Those interested in how data breaches occur should be familiar with the general topography of the Internet. In our previous piece, we discussed the difference between the surface web, deep web and dark web. Most estimates about the topography of… Read More "Data Leaks and the Deep Web: Swimming in the Deep End"
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy… Read More "In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review"
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a… Read More "Your Critical Vulnerabilities Might Not Be Your Biggest Risk"
ESET Threat Report H2 2025
A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts 16 Dec 2025 • , 2 min. read The second half of the year underscored just… Read More "ESET Threat Report H2 2025"
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
A phishing campaign abusing Microsoft 365’s Direct Send feature was observed to follow US Eastern business hours. The campaign was uncovered by the KnowBe4 Threat Lab team, who observed 29,785 confirmed phishing emails abusing the Direct Send functionality across July and August… Read More "Hackers Favor US Eastern Business Hours in M365 Phishing Campaign"
This Password Has Appeared in a Data Leak: How to Respond
“This password has appeared in a data leak, putting this account at high risk of compromise. You should change your password immediately” – if you own an iPhone or iPad running on iOS 14 or above, you may have received… Read More "This Password Has Appeared in a Data Leak: How to Respond"
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked. The incident involved the marketing platform Brevo, which Trezor uses for newsletters. Brevo said an… Read More "Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack"
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an… Read More "Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware"
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Attackers registered their own authentication methods Once an identity was compromised, Microsoft observed attackers registering authentication methods under their control, including phone numbers, authenticator applications, and software-based OTP tokens. This gave them a way to satisfy future MFA challenges without… Read More "Attackers use passkey-themed scams to hijack Microsoft 365 accounts"
Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component
ESET researchers examined CVE‑2025‑50165, a serious Windows vulnerability described to grant remote code execution by merely opening a specially crafted JPG file – one of the most widely used image formats. The flaw, found and documented by Zscaler ThreatLabz, piqued… Read More "Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component"