Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff. The post Microsoft... Read more »
ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken... Read more »
Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to... Read more »
The UK’s Department for Education has disclosed a serious data breach orchestrated via a social engineering attack on its external-facing helpdesk. Read more »
The NCSC and partners warned of a novel phishing technique being deployed against high-profile users of Zimbra’s Communication Suite, but the threat actor behind the campaign already seems to... Read more »
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached... Read more »
Reuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent... Read more »
A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum... Read more »
One of the myths of post-quantum computing is that IT leaders can make no meaningful progress until they launch a dedicated transformation programme, but there are simple, impactful steps... Read more »
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine... Read more »
