02 Jul

Ctrl+Alt+Oops: FortiBleed criminal’s logins stitch two gangs together

security Researchers scoured logs, finding opsec fail for at least one person who was working with INC and Lynx simultaneously Security sleuths say last month’s

Author rabih
02 Jul

Microsoft said exploitation was ‘less likely’ … but CISA just added SharePoint RCE to KEV list

security Attackers need little more than a valid SharePoint account to execute code on vulnerable on-prem servers Microsoft’s prediction that attackers probably wouldn’t rush to

Author rabih
02 Jul

Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data

security Company that also makes insulin pumps and other devices tells users what was exposed months after ShinyHunters attack Medical device giant Medtronic is warning patients that

Author rabih
02 Jul

India gives WhatsApp three days to defend username rollout amid security fears

Security Government of the messenger’s largest market demands a pause while Meta explains how it plans to stop impersonators India has asked WhatsApp to explain

Author rabih
02 Jul

Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released

cyber-crime Attackers appear to have reverse-engineered Big Red’s patch Attackers have been caught exploiting a critical flaw in Oracle E-Business Suite’s Payments module just six

Author rabih
02 Jul

Hackers shoveled snow for company, were rewarded with network admin access

Security Fortunately, they were professional red teamers. Unfortunately, they pwned the network PWNED Welcome back to PWNED, the column where we document serious security failures

Author rabih
01 Jul

EvilTokens device-code phishing kit totally more evil than we all thought

cyber-crime It’s a ‘complete BEC operations environment,’ Talos researcher says EvilTokens, the device-code phishing kit that can allow criminals to bypass multi-factor authentication (MFA) and

Author rabih
01 Jul

Claude Sonnet 5.0 heads straight down the middle of the road to dodge controversy

devops Safer, cheaper, and nothing to do with cybersecurity Anthropic has released the latest version of its mid-sized model, Sonnet 5, which the company claims

Author rabih
01 Jul

Somebody told DeepSeek to build in-browser ransomware and it gleefully complied

You can’t ask most models to help you make “ransomware” directly, but many will be more than willing if you give them the right prompt.

Author rabih
01 Jul

Red teamers turned Claude Desktop into a double agent to do their evil bidding

EXCLUSIVE Pentera Labs’ red teamers compromised a developer’s AI agent via his Claude Desktop app and ultimately turned that access into full remote code execution

Author rabih
30 Jun

Infosec professionals sour on automated pentesting tools

security 29% of security pros were open to fully autonomous pentesting last year; now only 9% are Perhaps bots aren’t the answer to everything when

Author rabih
30 Jun

Huntress CEO says threat hunter used ‘poor judgment’ in alerting ransomware crim about law enforcement probe

Security Ex-employee claims this ‘meets the definition of an insider threat’ Huntress CEO Kyle Hanslovan said he is aware of “questionable, long-term threat actor communications”

Author rabih
30 Jun

This month in security with Tony Anscombe – June 2026 edition

Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June

Author rabih
30 Jun

Verifiable Digital Credential Presentment

This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and

Author rabih
30 Jun

Microsoft builds a bouncer to keep bots out of Teams meetings

software Allows ISVs to put their names on the door so desirable bots always get in Microsoft has built a bouncer to keep bots out

Author rabih
30 Jun

India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info

security Open API leaked everything an attacker needs to impersonate bank officials In 2025, the Reserve Bank of India created the .bank.in subdomain and required

Author rabih
29 Jun

Security researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injection

AI + ML If you want a picture of the future of LLM security, imagine Whac-a-Mole meets Groundhog Day Researchers say that machine learning models

Author rabih
29 Jun

Four years into Ukraine invasion, Russia turns influence-ops back to US and Europe

Security Not today, Putin Four years into the Kremlin’s illegal invasion of its neighboring country, Russian influence operations have moved beyond their near-exclusive focus on

Author rabih
Load moreLoadingAll items loaded