Infosecurity News

NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks

N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion

Multiple Class Action Lawsuits Filed Against IDScan
Several victims of a recent breach of driver’s license information have sued the company they believe responsible

Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges

OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential Services
OpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructure

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules
The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploit

Outsider Phishing Kit Survives Takedown With 700 New Pages
Outsider phishing kit generated 700 new pages after a Google-led disruption

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers

US and Canadian Court Records Breached Following Thomson Reuters Incident
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US

FBI Probes Possible Breach of 153 Million Driver’s Licenses
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

International Operation Disrupts Sality P2P Botnet
US-led action sinkholes machines caught up in Sality botnet

Russian Man Extradited Over Malware Campaign Targeting Freelancers
Russian man extradited to US over malware campaign that targeted 80,000 freelance users

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third party

Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild

FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Threat group FulcrumSec claims MAG breach and leaks 550GB of data online

Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000



