Browsing Tag
Cybersecurity
67 posts
IDScan Breach Shows Why Scanned IDs Need an Expiration Date
IDScan confirmed unauthorized access to customer identity data after a dark-web service advertised more than 153 million driver’s-license records. The breach exposes a larger problem: ID-scanning systems can keep sensitive documents long after the check is finished.
Homebrew 7.0.0 Turns Mac Package Installs Into a Security Check
Homebrew 7.0.0 adds built-in vulnerability checks, a native BrewUI Mac app, stronger sandboxing, and several migration deadlines. For developers and Mac admins, the release turns package management into a security and inventory task.
EU Cyber Resilience Act Puts Product Security Teams on a 24-Hour Clock
The EU Cyber Resilience Act’s vulnerability-reporting duties start September 11, forcing makers of connected devices and commercial software to report actively exploited flaws quickly. Product teams should treat the deadline as an operational change, not a paperwork exercise.
Adobe Commerce Zero-Day Turns Online Stores Into Backdoor Targets
Adobe has issued an emergency hotfix for CVE-2026-75650, a critical Adobe Commerce and Magento Open Source flaw already exploited in the wild. Merchants should patch, confirm the hotfix, inspect for backdoors, and rotate more than the Magento encryption key.
PaperCut Zero-Days Turn Print Servers Into Remote-Access Beachheads
PaperCut NG/MF customers face an actively exploited two-flaw chain that can turn exposed print-management servers into remote-access footholds. Admins should apply Emergency Patch Release 2, restrict web access, and check for pc-app.exe child processes, deleted logs, SimpleHelp, and AnyDesk activity.
Ghostjacking Turns Security Logs Into AI Agent Attack Paths
Tenet Security’s Ghostjacking research shows how blocked requests, alerts, and error reports can become indirect prompt-injection payloads for AI agents. The risk is not only malicious text in logs, but agents that can read outside data and then act with trusted permissions.
OpenAI’s GPT-5.6-Cyber Puts Safer Hacking Behind a Trust Gate
OpenAI is giving approved defenders access to GPT-5.6-Cyber through a new Daybreak Red tier. The launch is less a general chatbot upgrade than a test of whether advanced exploit validation can be useful inside identity checks, scoped permissions, monitoring, hardware-key requirements, and human review.
N-able N-central Hotfix Turns RMM Servers Into an Incident Response Drill
N-able has released a second required hotfix for an actively exploited N-central authentication-bypass flaw. For MSPs and enterprise IT teams, the work is not only upgrading to 2026.3.1.10, but also checking Take Control sessions, Cloudflare Tunnel persistence, and downstream endpoints before treating the RMM platform as trusted again.
Rails Active Storage Flaw Turns Image Uploads Into a Secret-Rotation Drill
Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw that can let attackers turn image uploads into arbitrary file reads and possible remote code execution. For affected teams, the job is not only upgrading Rails and libvips, but checking exposure windows and rotating secrets that may have been readable by the Rails process.
Chrome’s AI Bug Surge Makes Browser Restarts a Security Deadline
Google says Chrome 149 and 150 fixed 1,072 security bugs, more than the prior 23 milestones combined, as AI-assisted vulnerability discovery accelerates. The result is a push toward twice-weekly security releases, dynamic patching, and stricter enterprise browser-restart policies.