Software

Microsoft reportedly using TPM chips to weed out Windows piracy

Microsoft’s Trusted Platform Module, specifically TPM 2.0, has been part of Windows 11’s system requirements since the operating system’s introduction in 2021. Now that the TPM is ubiquitous, being included with most CPUs for many years, Microsoft is looking to leverage it “to activate Windows devices at scale.” Currently, the enterprise sector activates Windows via

Microsoft reportedly using TPM chips to weed out Windows piracy Read More »

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. For at least a third of them, researchers were able to find the correct password using dictionaries and the patterns on factory stickers for the default credentials. The exposed servers are vulnerable to

Over 24,000 exposed server BMCs leak password hash via decades-old flaw Read More »

Data breach at medical billing firm MCBS affects 1.26 million people

Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. The security incident was disclosed late last month without any details about the number of potentially affected individuals. In a disclosure to the U.S. Department of Health and Human Services,

Data breach at medical billing firm MCBS affects 1.26 million people Read More »

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets

Ernst & Young data breach claimed by ShinyHunters extortion gang Read More »

Shadow AI agents are multiplying. Here’s how to find and secure them.

Your workforce is building agents in Salesforce Agentforce, Microsoft Copilot Studio, Cursor, Zapier, Retool, and a dozen other tools, often without visibility or approval from IT or security. For IT and security teams, the decision of whether or not agents should be used has already been made by the business, one shadow agent at a

Shadow AI agents are multiplying. Here’s how to find and secure them. Read More »

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. The complaint, filed on July 24 in California, alleges that Apple failed to adequately review and monitor applications distributed through the App Store while promoting the

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin Read More »

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. Tracked as CVE-2026-54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates. “An authenticated attacker could manipulate attributes associated with a machine

New Certighost PoC exploit lets attackers hijack Windows domains Read More »

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot’ malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum

New Dysphoria DDoS botnet spreads to 200k devices worldwide Read More »