Cybersecurity researchers uncovered what is being called the “mother of all breaches,” a colossal dataset containing 16 billion login credentials, including user passwords for Google, Facebook, and Apple. To put that figure in context, the cache represents twice the current… Read More "The Mother of All Breaches: A Corporate Credential Security Wake-Up Call"
Meta Sued Over Training Data for Its AI and Face-Recognition Systems
A set of parents and their children in Illinois and California filed a lawsuit last week in federal court in Chicago alleging that Meta illegally used their Facebook and Instagram photos to build NameTag, an unreleased face-recognition system for its… Read More "Meta Sued Over Training Data for Its AI and Face-Recognition Systems"
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
A United States court sentenced Ukrainian national Oleksii Oleksiyovych Lytvynenko to four years in prison this week for his role in the Conti ransomware operation. Lytvynenko, 44, was arrested in Ireland in 2023 and extradited to the United States in… Read More "Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison"
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Ravie LakshmananSep 11, 2026Artificial Intelligence / Cybercrime Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself… Read More "Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks"
ConnectWise patches critical ScreenConnect authentication failure after five days
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the… Read More "ConnectWise patches critical ScreenConnect authentication failure after five days"
Phishing Attacks Targeted Facebook Users With Fake Verification Offer
Cybercriminals abused Facebook Messenger chatbots in a campaign which distributed phishing attacks designed to steal business information and other sensitive data from Meta For Business users. The campaign, identified by Huntress, found a way to successfully pass security validation checks… Read More "Phishing Attacks Targeted Facebook Users With Fake Verification Offer"
Your Password Was Exposed in a Non-Google Data Breach: How to Respond
If you’re a Google Chrome user, you may have received the pop-up alert “Your password was exposed in a non-Google data breach” in your web browser. The alert informs users of any recent security breaches which may have compromised their… Read More "Your Password Was Exposed in a Non-Google Data Breach: How to Respond"
Phishing Research Challenges Conventional Security Awareness Testing
The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research. Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management,… Read More "Phishing Research Challenges Conventional Security Awareness Testing"
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Ravie LakshmananSep 11, 2026Vulnerability / Web Security GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a… Read More "GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure"
Update your firewall rules: Teams and Copilot are changing address
Enterprises that had been blocking the new Copilot address to prevent employees accessing their personal Microsoft accounts can use Microsoft’s TenantRestrictions control to achieve their goals instead, it said. All redirects should be completed by early October, Microsoft said, advising… Read More "Update your firewall rules: Teams and Copilot are changing address"