Latest SecOps News

Get this as an RSS feed

  • 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 (4 hours ago)
  • New SynkLoader malware pushed in Microsoft Teams phishing campaign (5 hours ago)
  • Homeland security cybercops say patch TrueConf (Russia’s Zoom) if you’re using it (6 hours ago)
  • Former NSA Director Paul Nakasone Launches National Security Advisory Firm (6 hours ago)
  • Hundreds of leaked AWS keys give full control over corporate accounts (7 hours ago)
  • Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot (7 hours ago)
  • Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet (7 hours ago)
  • In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug (7 hours ago)
  • Hackers poison popular Rust crates to steal developers’ credentials (8 hours ago)
  • Microsoft blames Windows gaming issues on RGB lighting devices (8 hours ago)
  • CNCMachineRMS C2 Protocol (8 hours ago)
  • Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini (8 hours ago)
  • New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets (8 hours ago)
  • Is Online Privacy Possible? How Digital Identities Can Help (9 hours ago)
  • Introducing dbsc.dev: Does Your Browser Support DBSC? (9 hours ago)
  • Microsoft rolls out Classic Outlook theme for New Outlook users (9 hours ago)
  • Critical Isolated-vm Vulnerability Leads to RCE on Host (10 hours ago)
  • CISA orders feds to patch actively exploited TrueConf Server flaws (10 hours ago)
  • AI Agents: Rogue Actors or Your New Workforce? (11 hours ago)
  • Wazuh and AI For Enhanced SOC Workflows (11 hours ago)
  • Microsoft lets you swap New Outlook’s looks with the face of Outlook Classic (11 hours ago)
  • Microsoft warns of max severity Entra ID flaw exploited in attacks (11 hours ago)
  • Hackers abuse FTP server banners to deliver new Windows malware (12 hours ago)
  • SickKids data breach exposes employee and job applicant info (12 hours ago)
  • Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 (13 hours ago)
  • Rust Supply Chain Attack Linked to North Korean Hackers (13 hours ago)
  • Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind (14 hours ago)
  • Microsoft Patches Exploited Entra ID Vulnerability (14 hours ago)
  • CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities (15 hours ago)
  • GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure (15 hours ago)
  • Developer given Mission:Impossible - fixing rubbish code that could crash a city - simply chose not to accept it (16 hours ago)
  • Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution (16 hours ago)
  • Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. (17 hours ago)
  • Intermittent failures creating agent tasks (22 hours ago)
  • Russian snoops add OAuth abuse to targeted phishing campaigns (22 hours ago)
  • Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads (1 days ago)
  • Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts (1 days ago)
  • Hackers poison arrayref Rust crate to push infostealer malware (1 days ago)
  • US Bank investigates LockBit’s claims as ransomware crims set pay-or-leak deadline (1 days ago)
  • ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More (1 days ago)
  • AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure (1 days ago)
  • Researcher tricks Apple’s Find My into sharing location data with Linux (1 days ago)
  • Slack Code taps into collective vibe, puts AI agents into the group chat (1 days ago)
  • Thunderbird to flap twice as fast from September (1 days ago)
  • Hackers Target Zimbra Servers in Active Exploitation Campaign (1 days ago)
  • Critical Elementor Pro bug exposes WordPress sites to RCE attacks (1 days ago)
  • New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data (1 days ago)
  • Ransomware crook poses as recovery firm to steal payments from fellow extortionists (1 days ago)
  • How MSPs can catch phishing attacks email filters miss (1 days ago)
  • Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE (1 days ago)
  • Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers (1 days ago)
  • Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution (1 days ago)
  • Grok chat duped into swallowing injected instructions (1 days ago)
  • French tax authority says break-in exposed data of 600K, including some private messages (1 days ago)
  • Citrix urges admins to patch new NetScaler flaws as soon as possible (1 days ago)
  • Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments (1 days ago)
  • Why “Shady AI” is Security’s Next Big Governance Problem (1 days ago)
  • CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification (1 days ago)
  • Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices (1 days ago)
  • CISA warns of hackers exploiting critical MLflow vulnerability (1 days ago)
  • NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands (1 days ago)
  • ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud (1 days ago)
  • New Manic Android malware can exfiltrate data through nearby devices (1 days ago)
  • 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets (1 days ago)
  • AI agent suggested installing a malware package. Engineer almost took its advice (1 days ago)
  • [0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8) (1 days ago)
  • [0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8) (1 days ago)
  • [0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8) (1 days ago)
  • [0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8) (1 days ago)
  • [0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8) (1 days ago)
  • [0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8) (1 days ago)
  • [0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8) (1 days ago)
  • APPLE-SA-08-18-2026-1 Safari 26.6.1 (1 days ago)
  • Cudy WR3000: Hard-coded JWT Secret to Root Command Injection (1 days ago)
  • Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code (1 days ago)
  • Smashing Security podcast #481: Never say this to a robot dog (1 days ago)
  • ‘Not a theoretical risk,’ feds warn as attackers use AI-made code to hack critical infrastructure controllers (2 days ago)
  • Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second (2 days ago)
  • ICE boss to agents: Leave the Meta spy glasses at home (2 days ago)
  • OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior (2 days ago)
  • Flock surveillance backlash mounts as fiendish Halloween plans circulate (2 days ago)
  • Comcast gives its Wi-Fi motion detector a security makeover (2 days ago)
  • SAP consultant job ads overshoot final offers by up to 12%, recruiter claims (2 days ago)
  • Prison for data analyst who tried to extort $2.5 million from his employer (2 days ago)
  • Oz Hair and Beauty - 1,988,331 breached accounts (2 days ago)
  • Australian hotel chain leaks guests’ PII after breach at third-party database operator (2 days ago)
  • Fanlore - 144,520 breached accounts (2 days ago)
  • OpenAI’s overhead will rise 20 percent for some workloads as it hardens security (2 days ago)
  • Expired credit cards revived by researchers to make unauthorized payments (3 days ago)
  • CISA gives feds 3 days to fix actively exploited Ray RCE bug (3 days ago)
  • Apple plugs image-processing hole ripe for spyware abuse (3 days ago)
  • Tim King, AmigaDOS royalty, dies aged 70 (3 days ago)
  • Copilot tricked into telling reseachers how to hack itself (3 days ago)
  • Government Teams users face another *** month of filtered captions (3 days ago)
  • Intermittent failures in runner group and runner-related permissions pages (3 days ago)
  • Sponsor gives KDE Plasma 6.6 the LTS treatment (3 days ago)
  • Incident with Actions (3 days ago)
  • Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc) (3 days ago)
  • Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer) (3 days ago)
  • Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x ( - = 2.0.63) (Srimax Software (Output Technology)) (3 days ago)
  • Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision) (3 days ago)
  • Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper) (3 days ago)
  • Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software) (3 days ago)
  • Microsoft MVP creates site to remind you of all the brands Redmond replaced (3 days ago)
  • Weekly Update 517: Cyber Ransoms (3 days ago)
  • Xen Project gets serious about safety in push to possibly partition robot brains (3 days ago)
  • Incident with GitHub.com (4 days ago)
  • Mozilla adds ad blocking to Firefox for iOS (4 days ago)
  • An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras (4 days ago)
  • Crook hawks millions of records allegedly plundered from corporate Azure tenants (4 days ago)
  • Excel’s Copilot function is headed for the Recycle Bin (4 days ago)
  • Code fixers have fired up the AI warp drive. Strange new worlds await (4 days ago)
  • Black Hat and DEF CON are AI conferences now, too (4 days ago)
  • Microsoft blames AI for delayed Exchange update, can’t say when it will arrive (4 days ago)
  • Microsoft blames AI for delayed Exchange update, can’t say when it will arrive (4 days ago)
  • Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI (4 days ago)
  • Who’s Tracking You? Use This New Service to Find Out (7 days ago)
  • Five years after quitting a job, developer’s former boss asked for rapid tech support (7 days ago)
  • Give Google the boot by building your own search engine (8 days ago)
  • Disruption with GHEC Team Sync (8 days ago)
  • Errors with the Fable 5 Model in Copilot (8 days ago)
  • Incident with Webhooks (8 days ago)
  • RingCentral - 1,596,490 breached accounts (8 days ago)
  • Smashing Security podcast #480: This is the AI service you should never sign up to (8 days ago)
  • Disruption with Login and Release Asset downloads (9 days ago)
  • Deeply buried 16-year-old SQLite bug caused last year’s Tailscale outages (9 days ago)
  • OpenWALDO aims to blow the doors off proprietary AI training models (9 days ago)
  • Incident with Pull Requests and Issues (9 days ago)
  • Weekly Update 516: Live From Vietnam (9 days ago)
  • Microsoft Plugs Nearly 400 Security Holes (10 days ago)
  • Incident with GraphQL API Requests (10 days ago)
  • Device Bound Session Credentials lands in Chrome on macOS (10 days ago)
  • GRC Solutions Partners with Defense.com™ to Help Businesses Take Control of Cyber Risk (10 days ago)
  • Disruption with Copilot for access to some models (11 days ago)
  • Hey, big spender – OpenAI has a new SKU just for you (11 days ago)
  • Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres (11 days ago)
  • Disruption with creation of fine grained personal access tokens (11 days ago)
  • Everything I Learned Shipping Device Bound Session Credentials (11 days ago)
  • Demoralized developer’s desperate hack came back to haunt him on LinkedIn (11 days ago)
  • NEC tests parking tech that only starts charging once you exit your car (11 days ago)
  • KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts (12 days ago)
  • Ransomware gangs skip the CEO, head straight for the 40-something IT manager (12 days ago)
  • Alcon - 218,395 breached accounts (12 days ago)
  • City of Suisun declares local emergency after cyberattack downs 911 dispatch system (12 days ago)
  • City of Coweta refuses to pay ransom after system-wide cyberattack (13 days ago)
  • Brinks Home - 732,162 breached accounts (13 days ago)
  • US cloud ‘kill switch’ is as dangerous as ransomware, European businesses fear (13 days ago)
  • New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. (14 days ago)
  • City of Coweta hit with system-wide ransomware attack, has backup (14 days ago)
  • Boston Children’s Hospital named in North Korean hacking operation (14 days ago)
  • Beware cut-price AI services that read your every word (14 days ago)
  • AU: Hackers leak sensitive Victorian court data to dark web (14 days ago)
  • What Canvas learned from a massive cyberattack (14 days ago)
  • Sysadmin summoned to explain italics – to a user with at least two degrees (14 days ago)
  • Exact Sciences - 10,869,543 breached accounts (14 days ago)
  • Incident with Actions (14 days ago)
  • What’s the Difference Between Automated Vulnerability Scanning and Penetration Testing? (15 days ago)
  • Latest GitHub outage squeezes Actions, Pages to death (15 days ago)
  • Canadian Man Pleads Guilty in Snowflake Extortions (15 days ago)
  • Humans in the loop miss a third of dangerous AI coding agent requests (15 days ago)
  • Incident with Pages - Deployment Lag (15 days ago)
  • Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits (15 days ago)
  • Inter-Con Security - 276,114 breached accounts (15 days ago)
  • Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency (15 days ago)
  • Some Copilot Cloud Agent jobs not starting (16 days ago)
  • Fake IRS letters target cryptocurrency holders (17 days ago)
  • UK mulls making employers ask before installing bossware (17 days ago)
  • Incident with Copilot (18 days ago)
  • Welcoming the Nepalese Government to Have I Been Pwned (18 days ago)
  • Weekly Update 515: Seeking Caffeine Utopia (18 days ago)
  • Incident with Copilot AI Model Providers (20 days ago)
  • Degraded availability GPT 5.6 Luna (20 days ago)
  • SplitVPN - 865,336 breached accounts (20 days ago)
  • Update Teams mobile app by October or lose your calendar (21 days ago)
  • The $5 million threat: AI Is supercharging phishing attacks (21 days ago)
  • Read This Before You Buy That TV Streaming Stick (22 days ago)
  • Copilot model Claude Fable 5 experiencing elevated errors (22 days ago)
  • North Korea’s elite hackers turned on their own government – and got caught (22 days ago)
  • Smashing Security podcast #478: This job interview could destroy your company (22 days ago)
  • Incident with Copilot AI Model Providers (23 days ago)
  • Incident with Actions (23 days ago)
  • Houston City College - 831,642 breached accounts (24 days ago)
  • PureLogs, PureRAT and misleading zgRAT (25 days ago)
  • Incident with GraphQL API Requests (25 days ago)
  • Weekly Update 514: This Week in Data Breaches (26 days ago)
  • Actions run failures and delays (27 days ago)
  • Several GPT models degraded (27 days ago)
  • Incident with Actions (27 days ago)
  • OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know (29 days ago)
  • Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker (29 days ago)