Your Shredded Visa Card May Still Work at the Checkout

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst... Read more »

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global... Read more »

Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off

Amazon’s less-detailed order emails protect purchase data but may make phishing harder to spot. Learn how to verify order messages safely online. The post Amazon’s Order Email Privacy Change... Read more »

Windows 11 24H2 Home and Pro Support Ends Oct. 13: What Users Should Do

Windows 11 24H2 Home and Pro support ends Oct. 13, 2026. Here’s what users and IT teams should know about upgrading to Windows 11 25H2. The post Windows 11... Read more »

ICE Warns Employees Against Meta Smart Glasses

ICE warned employees against using Meta smart glasses on duty as DHS seeks $7.5 million to develop biometric-enabled prototypes for field agents. The post ICE Warns Employees Against Meta... Read more »

NCSC tells organisations to have AI kill switches at the ready

In the wake of a series of cyber incidents involving AI agents, the NCSC has published interim guidance for operators of agentic systems, advising organisations retain the ability to... Read more »

Six Maximum-Severity Flaws Found in Cisco Products

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its... Read more »

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber... Read more »

Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this... Read more »

GitLab Warns of Active Exploitation of Critical GraphQL Flaw

GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS... Read more »
Subscribe to our Newsletter