28 Sep, 2026

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks. Hackers are also exploiting two additional vulnerabilities: a high-severity […]

2 mins read

Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it’s offering up to $250 in free promotional credits. Cloud sessions run Claude Code on Anthropic’s infrastructure instead of your own computer, so you can start a task, leave it running remotely, and return later to […]

1 min read

OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it’s unclear when it’ll begin rolling out. OpenAI users, particularly power users, have been requesting more usage than the existing $200 plan offers for a while, so the $500 plan isn’t just coming out of nowhere. Right […]

2 mins read

Microsoft plans to deprecate Windows Deployment Services

Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. WDS is a revised version of Remote Installation Services (RIS) that lets IT administrators remotely install Windows operating systems on fleets of dozens or hundreds of computers over a network. After deprecating WDS in the next […]

2 mins read

Rydox marketplace admin pleads guilty, faces 22 years in prison

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. Kosovo law enforcement and Albania’s Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024. The arrests […]

2 mins read

Microsoft: Recent Windows updates cause desktop loading issues

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. However, the company says this mainly affects Azure Virtual Desktop (AVD) hosts using FSLogix (a software solution that speeds up user profile loading in virtual desktop environments). Windows users affected by […]

2 mins read

Hackers steal $351.6 million in Bitget crypto exchange hack

​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. Bitget has temporarily suspended all withdrawals while investigating the incident with help from […]

3 mins read

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads. MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers say that while […]

3 mins read

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. The malware features worm-like capabilities and was discovered in an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data. Researchers at enterprise security company ThreatDown retrieved operational evidence […]

2 mins read

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. The addresses are part of a built-in GitLab feature called “Email work item to this project” and contain a long-lived token tied to the […]

3 mins read