems, forced all 27,000 staff to reset passwords in person, and cost the organization about £29…
Next.js Launches Monthly Security Release Program as First Update Patches 9 Vulnerabilities
Next.js has launched a monthly security release program, with the first update scheduled for July 20, 2026. This update will address nine vulnerabilities across supported versions of the framework. The initial release will provide patch updates for Next.js versions 16.2…
Top 10 Best Firewall as a Service (FWaaS) Providers – 2026
The firewall is leaving the rack: firewall-as-a-service delivers inspection, intrusion prevention, and policy from the cloud, so every user, branch, and cloud workload gets identical protection without appliances to size, patch, or refresh. Zscaler is our top FWaaS pick for 2026 on the strength…
AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service
A newly disclosed zero-day flaw in AnyDesk, tracked as CVE-2026-15682, allows local attackers to crash affected installations by abusing a core support feature, raising fresh concerns for organizations relying on the remote desktop tool for IT support and access management.…
Linus Torvalds Told Kernel Developers that Linux is Not Against AI projects
Linux creator Linus Torvalds has told kernel developers that the Linux project is not anti-AI, arguing that artificial intelligence and large language models should be judged on whether they provide practical technical value. He emphasized that developers will not be…
Dutch Police Disrupt €100 Million Investment Fraud Network Operating 20 Call Centers
Dutch police have moved against a large investment-fraud operation that allegedly used a network of call centers to reach victims at scale. The case shows how organized fraud can borrow the speed, scripts, and customer-service appearance of a legitimate business…
AI Penetration Testing Expands to Retrieval Poisoning, Memory Attacks, and Sensor Manipulation
AI systems are moving from chat windows into security operations, business workflows, and physical environments. That shift is changing what penetration testing must look for. An attacker may no longer need to breach a server or steal credentials to cause…
Hackers Actively Exploiting SonicWall SMA1000 0-Day Vulnerability in the Wild
SonicWall disclosed two vulnerabilities affecting its SMA1000 Series remote access appliances, and threat actors were already exploiting one of them before the advisory even went public. The flaws include a critical server-side request forgery (SSRF) bug, CVE-2026-15409, scoring a perfect…
Specter Turns Your Flipper Zero Into a Pocket Skimmer Detector
A new Flipper Zero app called Specter aims to turn the handheld device into a passive counter-surveillance tool for finding active 13.56 MHz NFC readers, including potentially suspicious readers hidden near payment terminals, access-control panels, desks, or other equipment. Unlike…
JetBrains Patched 6 Vulnerabilities Across TeamCity, YouTrack and IntelliJ IDEA
JetBrains has addressed six security vulnerabilities in its software development and project management products. The affected applications include IntelliJ IDEA, TeamCity, and YouTrack. The most critical vulnerability, tracked as CVE-2026-59792, is an improper path handling (CWE-23) flaw that could allow…
WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
WhatsApp users are being targeted by a social-engineering technique called GhostPairing that can give scammers access to an account without requiring a password or one-time verification code. Instead of breaking into the service directly, the scam abuses WhatsApp’s legitimate device-linking…
Hackers Don’t Crack Telegram 2FA—They Copy Your Already Logged-In Session
A macOS information-stealing malware is turning stolen Telegram desktop data into immediate account access. Instead of guessing passwords or breaking two-factor authentication, it copies the local files that prove a user has already logged in. When those files are restored…
Kratos PhaaS Attacking Microsoft 365 Users Across the US, Europe to Steal Credentials
Kratos is a phishing-as-a-service operation built to steal Microsoft 365 credentials. It is targeting organizations across the United States, Europe, and other regions by using believable document, invoice, and file-sharing lures that lead victims to fake login pages. The campaign…
GPT-Red – A Red Teamer to Find Prompt Injection Vulnerabilities in GPT 5.6 Sol
OpenAI has introduced GPT-Red, an internal automated red-teaming model designed to identify and remediate prompt injection vulnerabilities in GPT-5.6. This approach aims to tackle a growing safety challenge. While human red-team exercises are valuable, they cannot generate adversarial test cases…
CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle Payments, a component…
Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks
Splunk has released security updates addressing multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These flaws could lead to issues such as path traversal, disclosure of stored credential hashes, and arbitrary execution of SPL (Search Processing Language) searches. Three…
Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access
Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account…
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks
A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…