14 Sep, 2026

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims […]

7 mins read

Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. A new report from cloud security company Wiz confirmed exploitation across multiple environments, including an exploit chain that combines CVE-2026-42018 and CVE-2026-42016. The third vulnerability is CVE-2026-82329, a critical […]

2 mins read

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The security flaw, discovered by a security researcher using the ‘s3ntago‘ handle and reported via GitLab’s HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API. Unauthenticated attackers can […]

3 mins read

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Microsoft has fixed a bug that prevented Teams and Outlook from launching after installing updates released since the August 2026 Patch Tuesday. The company confirmed last week that this known issue affects users who haven’t installed Microsoft Store updates on ARM-based Windows devices (such as the Surface Pro 11 and Surface Laptop 7) running Windows […]

2 mins read

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. As Trezor warned on Wednesday, threat actors who breached Brevo, its third-party email provider, were emailing customers who opted in to receive newsletters. According to customers targeted in this […]

2 mins read

Conti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. 44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda SĂ­ochána) in July 2023 at the request of the United States and was extradited last year. Lytvynenko and his Conti […]

3 mins read

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages. After installation, the malware requests permission to use the Accessibility service, which gives […]

3 mins read

September Windows Server updates break Remote Desktop Services

Windows admins report that the September 2026 cumulative updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 systems, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. The problems appear after installing this month’s Microsoft September 2026 Patch Tuesday cumulative updates, with many admins reporting […]

2 mins read

Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials. “Due to a human error, […]

2 mins read

Microsoft Excel KB5002914 update breaks copy and paste for some users

Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. Microsoft released the security update this week as part of its September 2026 Patch Tuesday, and reports of the problem soon appeared on both Reddit and […]

2 mins read