10 Oct, 2026

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. The flaw […]

2 mins read

Musician sent to prison for $10 million streaming fraud using AI bots

A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme. 54-year-old Michael Smith pleaded guilty in March after being indicted in September 2024 for fraudulently inflating his songs’ listening stats […]

2 mins read

Advantest confirms personal information stolen in ransomware attack

Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. The Japanese company is a global manufacturer of automated test equipment for the semiconductor industry. On February 15, a threat actor breached its network and gained access to some of its systems. At the time, the disclosure […]

2 mins read

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 […]

3 mins read

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. During the Pwn2Own Ireland 2026 hacking contest, competitors target products in seven categories, including mobile phones (Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, […]

2 mins read

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. The security issue allows an unauthenticated attacker to access specific files within an affected application’s web root directory. However, exploitation requires knowing the exact name of […]

2 mins read

ASOS confirms data breach after “HACKED” in-app notifications

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company’s Snowflake environment. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. […]

2 mins read

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. Researchers found that the phishing operation leveraged the recent launch of the Muse AI agent, which Meta describes as an assistant for various personal tasks. The malicious pages […]

4 mins read

Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. As Wikimedia Chief Product and Technology Officer Selena Deckelmann revealed Monday, Wikipedia hosts over 67 million articles in more than 300 languages and gets up to 15 billion page views per month. However, last […]

2 mins read

Nikkei discloses breaches of employees’ Microsoft, Google email accounts

Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. In a Sunday statement, the company said an employee’s Google Workspace account was accessed in late July, exposing the personal information of employees and business partners. Nikkei changed the […]

2 mins read