Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
292 stories published
Hackers Hijack Hotel Wi-Fi DNS Settings to Steal Microsoft 365 Credentials
Threat actors are altering DNS configurations on hotel Wi-Fi networks to redirect guests to fake Microsoft 365 authentication pages.
Jul 24, 2026Certighost Exploit Enables Domain Controller Impersonation via Misconfigured AD CS
A working Active Directory exploit named Certighost allows low-privileged users to request Domain Controller certificates and perform DCSync attacks.
Jul 24, 2026Network Maintenance Automation Bug Triggers Widespread Microsoft 365 Outage
A logic flaw in Microsoft's automated network maintenance system inadvertently stripped IP routes, causing widespread Azure and Microsoft 365 downtime.
Jul 24, 2026ChatGPT AgentForger Vulnerability Allowed Rogue AI Agent Deployment
Zenity Labs discovered a critical vulnerability in OpenAI ChatGPT Workspace Agents that permitted stealth deployment of rogue autonomous agents via a link.
Jul 24, 2026Crafted SVGs in Bing Image Search Allow SYSTEM Command Execution
A critical vulnerability in Microsoft Bing's image processing tier allowed crafted SVG uploads to execute arbitrary commands as SYSTEM and root.
Jul 24, 2026Clop Ransomware Group Targets PTC Windchill and FlexPLM Software
The Clop ransomware group is targeting Internet-exposed PTC Windchill and FlexPLM servers in a data exfiltration and extortion campaign.
Jul 24, 2026NodeBB Patches Eight High-Severity Flaws Discovered by AI Agents
NodeBB released version 4.14.2 to fix eight high-severity vulnerabilities exposing admin privileges and private chats in versions prior to 4.14.0.
Jul 24, 2026Australian Energy Provider Origin Confirms Customer Data Breach
Origin Energy has confirmed a data breach after an unauthorized party accessed and leaked sensitive customer PII online.
Jul 23, 2026New Dolphin X Malware Uses AI to Profile and Rank High-Value Targets
The Dolphin X remote access trojan uses AI-powered victim profiling to score infected systems and prioritize targets for follow-on attacks.
Jul 23, 2026Bing Ads Malvertising Pushes Fake Claude Desktop App Delivering SectopRAT
Threat actors are abusing Bing search ads to distribute a fake Claude desktop app installer that drops the SectopRAT remote access trojan.
Jul 23, 2026Russian Hackers Exploit Zimbra Webmail Flaw to Steal Emails and 2FA Codes
Russian state-backed actors used a zero-click Zimbra webmail zero-day vulnerability to target Western organizations and siphon sensitive mailbox data.
Jul 23, 2026RefluxFS: Nine-Year-Old Linux Kernel Bug Grants Root Privileges
A newly discovered race condition in the Linux XFS filesystem driver, CVE-2026-64600, allows local attackers to elevate privileges to root.
Jul 23, 2026No news matches your search.