IDScan confirms breach after 153 million driver’s licenses leak on dark web

Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. The Louisiana-based firm, w… Continue reading IDScan confirms breach after 153 million driver’s licenses leak on dark web

Attackers call employees’ personal phones to break into Microsoft 365 accounts

Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Micros… Continue reading Attackers call employees’ personal phones to break into Microsoft 365 accounts

Fake GTA 6 download delivers malware-packed bundle to impatient gamers

Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early. Th… Continue reading Fake GTA 6 download delivers malware-packed bundle to impatient gamers

Cybercriminals are building phishing pages that exist only inside victims’ browsers

A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page fro… Continue reading Cybercriminals are building phishing pages that exist only inside victims’ browsers

OpenSSL’s new alpha build speeds up post-quantum crypto

The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a vers… Continue reading OpenSSL’s new alpha build speeds up post-quantum crypto

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle

A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. fed… Continue reading $245 million in stolen crypto funded racketeering crew’s lavish lifestyle

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s prima… Continue reading Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory… Continue reading Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Threat actors are giving AI agents a bigger role in cyberattacks

AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The re… Continue reading Threat actors are giving AI agents a bigger role in cyberattacks

IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the activi… Continue reading IT help-desk vishing tricks executives into handing over Microsoft 365 access