Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
“This update resolves a critical
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.
The
OpenAI Agents Hijack Another Victim Website
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.
The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.
North Korean Hackers Deploy New Linux Espionage Toolkit
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek.
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The activity, which mainly singles out directors, vice presidents, and other executive staff
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
“Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences
Recent Comments