11 Jun

ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day

Security University of Nottingham is first of many, Shiny tells The Reg Data theft and extortion group ShinyHunters claims to have exploited a critical Oracle

Author rabih
11 Jun

Microsoft’s worst ‘Nightmare’ unleashes BitLocker bypass 0-day

Security Another day, another Windows exploit code Nightmare Eclipse, the prolific zero-day vulnerability hunter with an axe to grind against Microsoft, released yet another exploit

Author rabih
11 Jun

2.4M+ VRChat users’ data accessed following cloud breach

security No disclosure via official channels, no offer of identity theft monitoring, no problem Online chat platform VRChat says a recent cyberattack compromised the data

Author rabih
11 Jun

OceanLotus: From external espionage to domestic targeting

Our tracking of OceanLotus activities from 2024–2026 reveals a shift in operational focus. During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to

Author rabih
11 Jun

OceanLotus: From external espionage to domestic targeting

Our tracking of OceanLotus activities from 2024–2026 reveals a shift in operational focus. During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to

Author rabih
11 Jun

Every employee’s password was stored in a single Excel file

SECURITY The CEO thought this was the best way to deal with some email issues PWNED Welcome, once again, to PWNED, the weekly screed where

Author rabih
11 Jun

Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate

Multiple reports indicate that Chinese operatives continue using every tech tool at their disposal – including American AI – to amass data on and manipulate everyone

Author rabih
10 Jun

Angry bug hunter with Microsoft beef drops new Windows 0-day

Security Revenge is a dish best served code They are angry at Redmond and will have their revenge. Nightmare Eclipse, the prolific bug hunter and

Author rabih
10 Jun

GitHub pulls pin on npm’s auto-run scripts

DevOPS Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors GitHub will change npm’s defaults so the install command

Author rabih
10 Jun

Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9

Patches Remote, unauthenticated RCE with root privileges is about as bad as it gets It’s patch time for Ivanti customers again after the security shop

Author rabih
10 Jun

SMB cyber-readiness: What makes or breaks it

“Fix the roof while the sun is shining.” – proverb Cybersecurity has a familiar way of saying the storm will come: “a breach is a

Author rabih
09 Jun

AI is making Patch Tuesday (kinda) fun again

Microsoft set a record with its June Patch Tuesday release, addressing 206 CVEs across its products and shipping fixes for them, with 38 deemed critical

Author rabih
09 Jun

Miasma worms its way onto GitHub as attack kit goes open source

cyber-crime As if there weren’t enough package poisonings to worry about As if the Miasma situation weren’t bad enough, now this weapon is spreading like

Author rabih
09 Jun

Apple’s iOS 27 goes all agentic on compromised passwords, promises to change them with one tap

personal tech iBiz might not win the AI race, but analysts say it’s focusing on features people may actually use Apple says that its next-gen

Author rabih
09 Jun

Signal says UK plan to scan devices for nude images ‘endangers us all’

Signal insists that plans to compel tech companies to scan devices for nude images of children announced by UK Prime Minister Keir Starmer on Monday

Author rabih
09 Jun

Chrome’s zero-day Whac-A-Mole continues with fifth exploited bug of the year

SECURITY Google paid researcher a tidy $55K bounty for its discovery Google has fixed its fifth actively exploited Chrome zero-day of 2026, and this one

Author rabih
09 Jun

France probes compromise of gov messaging platform after account hijack

security Authorities say the breach only exposed public chat rooms, but alleged attacker claims to have accessed far more data French officials are investigating a

Author rabih
09 Jun

Qilin NHS breach tally grows as Essex trust confirms stolen records

cyber-crime Two years on from ransomware attack, hospitals are still trying to identify and warn patients The patient tally from the Synnovis ransomware attack continues to

Author rabih
Load moreLoadingAll items loaded