Software

Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform. Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote […]

Ubiquiti patches three max severity security vulnerabilities Read More »

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Like cloud-hosted GitHub or GitLab SaaS (Software as a Service) platforms, Gitea provides a full suite of DevOps tools, but it is designed to be used as a self-hosted software development platform.

Hackers now exploit critical Gitea flaw in code injection attacks Read More »

Chrome’s ad-blocking champion gets one last update before the curtain falls

Affiliate links on Android Authority may earn us a commission. Learn more. For many Chrome users, uBlock Origin (uBO) has long been one of those essential browser extensions, quietly sitting in the toolbar and blocking ads without much fuss. But Google’s long-running Manifest V2 crackdown has steadily changed that, and the uBlock Origin team has

Chrome’s ad-blocking champion gets one last update before the curtain falls Read More »

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised. At the time,

LACMA data breach last year exposed social security and medical data Read More »

WhatsApp adds stronger two-step verification, multiple passkeys

WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. While the instant messaging service already allowed users to add passkeys for secure logins via fingerprint, Face ID, or screen lock code, it now lets them create separate ones for each platform. “More than a billion

WhatsApp adds stronger two-step verification, multiple passkeys Read More »

Hackers breached over 270 Zimbra servers in ongoing attacks

Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as

Hackers breached over 270 Zimbra servers in ongoing attacks Read More »

Police arrests dozens of suspects in global cybercrime crackdown

Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. The “Operation Jackal IV” international joint action targeted West African criminal networks between November 2025 and June 2026. The operation also focused on disrupting the Black Axe cybercrime syndicate, known for its

Police arrests dozens of suspects in global cybercrime crackdown Read More »

South Korean startup platform breach exposes key management failures

In July, South Korea’s government-backed startup support platform, Modu-ui Changup (모두의창업), suffered a data breach. The incident later revealed a critical encryption key management failure, demonstrating how encrypted data can still become exposed when organizations fail to protect encryption keys properly. The platform supports a nationwide startup audition program overseen by South Korea’s Ministry of

South Korean startup platform breach exposes key management failures Read More »

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. This new feature builds on another Teams policy introduced in June that added smarter bot protection, ensuring all detected bots are tagged in the lobby and require organizer approval before joining.

Microsoft Teams now lets admins block external bots from meetings Read More »

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. In a statement over the weekend, ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing “a fake ReliaQuest single sign-on (SSO) page behind

ReliaQuest confirms failed data-theft attack after ShinyHunters breach Read More »