Security researchers have uncovered NovaCookies, a phishing-as-a-service platform that helps criminals steal Microsoft 365 authentication sessions in real time. The platform gives attackers infrastructure that relays a genuine Microsoft sign-in page through attacker-controlled systems. Victims are directed to what appears to be a legitimate login process, allowing the service to collect credentials and intercept the authenticated session after the user enters a password and completes multi-fac
All Articles (3176)
Getting hacked has a way of making people panic first and think clearly second. That's understandable, because the moment you realize someone may have gotten into your email, social account, or bank login, your brain tends to jump straight to damage control. In that rush, many people focus on the most obvious fix and assume the crisis is basically over once they do it.
The biggest mistake people make after getting hacked is treating the incident like a single-password problem instead of a full
Cybersecurity staff at US phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide hacks by Beijing to steal customer data, and Bloomberg has now published a report on the event. T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese state-backed hackers’ access to its systems.[1]
The dramatic move came amid a sprawling espionage campai
Researchers have been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary. While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple kno
This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch on 8 September 2026 brings the 2026 total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.[1]
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elev
How to explain agentic AI to your leadership team, from Ashley Nicholson[1]:
It's not one, single tool. It's layers of capability.
Here are 5 levels that will determine who wins in 2026:
- Machine Learning:
- Turns data into decisions.
- Forecasts sales, detects fraud, and can predict churn.
- It can optimize pricing automatically.
- Tools: AWS SageMaker, Google Vertex AI, Azure ML.
- Neural Networks & Deep Learning:
- Complex pattern detection at scale.
- Inspects quality with computer vision.
- Powers v
Generative AI is quickly becoming one of the more lucrative uses for stolen cloud credentials. Attackers no longer need to set up crypto miners or exfiltrate data to cash in on a leaked IAM key. They can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called LLMjacking, first documented in 2024. FortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become.[1]
FortiGuard Labs recently analyzed a long-li
US President Trump has signed a landmark national security presidential memorandum that fundamentally alters the American approach to digital warfare. This directive authorizes federal law enforcement agencies to partner with vetted private technology firms to execute offensive cyber operations against foreign criminal organizations and international adversaries. Under this new framework, private sector specialists will work under direct government supervision to propose, coordinate, and carry
Mabna Institute is an Iran-based organization alleged by US authorities to have operated a large, coordinated credential-theft and data-exfiltration campaign since at least 2013. Its principal targets were universities and research institutions, but the victim set also included private companies, government agencies, and international organizations. US prosecutors allege that the activity supported the Islamic Revolutionary Guard Corps (IRGC), other Iranian government customers, and Iranian un
The zLabs team recently identified an updated variant of ToxicPanda, the Android banking Trojan known to have primarily targeted Europe, that introduces significant enhancements, including a comprehensive command set of 167 remote commands and substantially expands its targets globally. Among the newly added capabilities is a PIN theft mechanism targeting more than 140 banking and cryptocurrency applications. By abusing the Android Accessibility Service, threat actors can steal every UI element
Assessment: Chaos presents a high enterprise risk because the name now refers to two related but operationally distinct threat streams: the widely copied Chaos builder that emerged in 2021, and a newer ransomware-as-a-service operation observed from 2025. Early builder versions behaved partly as destructive wipers; later variants supported recoverable encryption. The newer operation conducts human-operated, double-extortion intrusions, combining data theft with encryption and pressure through
Imagine you receive a large box of numbers meant to serve as a public key for secure communication. The numbers look completely random, the way scrambled data should look if no one can find a pattern. Yet a careful test reveals a subtle internal order. That is the main finding of a recent paper by Ashrujit Ghoshal, Yuval Ishai, Aayush Jain, and Nuozhou Sun titled “Quasipolynomial Cryptanalysis of the McEliece Cryptosystem.” The paper does not open the box or read any of the messages inside i
Recent findings from Sophos highlight a worrying trend: cybercriminals are capitalizing on global interest in artificial intelligence. By impersonating established AI brands such as Perplexity, Claude, ChatGPT, and Copilot, these attackers are successfully tricking individuals and businesses into downloading malicious software. This campaign exploits users' eagerness to adopt the latest digital tools, turning a technological boom into a significant security risk for organizations worldwide.[1
Labor Day creates a predictable operational window that can favor cyber adversaries: offices close, security and IT staffing decline, senior decision-makers travel, vendors operate on reduced schedules, and suspicious activity can remain untriaged for longer. The principal concern is not a uniquely “Labor Day” malware family, but the deliberate timing of ransomware, data theft, business email compromise, distributed denial-of-service, and supply-chain exploitation to coincide with reduced defen
Cybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images. In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images. The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]
The discovery highlights a worrying security la
On August 20th of this year, the Rust Security Response Team disclosed a supply-chain attack that was affecting several packages hosted on the crates.io repository. Probably the most significant of the affected packages was the arrayref package, which is a long-established utility package with approximately 245 million previous downloads. It's estimated that this package alone is present in about 3/4 of environments where Rust is used.
Attackers were able to compromise the credentials of the leg
OT security was traditionally built around the control room: PLCs, HMIs, the systems directly running a process. But the systems that determine whether operations stay running now extend well past it. Connected OT, cloud services, and remote access infrastructure are part of the environment too. If a system's failure can stop production, affect safety, or compromise output, it's in scope.
That's what is explained as xOT (Extended Operational Technology), not a new category of device, but a st
Across four weeks in July and August 2026, OpenAI, Anthropic and Meta have each admitted that their models reached systems belonging to other organizations without consent, and the UK’s AI Security Institute (AISI) published a fourth account describing agents that invented identities and tried to slip a malicious contribution into a live open source project (Autonomous Long Horizon Malware Analysis. https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easy to parse, and traditionally much of it has remained walled off in the hands of large advertising platforms. Not anymore: A powerful, free new service called DecryptAds scrapes and correlates this adtech data and makes it easy to quickly learn a great deal about the entities tracking
A cybersecurity analysis by CloudSEK revealed the scale of the March 2026 LiteLLM supply-chain attack, which exposed about 434,000 CI/CD pipelines at more than 2,500 companies worldwide. Continuous Integration (CI) and Continuous Delivery (CD) pipelines are automated workflows that build, test, and deploy software from a developer’s environment to production users. Although the malicious packages were active for only about 40 minutes, the breach may have exposed critical credentials and securi