News

EU tightens cybersecurity rules for tech supply chains

EU tightens cybersecurity rules for tech supply chains 2026-01-21 at 17:24 By Anamarija Pogorelec The European Commission has proposed a new cybersecurity package aimed at strengthening the EU’s cyber resilience, including a revised EU Cybersecurity Act designed to secure ICT supply chains and ensure products reaching EU citizens are secure by design through a streamlined […]

EU tightens cybersecurity rules for tech supply chains Read More »

Rust package registry adds security tools and metrics to crates.io

Rust package registry adds security tools and metrics to crates.io 2026-01-21 at 15:23 By Anamarija Pogorelec The Rust project updated crates.io to include a Security tab on individual crate pages. The tab shows security advisories drawn from the RustSec database and lists which versions of a crate may have known issues. This change gives developers

Rust package registry adds security tools and metrics to crates.io Read More »

OpenAI adds age prediction to ChatGPT to strengthen teen safety

OpenAI adds age prediction to ChatGPT to strengthen teen safety 2026-01-21 at 15:05 By Sinisa Markovic OpenAI is rolling out age prediction on ChatGPT consumer plans to help determine whether an account likely belongs to someone under 18. Age prediction builds on protections already in place. ChatGPT relies on an age prediction model that evaluates

OpenAI adds age prediction to ChatGPT to strengthen teen safety Read More »

RansomHub claims alleged breach of Apple partner Luxshare

RansomHub claims alleged breach of Apple partner Luxshare 2026-01-21 at 14:34 By Zeljka Zorz Chinese electronic manufacturer and Apple partner Luxshare Precision Industry has allegedly been breached by affiliates of the RansomHub ransomware-as-a-service outfit. Luxshare is one of the primary assemblers of Apple’s wireless earbuds, iPhones, and Vision Pro devices, as well as a producer

RansomHub claims alleged breach of Apple partner Luxshare Read More »

Linux users targeted by crypto thieves via hijacked apps on Snap Store

Linux users targeted by crypto thieves via hijacked apps on Snap Store 2026-01-21 at 12:17 By Zeljka Zorz Cryptocurrency thieves have found a new way to turn trusted software packages for Linux on the Snap Store into crypto-stealing malware, Ubuntu contributor and former Canonical developer Alan Pope warned. SnapScope web app identifies malicious snaps (Source:

Linux users targeted by crypto thieves via hijacked apps on Snap Store Read More »

Pro-Russian hacktivist campaigns continue against UK organizations

Pro-Russian hacktivist campaigns continue against UK organizations 2026-01-21 at 12:00 By Sinisa Markovic The UK’s National Cyber Security Centre reports ongoing cyber operations by Russian-aligned hacktivist groups targeting organizations in the UK and abroad. NoName057(16) remains active In December 2025, the NCSC co signed an advisory warning that pro-Russian hacktivist groups were conducting cyber operations

Pro-Russian hacktivist campaigns continue against UK organizations Read More »

Cybercriminals speak the language young people trust

Cybercriminals speak the language young people trust 2026-01-21 at 08:30 By Sinisa Markovic Criminal groups actively recruit, train, and retain people in structured ways. They move fast, pay in crypto, and place no weight on age. Young people are dealing with a new kind of addiction. It isn’t drugs, alcohol, or gambling. It’s screens. Constant

Cybercriminals speak the language young people trust Read More »

Bandit: Open-source tool designed to find security issues in Python code

Bandit: Open-source tool designed to find security issues in Python code 2026-01-21 at 08:04 By Sinisa Markovic Bandit is an open-source tool that scans Python source code for security issues that show up in everyday development. Many security teams and developers use it as a quick way to spot risky coding patterns early in the

Bandit: Open-source tool designed to find security issues in Python code Read More »

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever 2026-01-21 at 07:34 By Help Net Security Penetration testing has evolved significantly over the past several years. While uncovering exploitable vulnerabilities remains the core goal, the real differentiator today is how findings are handled after the testing concludes. The method of reporting,

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever Read More »

Security leaders push for continuous controls as audits stay manual

Security leaders push for continuous controls as audits stay manual 2026-01-21 at 07:03 By Anamarija Pogorelec Security teams say they want real-time insight into controls, but still rely on periodic checks that trail daily operations. New RegScale research shows how wide that gap remains and where organizations are directing time, staff, and budget to manage

Security leaders push for continuous controls as audits stay manual Read More »

Initial access broker pleads guilty to selling access to 50 corporate networks

Initial access broker pleads guilty to selling access to 50 corporate networks 2026-01-20 at 15:43 By Zeljka Zorz A 40-year-old Jordanian man has admitted to selling unauthorized access to computer networks of at least 50 companies, the US Attorney’s Office of the District of New Jersey has announced. Feras Khalil Ahmad Albashiti has pleaded guilty

Initial access broker pleads guilty to selling access to 50 corporate networks Read More »

Let’s Encrypt rolls out 6-day and IP-based certificates

Let’s Encrypt rolls out 6-day and IP-based certificates 2026-01-20 at 12:25 By Anamarija Pogorelec Let’s Encrypt says its short-lived TLS certificates with a 6-day lifetime are now generally available. Each certificate is valid for 160 hours from the time it is issued. To request one, operators must select the “shortlived” profile in their ACME client.

Let’s Encrypt rolls out 6-day and IP-based certificates Read More »

Confusion and fear send people to Reddit for cybersecurity advice

Confusion and fear send people to Reddit for cybersecurity advice 2026-01-20 at 09:00 By Sinisa Markovic A strange charge appears on a bank account. An email claims a package is on the way. A social media account stops accepting a password that worked yesterday. When these moments hit, many people do the same thing. They

Confusion and fear send people to Reddit for cybersecurity advice Read More »

Product showcase: PrivacyHawk for iOS helps users track and remove personal data from data brokers

Product showcase: PrivacyHawk for iOS helps users track and remove personal data from data brokers 2026-01-20 at 08:06 By Anamarija Pogorelec Every interaction online, from signing up for a newsletter to making a purchase, leaves a trace. These traces are collected by data brokers and resold to advertisers, analytics firms, or, in some cases, criminals

Product showcase: PrivacyHawk for iOS helps users track and remove personal data from data brokers Read More »

Privacy teams feel the strain as AI, breaches, and budgets collide

Privacy teams feel the strain as AI, breaches, and budgets collide 2026-01-20 at 07:31 By Anamarija Pogorelec Privacy programs are under strain as organizations manage breach risk, new technology, and limited resources. A global study from ISACA shows that AI is gaining ground in privacy work, with use shaped by governance, funding, and how consistently

Privacy teams feel the strain as AI, breaches, and budgets collide Read More »

Cybersecurity jobs available right now: January 20, 2026

Cybersecurity jobs available right now: January 20, 2026 2026-01-20 at 07:23 By Anamarija Pogorelec Application Security Engineer xAI | USA | On-site – View job details As an Application Security Engineer, you will review and analyze code to identify vulnerabilities, define secure coding standards, and embed security practices into the CI/CD pipeline. You will perform

Cybersecurity jobs available right now: January 20, 2026 Read More »

Fake browser crash alerts turn Chrome extension into enterprise backdoor

Fake browser crash alerts turn Chrome extension into enterprise backdoor 2026-01-19 at 17:21 By Zeljka Zorz Browser extensions are a high-risk attack vector for enterprises, allowing threat actors to bypass traditional security controls and gain a foothold on corporate endpoints. Case in point: A recently identified malicious extension called NexShield proves that a single user

Fake browser crash alerts turn Chrome extension into enterprise backdoor Read More »

Law enforcement tracks ransomware group blamed for massive financial losses

Law enforcement tracks ransomware group blamed for massive financial losses 2026-01-19 at 14:00 By Sinisa Markovic Law enforcement agencies in Ukraine and Germany have identified two members of a Russian-affiliated ransomware group and carried out searches in western Ukraine. Search (Source: Cyber ​​Police of Ukraine) Investigators also named the alleged organizer, a Russian national, and

Law enforcement tracks ransomware group blamed for massive financial losses Read More »

British Army to spend £279 million on permanent cyber regiment base

British Army to spend £279 million on permanent cyber regiment base 2026-01-19 at 12:31 By Sinisa Markovic The British Army has announced a new permanent base for its cyber regiment, backed by £279 million in government spending. The plan centres on 13 Signal Regiment, the unit responsible for defending Army networks and supporting cyber operations.

British Army to spend £279 million on permanent cyber regiment base Read More »

Global tensions are pushing cyber activity toward dangerous territory

Global tensions are pushing cyber activity toward dangerous territory 2026-01-19 at 09:48 By Sinisa Markovic Cybersecurity is inseparable from geopolitics. Ongoing conflicts, sanctions, trade wars, geoeconomic rivalry, and technological competition have pushed state competition into cyberspace. States use cyber operations to exert pressure on rivals, enabling disruption without resorting to conventional weapons. Infrastructure vulnerabilities in

Global tensions are pushing cyber activity toward dangerous territory Read More »

Scroll to Top