Hackers compromise 5,000 Dropbox accounts using Lenovo ID flaw
The breach, which occurred between August 4 and August 21, allowed attackers to access Dropbox accounts by registering Lenovo IDs with the victims' email add...
20 articles
The breach, which occurred between August 4 and August 21, allowed attackers to access Dropbox accounts by registering Lenovo IDs with the victims' email add...
CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Run...
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [.
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather t...
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The po...
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US
Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S.
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be p...
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This c...
Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify con...
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerabili...
Researchers built a fake company to study fake employee scams.
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from HTML ...
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [.
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a f...
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPre...
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations acr...