Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and current employees. The incident affected people employed by Natural Resources …
Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance
Microsoft will retire support for Manifest V2 browser extensions in Microsoft Edge by early 2027, requiring users, enterprises, and developers to move to Manifest V3. The transition is intended to …
ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps
ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. The issue impacts both cloud-hosted and on-premises ScreenConnect …
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
A new Linux bot called Tengu is built to stay hidden and turn compromised systems into tools for disruption. The 32-bit malware poses as a routine kernel worker, persists across …
OpenAI Commits $1 Billion to Give Critical Infrastructure Defenders Frontier AI Cyber Tools
OpenAI has launched Daybreak for Frontline Defenders, a global cybersecurity initiative designed to help organizations protecting essential services use frontier AI capabilities against increasingly advanced cyber threats. The company said …
LG Smart TVs Caught Scanning Networks and Logging Audio in Standby
Your LG smart TV may be doing far more than displaying your favorite shows while it sits “off” in the corner of your living room. A new investigation from Gamers …
New BYOTC Attack Hijacks Trusted Windows Apps to Abuse Privileged Kernel Drivers
A new Windows attack shows how a trusted program can become a path to sensitive system functions. The method, called Bring Your Own Trusted Caller, or BYOTC, turns a legitimate …
Kimsuky Hackers Use OpenCode AI Agent to Mass-Produce Phishing Decoys in LNK Attacks
Kimsuky has been observed using an AI agent to produce convincing phishing decoys at scale, then hiding malware inside Windows shortcut files. The latest activity shows how ordinary-looking documents can …
DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms
South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access. The malware hides inside software that manages web traffic, allowing attackers …
Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data …
