Software

Android malware combo takes out loans and relays victims’ credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time. In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem […]

Android malware combo takes out loans and relays victims’ credit cards Read More »

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. The data-theft campaign, dubbed City-Forum by SaaS security firm Reco, has been traced to a single server that has targeted multiple organizations worldwide. These organizations include telecommunications companies, banks and financial services

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals Read More »

Hackers leverage new Microsoft SharePoint exploit in attacks

A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks. Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. Microsoft

Hackers leverage new Microsoft SharePoint exploit in attacks Read More »

Welcome to the internet in 2026, where AI agents are both victim and attacker in malware wars

It might feel like an eternity that we’ve been living in this AI era, but really we’re only at its advent. As such, many of the risks associated with it have until now been merely hypothetical. However, we’re now seeing research filter out from security and software research teams that show some genuinely concerning behaviour,

Welcome to the internet in 2026, where AI agents are both victim and attacker in malware wars Read More »

Signal adds new security feature to thwart man-in-the-middle attacks

Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven’t been intercepted. The new feature is part of a “key transparency” system that uses Cloudflare and Trail of Bits as trusted third-party independent auditors to verify the integrity of Signal conversations. “It works

Signal adds new security feature to thwart man-in-the-middle attacks Read More »

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldBreak” after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. As Nightmare Eclipse

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges Read More »

Here’s how Chrome is quietly tackling annoying website notification spam

Affiliate links on Android Authority may earn us a commission. Learn more. Website notifications can be useful, but it’s easy for a single “Allow” tap to turn into a steady stream of unwanted alerts. According to Google, Chrome has significantly reduced that abuse through a combination of protections that can block problematic sites and limit

Here’s how Chrome is quietly tackling annoying website notification spam Read More »

Wesco confirms security incident after ExfilSquad claims data theft

Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident. The company’s statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site. Jennifer Sniderman, Vice President of Corporate Communications at Wesco,

Wesco confirms security incident after ExfilSquad claims data theft Read More »

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has released Windows 11 KB512103 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. Today’s updates are mandatory as they contain the August 2026 Patch Tuesday security patches for 400 vulnerabilities discovered in previous months. You can install today’s update by going to Start >

Windows 11 KB5121003 & KB5120240 cumulative updates released Read More »

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 “Critical” vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege. The approximate number of bugs in each vulnerability

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days Read More »