News

SolarWinds Serv-U hit by four critical RCE-level vulnerabilities

SolarWinds Serv-U hit by four critical RCE-level vulnerabilities 2026-02-25 at 13:55 By Zeljka Zorz SolarWinds has fixed four critical vulnerabilities in its popular Serv-U file transfer solution, which is used by businesses and organizations of all sizes. If exploited, the flaws may allow attackers to create a system admin user and/or execute code as a […]

SolarWinds Serv-U hit by four critical RCE-level vulnerabilities Read More »

Reddit fined $19.5 million for failing to protect children’s personal data

Reddit fined $19.5 million for failing to protect children’s personal data 2026-02-25 at 13:38 By Anamarija Pogorelec The UK’s Information Commissioner’s Office (ICO) has fined Reddit $19.5 million after finding that the company failed to use children’s personal information lawfully, exposing them to inappropriate and harmful content. The investigation found that Reddit did not apply […]

Reddit fined $19.5 million for failing to protect children’s personal data Read More »

Ex-L3Harris executive sentenced to 87 months for selling stolen cyber-exploit trade secrets

Ex-L3Harris executive sentenced to 87 months for selling stolen cyber-exploit trade secrets 2026-02-25 at 12:15 By Sinisa Markovic Peter Williams, a former executive of Trenchant, L3Harris’ cyber division, has been sentenced to 87 months in prison by a federal judge in Washington, D.C., after pleading guilty to stealing and selling sensitive cyber-exploit trade secrets to […]

Ex-L3Harris executive sentenced to 87 months for selling stolen cyber-exploit trade secrets Read More »

CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108)

CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) 2026-02-25 at 12:14 By Zeljka Zorz CISA has added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems’ FileZen secure file transfer solution, to its Known Exploited Vulnerabilities (KEV) catalog. The vendor has confirmed active exploitation, stating it has received multiple reports of damage caused […]

CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) Read More »

Cyber valuations climb as capital concentrates, AI security expands

Cyber valuations climb as capital concentrates, AI security expands 2026-02-25 at 08:59 By Sinisa Markovic Venture funding in cybersecurity continued to concentrate in large private rounds at the end of 2025, driving valuations higher across stages. Data from DataTribe shows total capital invested approached $150 billion for the year, with a disproportionate share flowing into […]

Cyber valuations climb as capital concentrates, AI security expands Read More »

Microsoft adds domain libraries and Copilot integration to the quantum development kit

Microsoft adds domain libraries and Copilot integration to the quantum development kit 2026-02-25 at 08:05 By Anamarija Pogorelec The Microsoft Quantum Development Kit (QDK) is an open-source toolkit that runs on laptops and in common development environments. It includes code, simulators, libraries, and workflows that work with Visual Studio Code and GitHub Copilot. Integration with […]

Microsoft adds domain libraries and Copilot integration to the quantum development kit Read More »

Airline brands become launchpads for phishing, crypto fraud

Airline brands become launchpads for phishing, crypto fraud 2026-02-25 at 08:05 By Sinisa Markovic Airline brands sit at the center of peak travel booking cycles, loyalty programs, and high value transactions. Criminal groups continue to register thousands of lookalike domains tied to these brands, targeting travelers, employees, and business partners. Recent threat intelligence from BforeAI’s […]

Airline brands become launchpads for phishing, crypto fraud Read More »

Edge systems take the brunt of internet-wide exploitation attempts

Edge systems take the brunt of internet-wide exploitation attempts 2026-02-25 at 07:18 By Anamarija Pogorelec Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across […]

Edge systems take the brunt of internet-wide exploitation attempts Read More »

Teenagers charged over public bike service breach that exposed 4.62 million records

Teenagers charged over public bike service breach that exposed 4.62 million records 2026-02-24 at 17:06 By Sinisa Markovic Two South Korean teenagers have been charged in connection with a cyberattack that compromised the personal data of 4.62 million users of Seoul’s public bike service, Ttareungyi. The compromised data included user IDs, mobile phone numbers, addresses, […]

Teenagers charged over public bike service breach that exposed 4.62 million records Read More »

Microsoft expands Sovereign Cloud security with governance, local productivity and AI

Microsoft expands Sovereign Cloud security with governance, local productivity and AI 2026-02-24 at 15:26 By Anamarija Pogorelec Microsoft expands Microsoft Sovereign Cloud with new disconnected and AI capabilities that help organizations run critical infrastructure, productivity services and large AI models inside sovereign boundaries while keeping governance and operational continuity across connected and disconnected environments. Sovereign […]

Microsoft expands Sovereign Cloud security with governance, local productivity and AI Read More »

Self-spreading npm malware targets developers in new supply chain attack

Self-spreading npm malware targets developers in new supply chain attack 2026-02-24 at 15:10 By Zeljka Zorz Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. The operation, dubbed “SANDWORM_MODE,” represents a (still) rare example of worm-like […]

Self-spreading npm malware targets developers in new supply chain attack Read More »

Windows 365 for Agents brings managed cloud PCs to autonomous workflows

Windows 365 for Agents brings managed cloud PCs to autonomous workflows 2026-02-24 at 13:02 By Anamarija Pogorelec Microsoft’s Windows 365 for Agents is a cloud platform that gives AI agents secure access to cloud PCs. It lets builders run copilots, agents, and automated workflows in Windows environments without managing infrastructure. The platform includes security, policy […]

Windows 365 for Agents brings managed cloud PCs to autonomous workflows Read More »

International operation dismantles fraud network, €400,000 seized

International operation dismantles fraud network, €400,000 seized 2026-02-24 at 12:55 By Sinisa Markovic A coordinated international operation supported by Eurojust dismantled a fraudulent call centre operating from three offices and targeting citizens throughout Europe. Authorities arrested 11 suspects and seized more than €400,000 in cash. Initial investigations identified victims in Latvia and Lithuania who lost […]

International operation dismantles fraud network, €400,000 seized Read More »

Microsoft extends security patching for three Windows products at a price

Microsoft extends security patching for three Windows products at a price 2026-02-24 at 11:38 By Sinisa Markovic Support is ending for three Windows products released in 2016, with deadlines beginning in October 2026. Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB will reach end of support on October 13, 2026, followed […]

Microsoft extends security patching for three Windows products at a price Read More »

AI is becoming part of everyday criminal workflows

AI is becoming part of everyday criminal workflows 2026-02-24 at 09:00 By Mirko Zorz Underground forums include long threads about chatbots drafting phishing emails, generating code snippets, and coaching social engineering calls. A new study examined conversations captured between January 1, 2025 and July 31, 2025 across dozens of cybercrime forums to map how AI […]

AI is becoming part of everyday criminal workflows Read More »

EU targets Meta over WhatsApp AI access restrictions

EU targets Meta over WhatsApp AI access restrictions 2026-02-09 at 17:42 By Sinisa Markovic The European Commission believes Meta breached EU competition rules by blocking other AI assistants from accessing and interacting with users on WhatsApp. The case centers on a change Meta announced on 15 October 2025 to the WhatsApp Business Solution Terms. The […]

EU targets Meta over WhatsApp AI access restrictions Read More »

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment 2026-02-09 at 17:18 By Zeljka Zorz SmarterTools, the company behind the popular Microsoft Exchange alternative SmarterMail, has been breached by a ransomware-wielding group that leveraged a recently fixed vulnerability in that solution. How did the SmarterTools breach happen? Derek Curtis, the firm’s Chief Operating Officer, […]

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment Read More »

European Commission hit by cyberattackers targeting mobile management platform

European Commission hit by cyberattackers targeting mobile management platform 2026-02-09 at 16:02 By Zeljka Zorz The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the […]

European Commission hit by cyberattackers targeting mobile management platform Read More »

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731)

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) 2026-02-09 at 13:36 By Zeljka Zorz BeyondTrust fixed a critical remote code execution vulnerability (CVE-2026-1731) in its Remote Support (RS) and Privileged Remote Access (PRA) solutions and is urging self-hosted customers to apply the patch as soon a possible. Unlike the Remote Support zero-day […]

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) Read More »

Linux kernel 6.19 reaches stable release, kernel 7.0 work is already underway

Linux kernel 6.19 reaches stable release, kernel 7.0 work is already underway 2026-02-09 at 13:32 By Anamarija Pogorelec Development activity on the Linux kernel continues into early 2026 with the stable release of version 6.19. Kernel maintainers have completed the pre-release cycle and merged the final set of changes into the mainline tree. The release […]

Linux kernel 6.19 reaches stable release, kernel 7.0 work is already underway Read More »

Scroll to Top