Australian Police Charge Two Over TeamPCP Credential Theft

Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western... Read more »

Passenger data stolen from major UK airports

Identifying data on passengers who flew from East Midlands, Stansted and Manchester airports has been stolen by an unnamed threat actor. Read more »

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described... Read more »

Peers propose report into Computer Misuse Act reform

After previous proposals were brushed aside, Computer Misuse Act reform may be back on the agenda under a new amendment to the Cyber Security and Resilience Bill. Read more »

Meta to Pay Up to $18B Over Teen Social Media Use

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay... Read more »

CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do

CISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US... Read more »

Public wary of UK government ‘backdoor’ surveillance following Apple row, poll reveals

A poll of 2,000 UK citizens taken after the government issued a secret order seeking access to Apple users’ encrypted data finds that the public is sceptical of government surveillance... Read more »

OpenAI banned Russian ChatGPT accounts backing covert influence operation

OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives. OpenAI says it has banned... Read more »

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to... Read more »

CISA Red Team Fully Compromised Two Critical Infrastructure Orgs

CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous... Read more »
Subscribe to our Newsletter