Private equity giant Apollo Global Management has disclosed a data breach that exposed sensitive personal information. According to a data breach notice sent to affected individuals, a social engineering attack enabled threat actors to access some of the company’s cloud… Read More "Personal Information Exposed in Apollo Global Data Breach"
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Iran-linked hackers managed to shut down a British power plant for four days in July 2026. The story was broken by the Telegraph newspaper on August 22, 2026. That it took so long to become public knowledge immediately says two… Read More "Iran-Linked Hackers Shut Down UK Power Plant for Four Days"
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Anthropic is broadening access to the cybersecurity capabilities of its advanced AI models through a mix of partner integrations, an updated Claude Security offering, a new open source funding program, and plans to expand its Cyber Verification Program. The move… Read More "Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund"
Microsoft Patches Exploited Entra ID Vulnerability
Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products, including a critical Entra ID zero-day exploited in attacks. The exploited Entra ID flaw is tracked as CVE-2026-69836, and it could have… Read More "Microsoft Patches Exploited Entra ID Vulnerability"
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers at Adversa AI discovered a new attack technique and named it Cryptographic Context Injection. They reported their findings to xAI on June 3, 2026, and attempted to coordinate disclosure on August 4 and August 10. At the time of… Read More "Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini"
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf. A secure on-premises video conferencing platform, TrueConf relies on Scalable Video Coding (SVC) to connect client applications through a dedicated… Read More "CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities"
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has named more than 40 organizations allegedly targeted in the recent campaign that exploited a vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. The vulnerability and its exploitation The exploitation of the vulnerability,… Read More "Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign"
CareCloud Data Breach Impact Grows to 3.7 Million Individuals
The recently disclosed CareCloud data breach affects more than 3.7 million individuals, far more than initially believed. The cloud-based healthcare solutions provider revealed in early July that it had detected a network intrusion in mid-March. The breach was discovered following… Read More "CareCloud Data Breach Impact Grows to 3.7 Million Individuals"
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers. The exploited bug, tracked as CVE-2026-65400, is a high-severity authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials.… Read More "Recent macOS Screen Sharing Vulnerability Exploited in Attacks"
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
Hackers started exploiting a critical vulnerability in SAP Commerce Cloud just three days after its public disclosure, according to threat intelligence organizations. The vulnerability is tracked as CVE-2026-58231 and is described as an issue involving insufficient authorization checks and input… Read More "Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure"