- Microsoft: AI Cuts Post-Compromise Attack Time to Minuteson October 2, 2026 at 2:15 pm
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks
- Police Target KillSec Ransomware Group with Arrests and Seizureson October 2, 2026 at 9:20 am
Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects
- Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosureon October 2, 2026 at 8:25 am
The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days
- Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitationon October 1, 2026 at 2:17 pm
Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges
- China-Linked Hackers Impersonate AI Experts to Target US Policy Insiderson October 1, 2026 at 2:00 pm
TA419 posed as AI policymakers and economists to phish US AI policy experts’ Microsoft 365 accounts
Hacks – Threatpost The First Stop For Security News
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- iPhone Users Urged to Update to Patch 2 Zero-Daysby Elizabeth Montalbano on August 19, 2022 at 3:25 pm
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
- APT Lazarus Targets Engineers with macOS Malwareby Elizabeth Montalbano on August 17, 2022 at 3:07 pm
The North Korean APT is using a fake job posting for Coinbase in a cyberespionage campaign targeting users of both Apple and Intel-based systems.
- Black Hat and DEF CON Roundupby Threatpost on August 15, 2022 at 1:56 pm
‘Summer Camp’ for hackers features a compromised satellite, a homecoming for hackers and cyberwarfare warnings.
- New Hacker Forum Takes Pro-Ukraine Stanceby Elizabeth Montalbano on August 11, 2022 at 3:14 pm
A uniquely politically motivated site called DUMPS focuses solely on threat activity directed against Russia and Belarus
Mobile Security – Threatpost The First Stop For Security News
- iPhone Users Urged to Update to Patch 2 Zero-Daysby Elizabeth Montalbano on August 19, 2022 at 3:25 pm
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
- Xiaomi Phone Bug Allowed Payment Forgeryby Nate Nelson on August 16, 2022 at 12:26 pm
Mobile transactions could’ve been disabled, created and signed by attackers.
- Google Boots Multiple Malware-laced Android Apps from Marketplaceby Elizabeth Montalbano on July 18, 2022 at 12:32 pm
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.
- Leaky Access Tokens Exposed Amazon Photos of Usersby Nate Nelson on June 29, 2022 at 8:18 pm
Hackers with Amazon users’ authentication tokens could’ve stolen or encrypted personal photos and documents.
- Google Warns Spyware Being Deployed Against Android, iOS Usersby Elizabeth Montalbano on June 24, 2022 at 11:02 am
The company is warning victims in Italy and Kazakhstan that they have been targeted by the malware from Italian firm RCS Labs.
Krebs on Security In-depth security news and investigation
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigationby BrianKrebs on September 28, 2026 at 3:08 pm
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortionsby BrianKrebs on September 25, 2026 at 9:44 pm
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
- Data Broker Radaris Loses Domains in Privacy Fightby BrianKrebs on September 16, 2026 at 6:14 pm
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.
- Microsoft Plugs Nearly 1,000 Security Holesby BrianKrebs on September 8, 2026 at 9:44 pm
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
- FBI Probes Service Selling 153M+ Drivers Licensesby BrianKrebs on September 1, 2026 at 10:40 pm
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.














