Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia

Rogue OpenAI agents made unauthorized edits on Wikimedia wikis and sent millions of automated requests to Wikimedia’s public APIs, traffic that may have contributed to a partial outage of the Wikidata Query Service in May, the Wikimedia Foundatio… Continue reading Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia→

Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)

Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned. About CVE-2026-21589 CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all … Continue reading Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)→

Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. DSU is a tool used by enterprise IT administrators to app… Continue reading Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)→

Data breach at Denmark’s population register exposes 8.8 million people

A data breach at Denmark’s Central Population Register (CPR) has exposed the personal information of 8.8 million people. These include people living in Denmark, deceased people and citizens who have moved abroad. The CPR is Denmark’s nation… Continue reading Data breach at Denmark’s population register exposes 8.8 million people→

Fake brand discounts on social media prey on shoppers’ fear of missing out

Cybercriminals are using fake discounts posted on Facebook and TikTok to lure shoppers to phishing sites that steal their payment card details and one-time passwords, Group-IB has warned. The phishing kit called Milk Dragon (also known as NaiLong) has … Continue reading Fake brand discounts on social media prey on shoppers’ fear of missing out→

Detained ShinyHunters hacker reportedly helping FBI track down fellow members

A suspected ShinyHunters member known as Rey has been detained in Jordan and is reportedly helping the FBI track down the rest of the group. Reuters reports that Jordanian authorities detained Saif al-Din Khader, alias Rey, last week, with two of its t… Continue reading Detained ShinyHunters hacker reportedly helping FBI track down fellow members→

AI slop submissions force Google to freeze its open-source bug bounty

Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of invalid, AI-generated submissions swamped the engineers and open source maintainers who review them…. Continue reading AI slop submissions force Google to freeze its open-source bug bounty→

How RMM abuse gives attackers a way in that looks like business as usual

Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. The security company also ranked 11 attack tactics by how often it sees them an… Continue reading How RMM abuse gives attackers a way in that looks like business as usual→

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data A flaw in Titan, an internal Microsoft analytics se… Continue reading Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited→

AI is giving attackers a head start, Microsoft warns

Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the ben… Continue reading AI is giving attackers a head start, Microsoft warns→