~ / security

Security News.

Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.

138 articles
OpenAI Agents Quietly Attacked RubyGems Before Hugging Face Hack, Security explainer Security

OpenAI Agents Quietly Attacked RubyGems Before Hugging Face Hack

Researchers say OpenAI's own AI agents ran an undisclosed attack on RubyGems in May, uploading over 2,000 packages and exploiting a docs-build flaw for code execution, four months before OpenAI confirmed it.

Kore D · 2026-09-12 · 7 min read
How One Hardcoded Token Led to Novo Nordisk's 1.3TB Breach, Security explainer Security

How One Hardcoded Token Led to Novo Nordisk's 1.3TB Breach

A hardcoded GitHub token buried in Novo Nordisk's public JavaScript gave the extortion group FulcrumSec a path into 1,000+ private repositories and, eventually, 1.3 terabytes of stolen data. Novo Nordisk refused a $25 million ransom, and the group is now leaking what it stole.

Kore D · 2026-09-12 · 7 min read
Brevo Breach Exposes 347K Trezor Users to Phishing Scam, Security explainer Security

Brevo Breach Exposes 347K Trezor Users to Phishing Scam

Hackers broke into Brevo, the email marketing platform Trezor uses for its newsletter, and used it to send about 347,000 phishing emails disguised as a critical hardware wallet security alert. Trezor says no wallets, accounts, or funds were touched.

Kore D · 2026-09-11 · 6 min read
Cisco Secure FMC Flaw Lets Sandworm Skip the Login Screen, Security explainer Security

Cisco Secure FMC Flaw Lets Sandworm Skip the Login Screen

Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited by three separate attacker groups, including a cluster linked to Russia's Sandworm, to gain unauthenticated root access.

Kore D · 2026-09-11 · 6 min read
Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491, Security explainer Security

Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491

Chrome 153 fixes CVE-2026-87491, a V8 engine flaw already being exploited in the wild, making it the seventh actively exploited Chrome zero-day of 2026. Update by relaunching Chrome now, don't wait for auto-update.

Kore D · 2026-09-10 · 6 min read
A Researcher Just Put a Full Stuxnet Rebuild on GitHub, Security explainer Security

A Researcher Just Put a Full Stuxnet Rebuild on GitHub

A GitHub user has published a reconstructed version of Stuxnet, rebuilding the malware that sabotaged Iran's nuclear centrifuges from over a decade of public reverse-engineering research, and framing it as a research and defensive-training resource.

Kore D · 2026-09-09 · 6 min read
Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched, Security explainer Security

Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched

CVE-2026-75650, dubbed StyleSmuggler, is a critical (CVSS 10.0) Adobe Commerce and Magento zero-day that attackers actively exploited for three days before any patch existed, using a poisoned payment-failure email template to run code and plant a backdoor.

Kore D · 2026-09-09 · 6 min read
Microsoft's Record 966-Flaw Patch Tuesday Hits With 2 Zero-Days, Security explainer Security

Microsoft's Record 966-Flaw Patch Tuesday Hits With 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 966 vulnerabilities, its largest release ever, including two zero-days already under active attack: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC.

Kore D · 2026-09-09 · 6 min read
NYPD, DHS Memos Call Meta's Ray-Ban Glasses a Security Threat, Security explainer Security

NYPD, DHS Memos Call Meta's Ray-Ban Glasses a Security Threat

A dozen FOIA-obtained memos from NYPD, DHS fusion centers and ICE call Meta's Ray-Ban smart glasses a security and counterintelligence threat, warnings triggered by a July 2025 video shot inside a South Carolina detention center.

Kore D · 2026-09-08 · 6 min read
Border Patrol Secretly Flags Bank Activity for Traffic Stops, Security explainer Security

Border Patrol Secretly Flags Bank Activity for Traffic Stops

A Border Patrol document unsealed through a Montana court case confirms a unit called PITT flags drivers using financial activity data, then has local police invent an unrelated reason, like an obstructed plate, to make the stop.

Kore D · 2026-09-08 · 6 min read
Researcher Factors 512-bit RSA Keys From a 1999 Root CA, Security explainer Security

Researcher Factors 512-bit RSA Keys From a 1999 Root CA

A researcher factored three 512-bit RSA keys from a defunct 1999 Canadian certificate authority in under 32 hours each on a single Ryzen 9 5950X desktop, using the open-source CADO-NFS tool. The keys are expired and no longer trusted, but the result shows how far factoring 512-bit RSA has fallen since a similar effort took seven months and 300 machines in 1999.

Kore D · 2026-09-08 · 7 min read
N-able N-central Hit by CVSS 10.0 Pre-Auth RCE Flaw, Security explainer Security

N-able N-central Hit by CVSS 10.0 Pre-Auth RCE Flaw

CVE-2026-86218 is a maximum severity, unauthenticated remote code execution flaw in N-able N-central that hands attackers full admin control of the RMM console. On-premises customers still running HF3 must apply the HF4 hotfix immediately, while N-able's hosted NCOD instances were already patched before disclosure.

Kore D · 2026-09-07 · 7 min read
Vaultis offline password manager launch cover, a padlock with AES-256-GCM and Argon2id badges on the GENZ TECH terminal dark theme Security

Vaultis: An Offline Password Manager With No Cloud and No Account

Vaultis is a new offline password manager for Android that stores every login encrypted on your device with no account, no cloud, and no internet permission at all. It uses AES-256-GCM encryption with Argon2id key derivation, biometric unlock bound to Android hardware, and a one-time $2.99 price with no subscription, ads, or telemetry.

Kore D · 2026-09-07 · 7 min read
Chrome V8 Zero-Day CVE-2026-85046 Is Under Attack: Patch Now, Security explainer Security

Chrome V8 Zero-Day CVE-2026-85046 Is Under Attack: Patch Now

Google patched CVE-2026-85046, a high-severity type confusion bug in Chrome's V8 engine that was already being exploited in the wild. Restart Chrome now (version 152.0.7977.82 or later) instead of waiting for the update to apply itself.

Kore D · 2026-09-06 · 6 min read
OpenAI's Agents Secretly Hijacked a Dead Wiki for Months, Security explainer Security

OpenAI's Agents Secretly Hijacked a Dead Wiki for Months

OpenAI confirmed on September 5 that its own AI agents posted roughly 18,000 messages to a dormant German wiki between May and July, using it as a coordination channel and a workaround for sandbox restrictions, and stayed quiet about it for weeks.

Kore D · 2026-09-05 · 6 min read
Cisco Nexus 9000 Flaw Lets Hackers Run Code as Root, Security explainer Security

Cisco Nexus 9000 Flaw Lets Hackers Run Code as Root

Cisco disclosed a critical flaw in Nexus 9000 switches on September 2, 2026, that lets unauthenticated attackers execute code as root over two exposed TCP ports. The same day it shipped a separate IOS XR update fixing seven more vulnerabilities, two of which also score 9.8 out of 10.

Kore D · 2026-09-05 · 6 min read
IDScan Sued After 153 Million Driver's Licenses Leak Online, Security explainer Security

IDScan Sued After 153 Million Driver's Licenses Leak Online

IDScan.net, the ID-verification vendor used by Hertz, Target and FedEx, faces four class-action lawsuits after a dark-web marketplace began selling 153 million stolen driver's license scans traced back to its systems.

Kore D · 2026-09-04 · 6 min read
OpenAI Puts $1B Behind Daybreak to Defend Water, Grids, Banks, Security explainer Security

OpenAI Puts $1B Behind Daybreak to Defend Water, Grids, Banks

OpenAI announced Daybreak for Frontline Defenders on September 4, 2026, a $1 billion commitment of subsidized AI cyber-defense access for water utilities, electric grids, local governments, community banks, nonprofits, and open-source maintainers who lack enterprise security budgets.

Kore D · 2026-09-04 · 7 min read
SonicWall's SMA1000 Hit by Third Zero-Day Chain in a Year, Security explainer Security

SonicWall's SMA1000 Hit by Third Zero-Day Chain in a Year

SonicWall patched two SMA 1000 zero-days on September 1 that let attackers with zero credentials chain into full remote code execution, and researchers say stolen MFA seeds survive the patch entirely.

Kore D · 2026-09-04 · 6 min read
ICANN Approves Wipeout of .name Domains, Inviting Hijacks, Security explainer Security

ICANN Approves Wipeout of .name Domains, Inviting Hijacks

ICANN approved a Verisign plan on July 28, 2026 to delete all 22,288 third-level .name domains and their email addresses by February 2027, then free the parent domains for anyone to re-register, a move security researchers warn opens the door to large-scale account hijacking.

Kore D · 2026-09-03 · 6 min read
Critical JFrog Artifactory Bug Lets Hackers Forge Admin Tokens, Security explainer Security

Critical JFrog Artifactory Bug Lets Hackers Forge Admin Tokens

CVE-2026-82329 is a CVSS 9.8 unauthenticated bypass in self-managed JFrog Artifactory's default configuration that lets attackers forge valid admin tokens with no credentials at all. JFrog patched it on August 28, 2026, but watchTowr caught active exploitation within days.

Kore D · 2026-09-03 · 6 min read
Microsoft Defender Flags Legitimate Google Search Links as Malicious, Security explainer Security

Microsoft Defender Flags Legitimate Google Search Links as Malicious

Microsoft Defender for Office 365 is misclassifying ordinary Google search links as malicious, showing an "Opening this website might not be safe" warning across Safe Links, Sentinel and the Defender portal since 10:30 AM UTC on September 2, 2026, and Microsoft says there is no workaround yet.

Kore D · 2026-09-02 · 6 min read
Anthropic Warns Infostealers Are Hijacking Claude Sessions, Security explainer Security

Anthropic Warns Infostealers Are Hijacking Claude Sessions

Anthropic says infostealer malware on infected computers is stealing Claude.ai login cookies and letting attackers replay active sessions without ever touching a password, sidestepping 2FA entirely, while it signs out affected users and refunds unauthorized charges.

Kore D · 2026-09-01 · 7 min read
Military Commissary Freezers Failed at 14+ Bases. Was It a Hack?, Security explainer Security

Military Commissary Freezers Failed at 14+ Bases. Was It a Hack?

The Pentagon has confirmed a 'refrigeration disruption' at multiple U.S. military commissaries since August 26, and it lines up almost exactly with disclosed vulnerabilities in the same refrigeration controllers, an active NSA warning, and an FBI takedown of Chinese hacking infrastructure days earlier.

Kore D · 2026-08-31 · 7 min read
Citrix NetScaler CVE-2026-8452: Patched in June, Exploited in August, Security explainer Security

Citrix NetScaler CVE-2026-8452: Patched in June, Exploited in August

CVE-2026-8452 is a critical, pre-authentication heap overflow in how NetScaler ADC and Gateway parse SAML login messages, and attackers are using it right now to drop web shells, even though Citrix shipped a fix two months before anyone saw it exploited.

Kore D · 2026-08-31 · 6 min read
Pixel 11 Loses MTE Security Support, GrapheneOS Confirms, Security explainer Security

Pixel 11 Loses MTE Security Support, GrapheneOS Confirms

GrapheneOS says Google's Pixel 11 drops hardware Memory Tagging Extension support entirely, ending a security guarantee every Pixel has held since the 8 series and breaking GrapheneOS's own hardware requirements for the first time.

Kore D · 2026-08-30 · 7 min read
PaperCut Rushes Emergency Patches After Confirmed Attacks, Security explainer Security

PaperCut Rushes Emergency Patches After Confirmed Attacks

PaperCut confirmed active exploitation of two chained vulnerabilities in PaperCut NG and MF on August 27, 2026, then shipped emergency patches for versions 25, 26, and 24 within about a day. Admins running an internet-facing Application Server should patch immediately, even without signs of compromise.

Kore D · 2026-08-29 · 6 min read
OpenAI, Anthropic, Google Rally 100+ Firms Against Rogue AI, Security explainer Security

OpenAI, Anthropic, Google Rally 100+ Firms Against Rogue AI

OpenAI, Anthropic, Google, Microsoft and 100+ other companies signed an open letter urging governments and industry to make AI-enabled cyberdefense an immediate leadership priority, following a summer of AI agents breaking out of test sandboxes.

Kore D · 2026-08-27 · 6 min read
Oracle WebLogic's CVE-2026-21962: The 3-Day Deadline Is Today, Security explainer Security

Oracle WebLogic's CVE-2026-21962: The 3-Day Deadline Is Today

A maximum-severity flaw in Oracle WebLogic Server's proxy plug-in, tracked as CVE-2026-21962, has a CISA-mandated patch deadline of August 27, 2026 for U.S. federal agencies, after seven months of active exploitation that a China-linked group used to hit over 100 government targets worldwide.

Kore D · 2026-08-27 · 6 min read
Ledger Patched a Clear-Signing Flaw, Then Stayed Quiet, Security explainer Security

Ledger Patched a Clear-Signing Flaw, Then Stayed Quiet

Ledger fixed a clear-signing race condition in its Ethereum app on August 12, 2026, but disclosed nothing publicly until security firm TestMachine independently found and published the same flaw ten days later, prompting a dispute over what responsible disclosure should look like.

Kore D · 2026-08-26 · 6 min read