Software

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. This […]

CISA: WatchGuard RCE flaw now exploited in ransomware attacks Read More »

Trezor warns users of email provider breach, phishing attacks

Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Affected customers received fake “critical security alert” emails from help@trezor.io claiming that a “hardware microcontroller vulnerability” in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to

Trezor warns users of email provider breach, phishing attacks Read More »

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults

Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. The new Windows Age API uses information associated with a Microsoft account and can return age ranges such as under 10, 10-12, 13-15, 16-17, and

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults Read More »

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The company began rolling out patched versions to Windows (153.0.8010.36),

Google warns of new Chrome zero-day bug exploited in attacks Read More »

New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in

New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access Read More »

Man gets 15 years for extorting women with AI-generated porn videos

An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims via phone calls, voicemails, text messages, and online posts. When he was arrested on federal charges on June 23, 2025, 37-year-old James Strahler II was also charged with anonymous telecommunications harassment and child pornography production

Man gets 15 years for extorting women with AI-generated porn videos Read More »

Over 36,000 exposed Plex servers vulnerable to recent flaws

Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn’t provide additional details on Tuesday when it issued the warning,

Over 36,000 exposed Plex servers vulnerable to recent flaws Read More »

MFA’s Weakest Link: Account Recovery Is the New Attack Path

For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems. However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the

MFA’s Weakest Link: Account Recovery Is the New Attack Path Read More »

US says Chinese firms extracted billions of tokens from frontier AI models

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. A joint advisory from CISA, NSA, and the FBI states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI

US says Chinese firms extracted billions of tokens from frontier AI models Read More »

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical

Veradigm warns of patient data breach after ransomware gang claims attack Read More »