CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks. Hackers are also exploiting two additional vulnerabilities: a high-severity […]
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it’s offering up to $250 in free promotional credits. Cloud sessions run Claude Code on Anthropic’s infrastructure instead of your own computer, so you can start a task, leave it running remotely, and return later to […]
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it’s unclear when it’ll begin rolling out. OpenAI users, particularly power users, have been requesting more usage than the existing $200 plan offers for a while, so the $500 plan isn’t just coming out of nowhere. Right […]
Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. WDS is a revised version of Remote Installation Services (RIS) that lets IT administrators remotely install Windows operating systems on fleets of dozens or hundreds of computers over a network. After deprecating WDS in the next […]
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. Kosovo law enforcement and Albania’s Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024. The arrests […]
Microsoft: Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. However, the company says this mainly affects Azure Virtual Desktop (AVD) hosts using FSLogix (a software solution that speeds up user profile loading in virtual desktop environments). Windows users affected by […]
Hackers steal $351.6 million in Bitget crypto exchange hack
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. Bitget has temporarily suspended all withdrawals while investigating the incident with help from […]
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads. MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers say that while […]
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. The malware features worm-like capabilities and was discovered in an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data. Researchers at enterprise security company ThreatDown retrieved operational evidence […]
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. The addresses are part of a built-in GitLab feature called “Email work item to this project” and contain a long-lived token tied to the […]