Analyzing 2026's most prevalent browser attack techniques - 4 in 5 ClickFix attacks are reached via search engine results. 30+ criminal device code phishing kits in the wild, up from zero last year. 90% of phishing kits generated with the help of AI. Phishing domains active for an average of 2 days before being rotated for a fresh one.
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products - A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian...
IQVIA fined $7.8 million for failing to properly anonymize health data - Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization.
The Credential Layer Is Expanding Faster Than Security Teams Can See It - Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because...
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings - A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled....
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes - Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system. "Weak authorization in...
N0n ransomware: what you need to know - N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra...
Stable Channel Update for Desktop - The Stable channel has been updated to 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Citrix NetScaler Targeted Via New Zero Day - The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government
Citrix patches NetScaler SAML zero-day exploited in attacks - Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.