Dark Reading
A data-theft operation known as the “City-Forum” campaign has been active since at least March 2025, according to available reporting. The campaign has focused on organizations in multiple sectors and...
12 Aug 20261 min read
Read article →BleepingComputer
Cybercriminals are combining the SpyNote Android remote-access trojan with a newer NFC relay malware, WindRelay, to take control of victims’ phones, apply for loans, and use payment cards in fraudulen...
12 Aug 20262 min read
Read article →SecurityWeek
A vulnerability in Microsoft SharePoint that was patched in July is now being targeted in the wild, according to threat intelligence monitoring conducted after a public proof-of-concept exploit was re...
12 Aug 20262 min read
Read article →The Register - Security
Signal has introduced Automatic Key Verification (AKV), a feature designed to help users detect attempts to redirect encrypted conversations to an impostor. The update strengthens the app’s existing s...
11 Aug 20262 min read
Read article →Krebs on Security
Microsoft’s August security update addresses 398 vulnerabilities across Windows and supported software, including one flaw that the company says is being actively exploited. The release also covers tw...
11 Aug 20262 min read
Read article →NCSC (UK)
The UK National Cyber Security Centre (NCSC) has released a fictional worked example showing how organisations can apply its Secure Connectivity Principles for Operational Technology. The scenario fol...
11 Aug 20262 min read
Read article →The Hacker News
Artificial intelligence is enabling development teams to produce software at a much higher volume and speed, but security processes may not be scaling at the same rate. A new webinar, The True Cost of...
10 Aug 20262 min read
Read article →Dark Reading
New research describes a technique dubbed “GhostJacking,” in which attackers may exploit security alerts and blocked events to influence the behavior of AI agents. The findings point to weaknesses in...
10 Aug 20262 min read
Read article →BleepingComputer
A compromise of infrastructure used by WordPress developer BdThemes allowed attackers to tamper with a remote data feed and target administrator sessions on websites using the company’s plugins.Securi...
10 Aug 20262 min read
Read article →SecurityWeek
A series of smaller cybersecurity developments this week highlighted risks spanning artificial intelligence abuse, software supply chains, cloud data exposure and targeted social engineering.AI misuse...
9 Aug 20262 min read
Read article →The Register - Security
Ransomware groups are increasingly selecting victims based on their influence over business decisions rather than targeting only senior executives or system administrators, according to research from...
9 Aug 20262 min read
Read article →The Hacker News
Security researchers have identified two attack paths that could cause Atlassian’s Rovo AI assistant to send data accessible to a signed-in user to an attacker-controlled server. The findings were rep...
9 Aug 20262 min read
Read article →