Seven WordPress plugins have been used to plant rogue administrator accounts and webshells on live sites without a single plugin file being modified. Instead, attackers poisoned a promotional data feed the plugins load into the admin dashboard. Wordfence was notified… Read More "WordPress Plugins Compromised Without a Single File Change"
Faking it on the phone: How to tell if a voice call is AI or not
Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers. 23 Feb 2026 • , 4 min. read There was a time when we could believe everything… Read More "Faking it on the phone: How to tell if a voice call is AI or not"
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
A flaw in Atlassian’s enterprise AI assistant has allowed a single crafted link to seed attacker instructions into a victim’s authenticated session, then use the assistant’s own browsing agent to push company data out to the public web. Varonis Threat… Read More "Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant"
This month in security with Tony Anscombe – February 2026 edition
In this roundup, Tony looks at how opportunistic threat actors are taking advantage of weak authentication, unmanaged exposure, and popular AI tools 28 Feb 2026 With the second month of 2026 (almost) behind us, it’s time for ESET Chief Security… Read More "This month in security with Tony Anscombe – February 2026 edition"
DDoS Attack Hits Norwegian Government Services
A major DDoS attack on the Norwegian government’s digitalization agency has disrupted key services since Monday. The agency, known as Digitaliseringsdirektoratet (Digdir), explained in an update on August 25 that the attack began on Monday night at 3.38am local time.… Read More "DDoS Attack Hits Norwegian Government Services"
How SMBs use threat research and MDR to build a defensive edge
Corporate IT and security teams have the unenviable task of keeping relentless and increasingly sophisticated adversaries at bay. They’re often faced with limited resources and expanding attack surfaces, but recruiting and retaining top-tier security professionals to run an in-house Security… Read More "How SMBs use threat research and MDR to build a defensive edge"
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
One major security challenge with generative AI, and particularly AI agents, is making these systems prove what they really did. The Linux Foundation aims to address this challenge through a new open standard for AI runtime evidence that helps make… Read More "Linux Foundation Introduces TRACE Standard for AI Runtime Evidence"
What cybersecurity actually does for your business
The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed 06 Mar 2026 • , 5 min. read Cybersecurity is one of the few business functions where… Read More "What cybersecurity actually does for your business"
Average Cyber Insurance Losses Increase Despite Fewer Claims
The average cost of cybersecurity insurance claims made by large and middle-market companies surged in 2025, despite a significant drop in the volume of claims, according to Chubb’s 2026 Cyber Claims Report. The insurer said the growing severity of claims… Read More "Average Cyber Insurance Losses Increase Despite Fewer Claims"
Sednit reloaded: Back in the trenches
Since April 2024, Sednit’s advanced development team has reemerged with a modern toolkit centered on two paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. This dual‑implant approach enabled long‑term surveillance of Ukrainian military personnel. Interestingly,… Read More "Sednit reloaded: Back in the trenches"