A compromised AWS access key was the likely root cause of the cyber-attack on CRM provider Beacon, which has exposed personal information held by around 1500 UK charities. The software provider said in an August 12 incident update that the… Read More "Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charit"
OpenAI: Hugging Face Incident a “Warning Shot” to the World
An “unprecedented cyber incident” in which OpenAI agents broke free of an internet-isolated sandbox and hacked Hugging Face was largely driven by an improvised messaging board they created, the AI company has revealed. The agents were working on a “capture-the-flag”… Read More "OpenAI: Hugging Face Incident a “Warning Shot” to the World"
Boston Scientific Suffers Global Disruption After Cyber Incident
Boston Scientific has become the latest medical technology (medtech) company to be hit by a major cyber incident, leading to widespread IT disruption. The US-headquartered firm said in a brief statement published on August 26 that the incident was identified… Read More "Boston Scientific Suffers Global Disruption After Cyber Incident"
CISA Warns of Six Exploited Flaws in Microsoft, Linux and Citrix
The US Cybersecurity and Infrastructure Security Agency (CISA) added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly. CISA KEV listing… Read More "CISA Warns of Six Exploited Flaws in Microsoft, Linux and Citrix"
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Inf
A sophisticated Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms, the FBI has warned. The group has focused on critical infrastructure sectors including defense industrial base… Read More "Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Inf"
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Ravie LakshmananSep 14, 2026Cyber Espionage / Vulnerability A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national… Read More "Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries"
Manchester Airports Group Hit by Cyber Incident
Customer data relating to car park, lounge and Fast Track bookings, and in-airport Wi-Fi sign-ups at three UK airports has been obtained by an unauthorized third party. Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports,… Read More "Manchester Airports Group Hit by Cyber Incident"
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were… Read More "New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing"
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Aurora ransomware actors have been observed abusing SpaceX’s AI Cursor Agent as part of exploitation campaigns, according to a new study by Gambit Security’s Threat Intelligence team. The threat actors ran Claude Sonnet through Cursor Agent to assist with various… Read More "Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations"
New York Seizes a Dozen Celebrity Deepfake Websites
For the best part of a decade, abusive deepfake “pornography” websites have published thousands of nonconsensual videos depicting women, including high-profile celebrities, politicians, and public figures, into sexual situations. Now, in what is likely the largest takedown of explicit deepfake… Read More "New York Seizes a Dozen Celebrity Deepfake Websites"