Cybersecurity News
-
CrowdSec Source Code Leak Linked to TanStack Supply-Chain Attack
Cybersecurity company CrowdSec has traced the theft of private source code to a GitHub account compromised following the TanStack npm supply-chain attack earlier this year. The stolen code appeared on a breach…
-
Fake Package Delivery Messages Use Small Fees to Steal Banking Data
Fake package-delivery messages are a recurring phishing tactic in the United States and other countries, often claiming that a shipment cannot be delivered until the recipient fixes an address problem or pays…
-
Google Patches Pixel Modem Flaw Linked to Targeted Exploitation
Google has released its September 2026 security update for Pixel devices, addressing 110 vulnerabilities, including a modem flaw that may be under limited, targeted exploitation. The September 2026 Pixel Update Bulletin, published…
-
Revolut Data Disclosure Exposes Sensitive Customer Records as Phishing Attempts Follow
Revolut disclosed sensitive customer information after fraudsters successfully impersonated a government agency, exposing records that included identity documents, contact details, account statements, and transaction histories. The financial technology company says attackers did…
-
WordPress Fixes Theme Preview Flaw That Could Let Attackers Run Code on a Site
WordPress has fixed a security flaw that could allow a specially crafted link to install and preview a theme from the official WordPress.org directory without an administrator intentionally choosing to install it.…
-
Brevo Security Flaw Let Attacker Access 138 Customer Accounts
Email and marketing platform Brevo in an advisory has said an attacker gained access to 138 customer accounts after exploiting a flaw in the way its single sign-on system handled access between…
-
Microsoft Fixes Critical Security Flaws Across Azure, Copilot and Other Cloud Services
Microsoft has disclosed fixes for 18 security vulnerabilities affecting Azure, Copilot and other cloud services, including several flaws the company rates as Critical. The affected products include Azure AI Foundry, Azure Cosmos…
-
BIND 9.20.29 Fixes 14 Security Vulnerabilities Affecting DNS Servers
Internet Systems Consortium has released BIND 9.20.29 with fixes for 14 security vulnerabilities affecting the widely used DNS server software. BIND is software used by organizations, internet providers and other network operators…
-
Telegram Desktop Vulnerability Could Expose Messages Through Malicious HTML Chat Exports
A high-severity vulnerability in Telegram Desktop could allow malicious code hidden in a chat message to run when a user exports the conversation as HTML and opens the resulting file in a…
