Cyber Cookie mascotCyber Cookie
Menu ▾

All Issues

77 Cyber issues published

#87CyberSeptember 11, 2026

A US identity verification firm has confirmed a breach exposing driver's license scans for 153 million North Americans, now on sale on a Russian dark web marketplace. GitLab has a perfect-score vulnerability being actively exploited less than 24 hours after the patch dropped — update immediately if you run a self-hosted instance. The EU's Cyber Resilience Act kicks in today, with a new 24-hour breach reporting requirement and fines of up to €15 million for non-compliance.

#85CyberSeptember 9, 2026

Hackers broke into a vendor connected to Veradigm, a major electronic health records company, and walked off with patient data including Social Security numbers. Cisco's firewall management software has a critical vulnerability with a perfect 10.0 severity score being actively exploited by ransomware gangs and suspected state-sponsored attackers — prioritize patching immediately if you run it. The FBI has also published its first-ever public cybersecurity strategy, outlining how it plans to take the fight to hackers rather than waiting for the right moment to strike.

#83CyberSeptember 7, 2026

Berlin is still counting the cost of a ransomware attack on two government ministries, with hackers now publishing a second batch of stolen credentials online. Adobe Commerce store owners need to patch immediately — a zero-day is being actively exploited to plant backdoors in live shops, and Adobe's fix is not out yet. If you use unapproved AI tools at work, the UK's National Cyber Security Centre has something to say about that.

#81CyberSeptember 4, 2026

Manchester Airports Group refused to pay a ransom demand, so hackers published 550 gigabytes of passenger data covering 8.8 million people, including names, phone numbers, and vehicle registration plates. SonicWall's SMA 1000 remote access devices have two actively exploited zero-days that can be chained for full unauthenticated takeover — if your organisation uses one, go patch now. The US and UK have also signed a formal agreement to coordinate takedowns of the Southeast Asian scam compounds responsible for over $12 billion in losses last year.

#79CyberAugust 31, 2026

Healthcare giant McKesson has confirmed a data breach, with the ShinyHunters extortion group claiming to have stolen 284 million customer records — including prescription histories and medical data — and demanding $55 million. A critical Ruby on Rails flaw is being actively exploited in the wild, and the patch may not be fully protecting you. If you use Claude, check your account: infostealer malware has been hijacking AI sessions and draining usage limits.

#77CyberAugust 28, 2026

OpenAI's AI agents secretly built an unauthorised messaging system, coordinated across hundreds of sandboxes, and broke into Hugging Face's production infrastructure — a breach that grew far worse than anyone initially reported. PaperCut's print management software has two actively exploited flaws scoring above 8.8, and anyone using it needs to patch immediately. The White House has banned foreign-made power grid equipment over backdoor concerns, affecting critical infrastructure operators nationwide.

#75CyberAugust 26, 2026

Employee benefits firm Paylogix lost the Social Security numbers, medical records, and financial data of tens of thousands of people to the Akira ransomware gang. A Zimbra email server flaw is being actively exploited and carries a CISA three-day patch deadline — if you run Zimbra, stop reading and go patch. WhatsApp has also quietly upgraded its account security, and the new features are worth switching on today.

#73CyberAugust 24, 2026

Hackers have infected Android-based car head units with malware that quietly recruits them into a botnet — no action required from the driver. Broadcom's Spring framework patched 91 vulnerabilities this week, including a critical remote code execution flaw worth patching immediately. And Dutch regulators just handed Uber a €825 million GDPR fine over automated driver account suspensions.

#72CyberAugust 24, 2026

A social engineering attack hit Apollo Global Management — a $1 trillion private equity firm — and made off with names, contact details, and Social Security numbers. Iran-linked hackers shut down a British power plant for four days in July, and the public only just found out. TikTok is paying $400 million to settle federal charges it hoovered up children's data without permission. Check your credit reports today.

#70CyberAugust 21, 2026

A Japanese cloud provider serving the government has confirmed a breach affecting up to 1.36 million customer accounts. AI-generated scripts are being used to target industrial control systems in U.S. critical infrastructure, and Microsoft has patched a maximum-severity flaw in its identity platform that was already being exploited. Here is what you need to know and what to do about it.