The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight contro…
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infoste…
Natalie Dreier reports: A Florida man who calls himself a “cybersecurity engineer” on TikTok and Twitch was arrested after police reopened an investigation clo…
JiJi reports: Japanese police have captured a Russian national believed to be a key member of the “Qilin” international hacker group and extradited him to Germ…
Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation: On October 5, 2026, Danish authorities publicly …
Sarah Butler reports: ASOS is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion r…
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There…
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful …
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol d…
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousand…
A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of device…
Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Justin Doubleday reports: The Cybersecurity and Infrastructure Security Agency is continuing to offer cyber pay incentives to retain skilled technical staff, b…
Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited reso…
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and r…
Saif al-Din Khader is cooperating with the FBI, reports said, as the bureau responds to a massive breach that exposed employee data.
Every request an analyst sends to a phishing page or criminal forum carries an IP…Anonymous Proxies Review 2026: Proxy Types, Security Use Cases and Who It’s F…
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…