Your inbox is an identity system all of its own: whoever owns it may own a lot more
Pro-Iran hackers who took credit for a nationwide Friday outage of a platform delivering emergency alerts in major U.S. cities said today that they hacked the National Weather Service website....
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging...
Pro-Iran hackers who have claimed attacks on multiple Western websites throughout the U.S.-Israel conflict with the Islamic Republic said they were behind the outage of an incident response...
The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to...
OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government....
Plus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more.
Time to start praying to the goddess of wisdom and war
Google Chrome security advisory (AV26-634)
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal...
Personal cell phones on protective missions, no threat detection on government-issued devices among the litany of sins
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on...
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure...
Chinese companies control nearly two-thirds of Argentina’s own squid fleet.
A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the...
A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace,...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product...
Researchers warn many AI coding assistants now execute commands from project configurations
DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public...
AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built...
We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.)
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm...
Exposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special operations officer.
Dear readers, In a rare joint call to action, the leaders of the Five Eyes cybersecurity agencies issued a stark warning this week that the timeline for frontier AI models “to exceed current...
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig...
Four selected agencies—the Departments of State, Transportation, Veterans Affairs (VA), and the Small Business Administration —varied in their efforts to implement and ensure contractor compliance...
When the Iranian missiles and drones came for the nerve center of America’s naval operations in the Middle East, some of them hit their mark. The U.S. Navy base in Bahrain was repeatedly targeted...
Innocuous error reports, hypersonic targets, and a mystery with no fingerprints
Fake USB sticks used by the Japanese army spread a China-linked computer virus inside a secure network for nearly a year before they were found to contain malware, Japan’s Nikkei newspaper...
Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop...