Customer identity is where security meets revenue: every point of login friction costs conversions, while every authentication gap invites account…
Tag: EN
Gemini crosses the line in cybersecurity test
Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets…
ZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification
ZTE has addressed four vulnerabilities in its SmartLife mobile application following the discovery of critical weaknesses that allowed attackers to…
Vidar Malware Rewrites Its Obfuscation With Every Build to Make Detection Harder
Vidar has spent years stealing the data people keep closest: saved passwords, browser cookies, wallet files and system details. Now its operators have…
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to…
Hackers Steal NTDS.dit to Dump Active Directory Password Hashes and Forge Golden Tickets
Threat actors that gain a foothold in a Windows network are increasingly aiming for the domain controller, the server that manages identities and…
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in…
Top 10 Best Identity Threat Detection & Response (ITDR) Tools in 2026 [Ranked & Scored]
The modern breach doesn’t kick the door in it signs in. Stolen sessions, abused service accounts, and helpdesk-reset social engineering made identity the…
LimeLeads – 17,838,396 breached accounts
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The…
D-Link Router Hit by CVSS 10.0 Flaw Exploitable Remotely Without Authentication
D-Link Systems has disclosed that it is investigating a critical security vulnerability in its DIR-822A router, tracked as CVE-2026-86296. The flaw has…
Introducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.
Windows COM Flaw Lets Attackers Gain SYSTEM Privileges With a Malicious DLL
A newly detailed Windows privilege escalation flaw tracked as CVE-2026-66804 allowed a standard, low-privileged user to plant a malicious DLL and execute…
Developers Complain After Z.ai’s ZCode Sends Data To Cloud
Developers say ZCode sent details on their coding projects to external cloud server without their knowledge or consent
How to Use AI With Your Privacy Intact
Your conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself.
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy…
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus…
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app…
Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes…
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This…
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.
