Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other…
Tag: EN
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still…
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
A new Linux bot called Tengu is built to stay hidden and turn compromised systems into tools for disruption. The 32-bit malware poses as a routine kernel…
LG Smart TVs Caught Scanning Networks and Logging Audio in Standby
Your LG smart TV may be doing far more than displaying your favorite shows while it sits “off” in the corner of your living room. A new investigation from…
OpenAI Commits $1 Billion to Give Critical Infrastructure Defenders Frontier AI Cyber Tools
OpenAI has launched Daybreak for Frontline Defenders, a global cybersecurity initiative designed to help organizations protecting essential services use…
New BYOTC Attack Hijacks Trusted Windows Apps to Abuse Privileged Kernel Drivers
A new Windows attack shows how a trusted program can become a path to sensitive system functions. The method, called Bring Your Own Trusted Caller, or…
Vadodara Businessman Duped of Rs 19.75 Lakh in Fake Supplier Email Scam
A city-based businessman lost close to Rs 20 lakh after fraudsters hijacked his correspondence with a Dubai supplier and rerouted a payment meant for a…
ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps
ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and…
Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users
Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents,…
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs…
Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives
Switzerland’s federal administration is preparing to test a sovereign, open-source digital workplace that could reduce its long-term dependence on…
Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance
Microsoft will retire support for Manifest V2 browser extensions in Microsoft Edge by early 2027, requiring users, enterprises, and developers to move to…
HPE Patches Multiple ArubaOS-CX Vulnerabilities
Hewlett Packard Enterprise has released a security advisory for Aruba Networking ArubaOS-CX, warning customers about multiple vulnerabilities affecting…
Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach
Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and…
Nightwing CEO has a Labor Day message for staff – and apparently The Register
Nothing says ‘For internal use only’ quite like emailing it to the press
Cloudflare and CrowdStrike Bring AI Agents Into the Cyber Defense Fight
Cloudflare is using OpenAI GPT-5.6 Cyber to automate vulnerability discovery and remediation as AI agents reshape enterprise security operations.
IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers
Identity verification company IDScan is being sued in multiple cases after hackers allegedly gained unauthorized access to the service and started selling…
CrowdStrike Investigates FalconFlank Zero-Day as PoC Reaches SYSTEM
CrowdStrike is investigating FalconFlank, a privilege-escalation PoC that can reach SYSTEM access. Here’s what defenders should disable and monitor.
LG TV flaws could let attackers listen in, even in standby mode
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks