One-time SMS links that never expire can expose personal data for years

Online services often treat one-time links sent by text message as low-risk conveniences. A new study shows that these links can expose large amounts of personal data for years. Malicious URLs continue to shift from email to SMS According to to Proofpo… Continue reading One-time SMS links that never expire can expose personal data for years

Tesla, Sony, and Alpine systems compromised on day one of Pwn2Own Automotive 2026

Security researchers uncovered 37 previously unknown vulnerabilities on the opening day of Pwn2Own Automotive 2026, earning a combined $516,500 in prize money, according to results released by Trend Micro’s Zero Day Initiative. The Master of Pwn leader… Continue reading Tesla, Sony, and Alpine systems compromised on day one of Pwn2Own Automotive 2026

Exposed training apps are showing up in active cloud attacks

Security teams often spin up vulnerable applications for demos, training, or internal testing. A recent Pentera research report documents how those environments are being left exposed on the public internet and actively exploited. The research focuses … Continue reading Exposed training apps are showing up in active cloud attacks

A new framework helps banks sort urgent post-quantum crypto work from the rest

Financial institutions now have a concrete method for deciding where post-quantum cryptography belongs on their security roadmaps. New research coordinated by Europol sets out a scoring framework that helps banks rank systems and business use cases bas… Continue reading A new framework helps banks sort urgent post-quantum crypto work from the rest

Pro-Russian hacktivist campaigns continue against UK organizations

The UK’s National Cyber Security Centre reports ongoing cyber operations by Russian-aligned hacktivist groups targeting organizations in the UK and abroad. NoName057(16) remains active In December 2025, the NCSC co signed an advisory warning that pro-R… Continue reading Pro-Russian hacktivist campaigns continue against UK organizations

Bandit: Open-source tool designed to find security issues in Python code

Bandit is an open-source tool that scans Python source code for security issues that show up in everyday development. Many security teams and developers use it as a quick way to spot risky coding patterns early in the lifecycle, especially in projects … Continue reading Bandit: Open-source tool designed to find security issues in Python code

Confusion and fear send people to Reddit for cybersecurity advice

A strange charge appears on a bank account. An email claims a package is on the way. A social media account stops accepting a password that worked yesterday. When these moments hit, many people do the same thing. They open Reddit and ask strangers for … Continue reading Confusion and fear send people to Reddit for cybersecurity advice