Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff

Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff. The post Microsoft... Read more »

ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken... Read more »

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to... Read more »

Department for Education suffers data breach

The UK’s Department for Education has disclosed a serious data breach orchestrated via a social engineering attack on its external-facing helpdesk. Read more »

Laundry Bear pivots to new exploit days after Zimbra alert

The NCSC and partners warned of a novel phishing technique being deployed against high-profile users of Zimbra’s Communication Suite, but the threat actor behind the campaign already seems to... Read more »

OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached... Read more »

OpenAI’s Rogue AI Agent Breached Second Company, Report Says

Reuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent... Read more »

VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims

A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum... Read more »

How IT leaders can start the shift to quantum-safe security

One of the myths of post-quantum computing is that IT leaders can make no meaningful progress until they launch a dedicated transformation programme, but there are simple, impactful steps... Read more »

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine... Read more »
Subscribe to our Newsletter