Red Hat security advisory (AV26-652)
The soaring temperatures pushed the Mid-Atlantic’s electrical grid to the brink on Thursday, when it was feared that air-conditioning units across 13 states – combined with data centers’...
Russian hackers are suspected of gaining access to Foreign Office and council systems using stolen logins. The cybercriminals breached security firewalls provided by Fortinet, a cyber security...
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the...
Between August 2024 and February 2026, Uninhabited Aerial Vehicles (UAVs) were flown in the airspace of a dozen NATO member states and Ireland, forcing repeated closures of major commercial...
ShinyHunters leaks names, addresses, DOBs, and more after Christian college discloses cyberattack
President Donald Trump enters the annual NATO leaders’ summit in Ankara next week with powerful leverage over the military alliance: The U.S. has the world’s most advanced artificial intelligence...
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong...
Modula-based source code resurfaces after nearly four decades
France is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant...
The Office of Professional Responsibility has opened more than 100 cases over what ICE officials call “incidents of doxing and threats” against ICE employees.
The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.
Financial institutions are putting their clients at risk in the name of convenience.
We are currently witnessing a quiet but profound shift in how the next generation seeks to manage emotional regulation. We see a new mental health behavior has firmly established itself within a...
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the...
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google...
Attested TLS: the handshake that can't prove who's on the other end
Attested TLS: the handshake that can't prove who's on the other end
Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The...
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and...
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing...
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to...
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and...
GitHub security advisory (AV26-650)
Erlang security advisory (AV26-651)
A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while...
Third-party contractor compromise exposed health information and insurance billing passwords
In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly,...
WatchGuard security advisory (AV26-649)