Stay Ahead of the Tech Curve
Breaking cybersecurity threats, technology updates, and IT industry insights, curated by our editors.
- Stories published
- 50
- Trending now
- 5
- Breaking
- Live
Wiz Red Agent Breaches Snowflake’s Internal Jira Through a GitHub Actions Flaw Missed by Security Scanning
Wiz says its autonomous Red Agent discovered and exploited a GitHub Actions injection in a Snowflake repository just five days after the flaw went live, reaching internal Jira data during controlled testing.
NewTrendingWiz Red Agent Breaches Snowflake’s Internal Jira Through a GitHub Actions Flaw Missed by Security Scanning
Wiz says its autonomous Red Agent discovered and exploited a GitHub Actions injection in a Snowflake repository just five days after the flaw went live, reaching internal Jira data during controlled testing.
TrendingHackers Raid French Tax Systems, Exposing Data of Nearly 900,000 Accounts
Hackers breached French tax and land registry systems in separate attacks, exposing data linked to at least 678,000 individuals and professional accounts, plus 200,000 land registry accounts.
TrendingNew DRAM Scrambling Attack Challenges CPU Memory Security Boundaries
Security researcher Christopher Domas has demonstrated a DRAM scrambling technique on AMD Family 16h processors that can remap physical memory addresses and expose protected memory regions beneath conventional CPU security boundaries.
TrendingApple Explains Its Threat Notifications for Mercenary Spyware Targets
Apple says its threat notifications are high-confidence warnings for users individually targeted by mercenary spyware. The company explains how alerts are delivered, how to verify them, and what users should do next.
TrendingCity-Forum Campaign Targets Salesforce and ServiceNow Guest Access
A long-running campaign is targeting Salesforce Experience Cloud and ServiceNow portals by abusing overly permissive guest access. Reco says the activity uses custom tooling to enumerate exposed data across organisations worldwide.
TrendingWordPress 7.0.4 Fixes High-Risk Imagick RCE Vulnerability Through Malicious File Uploads
WordPress 7.0.4 addresses CVE-2026-65640, an authenticated remote code execution vulnerability involving Imagick and Ghostscript. Administrators are urged to update, particularly on sites with multiple users who can upload files.
TrendingWindRelay and SpyNote Combine in a New NFC Payment Fraud Scheme
Group-IB has uncovered WindRelay, an NFC relay malware used with SpyNote RAT in a social-engineering campaign that combines Android remote access with fraudulent card transactions.
TrendingCisco Firewall Zero-Day CVE-2026-20349 Exploited in the Wild
Cisco has confirmed active exploitation of a high-severity vulnerability in its Secure Firewall ASA and FTD software that can let unauthenticated attackers remotely force affected devices to reload, causing denial of service.
TrendingGoogle Cloud Sets 2029 Target for Post-Quantum Cryptography Readiness
Google Cloud has outlined a roadmap to achieve full post-quantum cryptography readiness by 2029, with major milestones across encryption, digital signatures, identity, key management, and cloud infrastructure.
TrendingNorth Korean Hackers Build AI Tools to Support Cyberattacks, Report Says
A Genians report says North Korea-linked Kimsuky has built local AI capabilities that could support cyberattack automation, stolen-data analysis, malware development and more convincing phishing campaigns.
TrendingMinterEllison Cyber Risk 2026: AI Is Changing How Organisations Face Attacks
MinterEllison's 2026 cyber risk report finds that AI is reshaping attacks, defence and governance, while supplier exposure and incident preparedness remain major concerns for organisations.
TrendingOpenAI Raises Security Controls as Astra Approaches Critical Cyber Capability Threshold
OpenAI says preliminary evaluations of its upcoming Astra model show major advances in agentic coding and cybersecurity, prompting stronger safeguards as the company assesses whether it may reach the Critical threshold.