24 Sep, 2026

US seizes over 1,000 websites in FIFA World Cup piracy crackdown

The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. Law enforcement authorities identified the seized domains using leads provided by U.S. authorities, FIFA (Fédération Internationale de Football Association), the Motion Picture Association’s Alliance for Creativity and Entertainment (ACE), and multiple […]

2 mins read

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on […]

2 mins read

Microsoft shares manual fix for WSUS sync delays and timeouts

Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. This known WSUS sync issue affects both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms. On impacted WSUS servers, […]

2 mins read

Windows LegacyHive zero-day flaw gets free, unofficial patches

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the “Nightmare Eclipse” handle in the Windows User Profile Service. Nightmare Eclipse disclosed it the day […]

3 mins read

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining ” personal information of certain […]

2 mins read

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. Last week, SonicWall warned that threat actors were actively exploiting two previously undisclosed vulnerabilities in an exploit chain that affected SMA1000 Secure Mobile Access appliances. The flaws, tracked as CVE-2026-15409, a critical server-side […]

3 mins read

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. According to an update from the platform yesterday, the attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to generate […]

2 mins read

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI’s Codex, Google’s Gemini CLI and Antigravity, without attacking the sandbox head-on. The agent stays inside the box and follows every rule. It just writes a file that a trusted tool outside the box later runs, loads, or scans, […]

4 mins read

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data encryption. Cloud security […]

3 mins read

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. Researchers analysing the module believe it is part of the Cavern command-and-control framework that has been previously linked to an Iranian threat actor targeting entities in Israel. At least 12 systems […]

3 mins read