A cloud database containing more than 9 million facial images was left exposed without authentication, according to security researcher Jeremiah Fowler.
Tag: EN
OpenAI Enhances Model Security With Sandboxing
OpenAI has rolled out significant security improvements to its AI model infrastructure, introducing sandboxing technology, rapid alert systems, and…
Cisco Patches Critical Crosswork, Secure Workload Flaws
Cisco has issued security updates addressing critical vulnerabilities in its Crosswork network automation platform and Secure Workload security solution.
Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an…
Premier League mandates cybersecurity standards
The Premier League has implemented mandatory cybersecurity standards for all member clubs, marking the first time the organization has moved beyond…
Twitch wants your content for Amazon AI training. Here’s how to opt out
Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.
OpenAI TAC program glitch locks out security researchers
OpenAI’s Trusted Access for Cyber (TAC) program experienced a technical failure this week that removed vetted security researchers from the system and…
Why DAST Findings Are Hard to Fix and How to Make Them Actionable
Dynamic testing is essential because it uncovers vulnerabilities in running applications. But while SAST gets the attention because it’s shift-left and…
AI data giant Alation confirms cyberattack
The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.
New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts
Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as…
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.
The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI
At 9:03, an employee opens an approved AI assistant with a corporate account and asks it to summarize launch notes. At 9:27, a feature they need is…
78 arrests in bust of major Western Mediterranean smuggling network in Spain
The operation, conducted under a newly established Europol Taskforce within Europol’s European Centre Against Migrant Smuggling, brought together officers…
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications,…
Using Microsoft Graph and Powershell – Risk Detection Commands, (Thu, Aug 20th)
Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at “Risky” logins.
PacketFence Cloud: Enterprise Network Access Control, Now a Managed Service
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: PacketFence Cloud: Enterprise Network Access Control, Now a Managed Service
Why “Shady AI” is Security’s Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t…
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network…
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.