11 Oct, 2026

Microsoft Teams to get support for third-party deepfake detection tools

Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. According to new entries on the Microsoft 365 Roadmap, both changes are now in development and will reach general availability in November after a worldwide rollout. Once available, Microsoft says it will provide Teams integration and experiences to surface […]

2 mins read

ASOS links data breach to social engineering attack, credential theft

UK fashion retailer ASOS confirmed that a recent data breach was caused by a social engineering attack in which hackers stole an employee’s login credentials and used them to access information on third-party platforms used by the company. “We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted […]

2 mins read

Owner of Empire cybercrime market gets 40 years in prison

The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. 30-year-old Raheim Hamilton (also known online as “Sydney” and “ZeroAngel”) owned and operated Empire Market from August 2017 until its abrupt […]

3 mins read

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. The day’s highlight was the Samsung Galaxy S26 flagship getting hacked three times by KAIST Hacking Lab‘s Kyeongmin Kim, PetoWorks, and a team made up of Dimitrios Valsamaras, Ken Gannon, and CENSUS Labs’s Tenia Valsamara. […]

2 mins read

Ransomware recovery CEO charged over secret ransom payments

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” was indicted by a federal grand jury in the Eastern District of […]

4 mins read

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. Hackers gain access to exposed endpoints by using previously leaked credentials, or logins obtained from infostealer logs, credential stuffing, and password spraying attacks. They then extract additional authentication data from compromised […]

2 mins read

Hackers hijack Google domains after breaching ccTLD registries

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but “did not involve […]

3 mins read

Microsoft Outlook to block MSIX attachments starting November

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. .msix files are modern Windows installation packages tailored for specific computer architectures or configurations, while .msixbundle is a container that groups multiple .msix packages into a single […]

2 mins read

PoeLLM malware infects exposed AI servers in cryptomining attacks

A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. The malware features an uncommon method to retrieve command-and-control (C2) addresses by extracting keywords in a poem hosted on GitHub. Researchers at Lumen’s Black Lotus Labs (BLL) tracking the botnet malware say it has compromised more […]

3 mins read

Hackers exploit critical Atlassian flaw after public PoC release

A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. Earlier today, security company Previdian detected the activity on its honeypot network, just hours after a detailed technical report was published. An unauthenticated attacker can exploit CVE-2026-21589 to access specific files […]

3 mins read