Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining …
Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers
A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers. Instead of leaving an obvious malicious PHP file behind, …
Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users
Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents, guardians, and school staff across Australia and New …
Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives
Switzerland’s federal administration is preparing to test a sovereign, open-source digital workplace that could reduce its long-term dependence on Microsoft 365 for sensitive government operations. The Swiss Federal Council was …
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned …
Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach
Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and current employees. The incident affected people employed by Natural Resources …
Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance
Microsoft will retire support for Manifest V2 browser extensions in Microsoft Edge by early 2027, requiring users, enterprises, and developers to move to Manifest V3. The transition is intended to …
ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps
ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. The issue impacts both cloud-hosted and on-premises ScreenConnect …
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
A new Linux bot called Tengu is built to stay hidden and turn compromised systems into tools for disruption. The 32-bit malware poses as a routine kernel worker, persists across …
OpenAI Commits $1 Billion to Give Critical Infrastructure Defenders Frontier AI Cyber Tools
OpenAI has launched Daybreak for Frontline Defenders, a global cybersecurity initiative designed to help organizations protecting essential services use frontier AI capabilities against increasingly advanced cyber threats. The company said …
