Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two of them have been flagged as exploited. The exploited flaws, dubbed MikroTrick, allow attackers to bypass… Read More "MikroTik Patches Critical Flaws Chained to Hack Routers"
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who… Read More "FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials"
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA… Read More "BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA"
Healthcare and Victim Support Charities Affected by Beacon Cyber Incid
Around 1500 UK charities have potentially suffered data breaches following a cyber incident impacting third-party CRM provider Beacon. Personal details held by these charities, including those operating in sensitive areas such as healthcare and victim support, are believed to have… Read More "Healthcare and Victim Support Charities Affected by Beacon Cyber Incid"
Mathspace Data Breach Exposes Over 1 Million People
Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals. The incident, it says, was discovered last week, roughly three weeks after hackers compromised its self-hosted Metabase instance using a known vulnerability.… Read More "Mathspace Data Breach Exposes Over 1 Million People"
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It… Read More "BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams"
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
Security researchers have uncovered a new phishing-as-a-service (PhaaS) operation which they claim has already exfiltrated more than 5100 Microsoft 365 credential records from victims. Bigbear 2.0 is based on adversary-in-the-middle framework Evilginx2, according to CloudSEK. The research outfit managed to… Read More "BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials"
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Ravie LakshmananSep 08, 2026Vulnerability / Web Security Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score:… Read More "Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell"
Government Updates UK’s National Risk Register with Cyber Warnings
The UK government has added several new cyber-related scenarios to its National Risk Register; some of which could theoretically result in mass casualties. The register is based on the government’s internal, classified National Security Risk Assessment, and considers malicious risks… Read More "Government Updates UK’s National Risk Register with Cyber Warnings"
Why CISOs should focus on real AI threats, not hype
Build defenses around your actual threat profile It’s vital, however, that investment decisions be made on data and the specific threat profile facing an individual organization. This is why AI proving grounds are becoming increasingly critical to the world’s leading… Read More "Why CISOs should focus on real AI threats, not hype"