Berlin Refuses to Pay Hackers After Government Network Attack

Berlin Tells Cyber Extortionists: “We’re Not Paying!” Berlin’s state government has confirmed it is facing an extortion attempt following the compromise of its administrative network, and officials have made one part of their response very clear. They’re not paying. Investigators discovered additional data had been removed from systems belonging to Berlin’s Senate Department for Mobility, […]

Read More

Five Critical WordPress Flaws Put Websites at Risk

Five WordPress Security Problems You Don’t Want to Ignore Everyone and their dog has created a website using WordPress (even us!), but that doesn’t mean its inheritently secure. WordPress administrators have been handed another compelling reason to check the updates page. Security researchers have disclosed five critical WordPress vulnerabilities affecting WPMU DEV Dashboard, Avada, TranslatePress, […]

Read More

Fire Ant Hijacks Cisco Routers and Hides the Evidence

Fire Ant Moves Into the Network’s Best Seat Fire ant, a China-linked cyber espionage operation, not the insects have been targeting some of the most trusted equipment inside corporate networks, including Cisco routers and authentication servers. And controlling the router is rather more useful to an attacker than compromising another laptop. Investigators from Sygnia discovered […]

Read More

Russian Threat Group ‘UAC-0099’ Uses Malware to Trick AI Security Tools

Hackers Are Now Trying to Scare the AI Cyber attackers have found another unusual way to hide malware: convincing the artificial intelligence analysing it that it would rather not look. Russia-aligned threat group UAC-0099 has been observed using a technique researchers have named GuardBreaker. Instead of simply attempting to hide malicious code through encryption or […]

Read More

Cisco SD-WAN Manager Flaw

Cisco SD-WAN Manager Flaw: Medium Severity, Real Exploitation Cisco has released security updates for an actively exploited vulnerability in Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. The flaw, CVE-2026-20262, has a CVSS score of 6.5, so on paper it sits in the “medium” category. However, “medium” becomes a lot more interesting when attackers are […]

Read More

Joomla JCE Flaw Actively Exploited

Joomla JCE Flaw: Patch It, Then Check You Weren’t Already Hit CISA has warned that a critical Joomla Content Editor vulnerability is being actively exploited. The flaw, CVE-2026-48907, carries the maximum CVSS score of 10.0, which is never the sort of score you want next to your CMS plugin. The issue affects Widget Factory Joomla […]

Read More

Microsoft Defender Needs a Defender

Microsoft Confirms RoguePlanet Defender Zero-Day Microsoft confirmed it is developing a patch for RoguePlanet, a Microsoft Defender zero-day now tracked as CVE-2026-50656 with a CVSS score of 7.8. The vulnerability is an elevation-of-privilege flaw in the Microsoft Malware Protection Engine. A researcher known as Chaotic Eclipse released a proof-of-concept, describing the issue as a race […]

Read More

F5 Patches Critical NGINX Flaws

NGINX Critical Flaws: Patch Before Your Web Server Starts Freelancing F5 released patches for two critical NGINX Open Source vulnerabilities that could enable remote code execution. CVE-2026-42530 is a use-after-free issue in the HTTP/3 QUIC module affecting certain configurations. CVE-2026-42055 is a heap-based buffer overflow affecting HTTP/2 proxying or gRPC configurations with specific directives. Both […]

Read More

Shadow AI and Access Control

Shadow AI: It’s Not Just What Staff Paste In, It’s What Agents Can Do Shadow AI has evolved beyond data leakage. The real risk is now access control, because AI agents can call APIs, use credentials, access SaaS platforms, modify data and trigger workflows. Many agents are created informally through SaaS tools, browser extensions, developer […]

Read More