21 Sep, 2026

Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs

The Netherlands’ National Cyber Security Centre (NCSC) is warning that a critical Citrix NetScaler vulnerability tracked as CVE-2025-6543 was exploited to breach “critical organizations” in the country. The critical flaw is a memory overflow bug that allows unintended control flow or a denial of service state on impacted devices. “Memory overflow vulnerability leading to unintended control […]

3 mins read

Details emerge on WinRAR zero-day attacks that infected PCs with malware

Researchers have released a report detailing how a recent WinRAR path traversal vulnerability tracked as CVE-2025-8088 was exploited in zero-day attacks by the Russian ‘RomCom’ hacking group to drop different malware payloads. RomCom (aka Storm-0978 and Tropical Scorpius) is a Russian cyberespionage threat group with a history in zero-day exploitation, including in Firefox (CVE-2024-9680, CVE-2024-49039) and Microsoft Office (CVE-2023-36884). ESET […]

4 mins read

Microsoft tests cloud-based Windows 365 disaster recovery PCs

Microsoft has announced the limited public preview of Windows 365 Reserve, a service that provides temporary desktop access to pre-configured cloud PCs for employees whose computers have become unavailable due to cyberattacks, hardware issues, or software problems. Windows 365 Reserve provides up to 10 days of access per user annually to these cloud-based Windows 365 […]

2 mins read

OpenAI is testing 3,000-per-week limit for GPT-5 Thinking

OpenAI has responded to criticism that it shipped GPT-5 with token limits to minimize cost and maximize profit not with words, but rather with a new 3,000-per-week limit. In a series of posts on X, Sam Altman confirmed that OpenAI is working on a 3,000-per-week limit for GPT-5 Thinking messages for Plus users. This will increase the […]

1 min read

OneNote finally gets “paste text only” feature on Windows and Mac

OneNote is a powerful note-taking app, but that doesn’t necessarily mean it has all the features you want. One of the missing features is ‘Paste as text only,’ and it’s finally coming to OneNote. In a blog post, Microsoft confirmed that it’s testing the ability to paste text only (plain format). Right now, when you copy content […]

1 min read

xAI is testing Grok 4.20 to take on GPT-5, may launch this month

Elon Musk-owned xAI is testing Grok 4.20, a new model update to Grok 4, which already competes with GPT-5 in some benchmarks, such as ARC-AGI 2. GPT-5 is one of the best models for coding, and it competes with Claude Opus 4.1 head-to-head in some coding challenges. On the other hand, Grok falls a bit […]

1 min read

MuddyWater’s DarkBit ransomware cracked for free data recovery

Cybersecurity firm Profero cracked the encryption of the DarkBit ransomware gang’s encryptors, allowing them to recover a victim’s files for free without paying a ransom. This occurred in 2023 during an incident response handled by Profero experts, who were brought in to investigate a ransomware attack on one of their clients, which had encrypted multiple […]

3 mins read

‘Chairmen’ of $100 million scam operation extradited to US

The U.S. Department of Justice charged four Ghanaian nationals for their roles in a massive fraud ring linked to the theft of over $100 million in romance scams and business email compromise attacks. The defendants were allegedly high-ranking members of a major international fraud ring based in Ghana that targeted companies and individuals across the United States […]

2 mins read

Over 29,000 Exchange servers unpatched against high-severity flaw

Over 29,000 Exchange servers exposed online remain unpatched against a high-severity vulnerability that can let attackers move laterally in Microsoft cloud environments, potentially leading to complete domain compromise. The security flaw (tracked as CVE-2025-53786) helps threat actors who gain administrative access to on-premises Exchange servers to escalate privileges within the organization’s connected cloud environment by […]

3 mins read

Connex Credit Union data breach impacts 172,000 members

Connex, one of Connecticut’s largest credit unions, warned tens of thousands of members that unknown attackers had stolen their personal and financial information after breaching its systems in early June. Founded in 1940, this member-owned organization is a non-profit with over $1 billion in assets, providing banking, insurance, and credit card services to more than […]

2 mins read