Feeds last updated @: UTC - 05:45 - 18/07/2026
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
https://www.theregister.com/security
https://hackread.com/ttf-trap-phishing-fake-font-files-windows-malware/
https://hackread.com/two-scattered-spider-members-sentenced-tfl-cyberattack/
https://hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/
https://hackread.com/fake-celine-dion-paris-tickets-facebook-ticketmaster-clones/
WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forgery. This vulnerability appears as CVE-2026-16194. The attack may be performed from remote. In addition, an exploit is available. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.tarteaucitron.cookie.purge of the file tarteaucitron.js of the component Cookie. Performing a manipulation results in cookie without 'httponly' flag. This vulnerability is reported as CVE-2026-49977. The attack is possible to be carried out remotely. No exploit exists.https://www.debian.org/security/
https://msrc.microsoft.com/update-guide/vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15905
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15904
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15903
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15902
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15901
https://www.ncsc.nl/nieuws/dora-horjus-programmamanager-house-of-cyber-bij-ncsc
https://www.ncsc.nl/alerts/beveilig-je-ip-cameras-om-spionage-van-statelijke-actoren-te-voorkomen
https://www.ncsc.nl/nieuws/cbw-en-wwke-vanaf-15-augustus-2026-van-kracht
https://www.ncsc.nl/nieuws/versie-21-van-stix-en-taxii-per-1-juli-2026-verplicht-voor-de-overheid
https://www.ncsc.nl/expertblogs/wissel-effectiever-dreigingsinformatie-uit-met-stixtaxi-21
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2400
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2399
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2398
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2397
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2396
https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html
https://techrepublic.com/topic/security
23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people.
The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach appeared first on TechRepublic.
https://www.techrepublic.com/article/news-23andme-18-million-settlement-2023-genetic-data-breach/
Microsoft is reportedly developing Project Perception, a lower-cost AI security tool that would use multiple models to identify enterprise vulnerabilities.
The post Microsoft’s ‘Project Perception’ Could Challenge Anthropic’s Mythos in AI Security appeared first on TechRepublic.
https://www.techrepublic.com/article/news-microsoft-project-perception-ai-security-tool/
Zoom patched a critical Windows flaw that could enable remote account takeover, along with three high-severity privilege-escalation vulnerabilities.
The post Critical Zoom Flaw Could Let Attackers Take Over Windows Accounts appeared first on TechRepublic.
https://www.techrepublic.com/article/news-zoom-windows-account-takeover-vulnerability/
The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.
The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic.
https://www.techrepublic.com/article/news-fcc-phone-identity-verification-burner-phone-proposal/
Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims.
The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.
https://www.techrepublic.com/article/news-apple-hide-my-email-privacy-lawsuit/
https://www.bleepingcomputer.com/
https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/
https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/
https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/
https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/
"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the
How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with
I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's often attributed back to me, I'll relay it here regardless:
Trying to delete yourselfhttps://www.troyhunt.com/swimming-pools-pee-and-trying-to-delete-your-data-from-the-internet/
How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and to make it
I know enough about home cinema audiovisual to know there's a lot I don't know. It's conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the topic. That's not to sound derogatory (it's
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Really interesting piece of cryptographic history:
In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away...
https://www.schneier.com/blog/archives/2026/07/details-of-alan-turings-voice-encryption-system.html
Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective.
https://www.schneier.com/blog/archives/2026/07/protecting-privacy-in-an-ai-era.html
Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature.
We are one step closer to 1984 technology:
The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment...
https://www.schneier.com/blog/archives/2026/07/a-video-screen-that-is-also-a-camera.html
This is a current list of where and when I am scheduled to speak:
https://www.schneier.com/blog/archives/2026/07/upcoming-speaking-engagements-58.html