Webinar: Analyzing Real Google Workspace Breaches and Early Response Decisions
A September 23 webinar from BleepingComputer and Material Security examines real Google Workspace breaches and the response decisions that shaped their outcomes
ThreatsA September 23 webinar from BleepingComputer and Material Security examines real Google Workspace breaches and the response decisions that shaped their outcomes
ThreatsSchneier's DEF CON talk on AI hacking drew over 100K YouTube views. It combines insights from his 2022 book with current AI hacking behavior.
ThreatsAI agents can locate vulnerabilities with only a vague description of a bug. This threatens existing open source embargo practices for security disclosures.
ToolsAnthropic has disclosed a fourth incident in which its AI models breached real third-party systems, tracing the root cause to biased reasoning and recklessness.
VPN & PrivacyThreat actors call employees on personal devices, steal Microsoft credentials, then use the Graph API to quietly exfiltrate corporate data at scale.
ToolsA new cPanel flaw lets an authenticated hosting account achieve root-level code execution via SQL injection in EmailTrack. All supported versions are affected.
Threats
James Strahler II was sentenced to 15 years for cyberstalking, AI-generated sextortion, and child sexual abuse material. He is the first person convicted under
A breach at Trezor's shipping provider ShipMonk has grown to affect 81,000 customers after the provider failed to delete data as contractually required.
Microsoft is fixing a bug causing Teams and new Outlook to crash on ARM devices after August 2026 Patch Tuesday updates. A temporary workaround is available.
A new Shai-Hulud variant scans 469 locations for developer credentials, up from 189. Securing the credential layer is now the core supply chain defense priority
Comcast has added WiFi-based motion detection to its routers. The feature can share motion data with third parties, including law enforcement.
Novocure disclosed a mid-August cyberattack exposing over 1,400 U.S. patient records and employee contact data. No medical devices were accessed.
A price-manipulation attack on Tectonic drained $74 million in borrowed assets. Cronos halted and restored the blockchain to a pre-exploit state.
Two root RCE vulnerabilities in the Unitree G1 EDU robot allow network-adjacent and BLE-based code execution. No confirmed fixed firmware version exists.
AI tools let cybercriminals profile victims faster and cheaper than ever. Here's what the threat looks like and what you can still control.