Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. The security issue allows an unauthenticated attacker to access specific files within an affected application’s web root directory. However, exploitation requires knowing the exact name of […]
ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company’s Snowflake environment. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. […]
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. Researchers found that the phishing operation leveraged the recent launch of the Muse AI agent, which Meta describes as an assistant for various personal tasks. The malicious pages […]
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. As Wikimedia Chief Product and Technology Officer Selena Deckelmann revealed Monday, Wikipedia hosts over 67 million articles in more than 300 languages and gets up to 15 billion page views per month. However, last […]
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. In a Sunday statement, the company said an employee’s Google Workspace account was accessed in late July, exposing the personal information of employees and business partners. Nikkei changed the […]
Engineer sentenced for locking over 3,000 devices on employer network
A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer’s network in a ransomware-style attack. 57-year-old Daniel Rhyne from Kansas City, Missouri, pleaded guilty to his role in a failed extortion plot targeting the New Jersey company […]
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. The watermark will not be visible when you read or copy the text. Instead, OpenAI says its new textGrain technology slightly changes the model’s word choices to create a statistical pattern that can later be detected. “Over […]
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). VulnCheck VP of Security Research Caitlin Condon posted on LinkedIn over the weekend that the company’s Canary Intelligence honeypots had observed probes targeting CVE-2026-61500. Condon said the observed activity […]
IQVIA fined $7.8 million for failing to properly anonymize health data
Italy’s Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. IQVIA is a multinational company that provides healthcare data analysis, technology, and clinical research services. The company claims on its website that […]
Denmark population registry data breach affects 8.8 million people
Denmark’s Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. This includes people who live in the country, individuals who have moved abroad, and also deceased people. The CPR is the country’s national civil registry, containing personal information on residents, including names, addresses, dates […]