Security researchers have uncovered a new phishing-as-a-service (PhaaS) operation which they claim has already exfiltrated more than 5100 Microsoft 365 credential records from victims. Bigbear 2.0 is based on adversary-in-the-middle framework Evilginx2, according to CloudSEK. The research outfit managed to… Read More "BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials"
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Ravie LakshmananSep 08, 2026Vulnerability / Web Security Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score:… Read More "Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell"
Government Updates UK’s National Risk Register with Cyber Warnings
The UK government has added several new cyber-related scenarios to its National Risk Register; some of which could theoretically result in mass casualties. The register is based on the government’s internal, classified National Security Risk Assessment, and considers malicious risks… Read More "Government Updates UK’s National Risk Register with Cyber Warnings"
Why CISOs should focus on real AI threats, not hype
Build defenses around your actual threat profile It’s vital, however, that investment decisions be made on data and the specific threat profile facing an individual organization. This is why AI proving grounds are becoming increasingly critical to the world’s leading… Read More "Why CISOs should focus on real AI threats, not hype"
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Cryptocurrency wallet manufacturer Trezor has revealed that a breach at a key shipping partner has affected 67,000 more customers than originally thought. In an update posted on September 4, the hardware specialist said it was informed that the trove stolen… Read More "Trezor Supply Chain Breach Now Impacts 81,000 Customers"
Securing AI agents: Key controls and best practices
“We spent twenty years building identity management for people: usernames, passwords, role-based access,” says Justin Beals, CEO of governance, risk, and compliance company Strike Graph. “None of that was designed for agents that don’t get tired, don’t go home, and… Read More "Securing AI agents: Key controls and best practices"
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Ravie LakshmananSep 08, 2026Data Privacy / Regulation Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users’ personal information, including their HIV status, with third-parties.… Read More "Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing"