News

Windows memory integrity switches on automatically for eligible devices in October 2026

Windows memory integrity switches on automatically for eligible devices in October 2026 2026-09-03 at 07:30 By Anamarija Pogorelec Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory […]

Windows memory integrity switches on automatically for eligible devices in October 2026 Read More »

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 2026-09-02 at 16:24 By Sinisa Markovic Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) Read More »

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 2026-09-02 at 15:42 By Zeljka Zorz A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Read More »

Attackers are going after prominent individuals through OAuth phishing, FBI warns

Attackers are going after prominent individuals through OAuth phishing, FBI warns 2026-09-02 at 13:58 By Sinisa Markovic Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses

Attackers are going after prominent individuals through OAuth phishing, FBI warns Read More »

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 at 13:13 By Zeljka Zorz Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built

SonicWall SMA 1000 appliances under attack via zero-day flaws Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

Global sinkhole operation ends Sality botnet’s 23-year run

Global sinkhole operation ends Sality botnet’s 23-year run 2026-09-02 at 11:56 By Sinisa Markovic Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation

Global sinkhole operation ends Sality botnet’s 23-year run Read More »

DuckDB stays open source while the team behind it goes to work for Amazon

DuckDB stays open source while the team behind it goes to work for Amazon 2026-09-02 at 09:29 By Anamarija Pogorelec Hannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on

DuckDB stays open source while the team behind it goes to work for Amazon Read More »

National Life Group CISO expects more vulnerabilities in six months than in thirty years

National Life Group CISO expects more vulnerabilities in six months than in thirty years 2026-09-02 at 09:00 By Mirko Zorz In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot

National Life Group CISO expects more vulnerabilities in six months than in thirty years Read More »

Scareware ads keep running on Google’s transparency tool, even after they’re reported

Scareware ads keep running on Google’s transparency tool, even after they’re reported 2026-09-02 at 08:30 By Mirko Zorz A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to

Scareware ads keep running on Google’s transparency tool, even after they’re reported Read More »

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira 2026-09-02 at 08:00 By Mirko Zorz Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain,

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira Read More »

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud 2026-09-02 at 07:30 By Anamarija Pogorelec Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud Read More »

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of

CISA review makes the case for eliminating vulnerability classes Read More »

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks 2026-09-01 at 17:07 By Sinisa Markovic A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks Read More »

Fake Claude Opus 5 app delivers malware and wipes its own tracks

Fake Claude Opus 5 app delivers malware and wipes its own tracks 2026-09-01 at 15:21 By Sinisa Markovic A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using

Fake Claude Opus 5 app delivers malware and wipes its own tracks Read More »

Berlin refuses to be blackmailed after network breach

Berlin refuses to be blackmailed after network breach 2026-09-01 at 12:07 By Sinisa Markovic Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an emergency Senate session at the Rotes

Berlin refuses to be blackmailed after network breach Read More »

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers 2026-09-01 at 08:30 By Mirko Zorz Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup,

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers Read More »

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes 2026-09-01 at 08:04 By Anamarija Pogorelec Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes Read More »

Scroll to Top