Latest stories — Page 4

Ransomware Group N0n Claims Attack on Houston Thyroid and Endocrine Specialists
A criminal group has listed a Houston endocrinology practice on its dark-web pressure site, claiming to hold patient records. The practice has not publicly confirmed any incident.

Kiteworks Told Customers to Go Dark for Nine Hours After a Federal Warning
Fewer than 50 organisations use the affected feature. No breach has been confirmed. But the feds thought the risk serious enough to pick up the phone.

Fake Meeting Invites Are Now Delivering Real Remote-Control Software
Microsoft says attackers are skipping the malware and installing legitimate MSP360 and ScreenConnect on victim machines, giving themselves a hands-on-keyboard foothold that looks like normal IT admin work.

Zimbra mail server flaw exploited in the wild, Microsoft warns after weeks of quiet attacks
Microsoft Threat Intelligence says attackers used a specially crafted email to hijack Zimbra Collaboration Suite mail servers, drop web shells and steal mailbox data, before the flaw was patched.

OpenSSL Ships a Pile of Fixes, and a DTLS Bug That Can Spill Memory to the Wrong Side of the Wire
A dozen CVEs land in Ubuntu and Debian's OpenSSL packages at once. The one worth reading first is a DTLS handshake bug that can leak heap memory across a connection.

Apple Patches Actively Exploited Zero-Day Tied to WhatsApp Attack Chain
A graphics-processing flaw in iOS and macOS is being used in what Apple calls an 'extremely sophisticated' targeted attack. CISA gave US federal agencies three days to fix it.

Browsing a Model Was Enough. The 'trust_remote_code' Flaw That Won't Go Away
A bug in Unsloth Studio ran malicious code before a model ever loaded. It's the fourth time this year the same one-line AI setting has opened the door.

Cloudflare Is Building Its Own Certificate Authority to Harden the Web Against Quantum Computers
The internet infrastructure giant wants to issue its own digital trust certificates, buying a head start from GlobalSign and promising post-quantum protection before most of the web even knows it needs it.

Linux patches two Spectre-style flaws in the kernel's BPF engine
Kernel maintainers shipped fixes for CVE-2026-64507 and CVE-2026-64508 after researchers showed old branch predictions could leak data from new code.

How one password reset gave hackers the keys to a company's cloud
Microsoft's incident response team says a group it tracks as Storm-3068 walked from a single user account into Azure DevOps, build pipelines and Kubernetes clusters without deploying any malware.

NeedyMantis: The Hidden Malware That Moves In After the Break-In
Microsoft has named a previously unknown malware family being used against telecoms, universities, and government contractors. The group behind it is linked to China. And once it's inside a network, it's built to stay quiet.

Russia's Star Blizzard drops the ClickFix act and switches to one-click RedFlick malware
Microsoft says the FSB-linked crew has scaled up its phishing and streamlined how it plants its CosmicPulse backdoor. More than 100 organisations in the US and UK have been hit this year.

A flaw in the official MCP Python SDK let hostile servers walk off with OAuth logins
Applications built on Anthropic's Model Context Protocol client library could be tricked into sending real service credentials to an attacker-controlled endpoint. The fix is in version 1.30.0.

Who Is Running Up Your AI Bill at 3am
Security researchers have mapped an ecosystem of more than 80,000 proxy servers quietly routing stolen AI credentials to frontier models, and companies are footing bills they never ran up.

Ransomware Group The Gentlemen Claims Attack on German Secure-File Firm FTAPI Software
A criminal gang that has posted dozens of claimed victims in recent months has listed FTAPI Software on its dark-web extortion site. The Munich company serves hospitals, insurers and public agencies across Europe. Nothing has been confirmed.

Two Critical Check Point Flaws Are Being Actively Exploited and Federal Agencies Had Three Days to Patch
CISA added both vulnerabilities to its must-patch list on September 22, with a September 25 deadline for US government networks. One was a zero-day. The other had already been quietly targeted in the wild.

Ransomware Group The Gentlemen Claims Attack on Leeds Glass Firm Crystal Glass
A family-run glazing company in West Yorkshire has been listed on a dark-web extortion page by The Gentlemen ransomware group. The firm has not confirmed any incident, and the claim is unverified.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

INC Ransom Claims Attack on Alaska School District Serving Remote Arctic Communities
The criminal group INC Ransom has listed North Slope Borough School District on its dark-web pressure site. The district has not confirmed any incident, and the claim has not been independently verified.

ShinyHunters Claims FBI Hack Exploiting Oracle Flaw
The cybercrime group says it breached FBI systems using a critical Oracle software vulnerability. The FBI is investigating the claim.

Six Critical Flaws in Adobe Connect Could Let Attackers Take Over Accounts
Two of the worst bugs require no action from the victim. Adobe wants patches applied within 30 days, but one score of 9.9 makes that window feel generous.