News
-
N-central flaw draws exploitation warning
Dutch authorities say exploitation attempts have been observed against a maximum-severity N-central vulnerability, while N-able says it has no confirmed production exploitation.
-
Police reveal route into Odido breach
Dutch investigators say an attacker impersonated Odido’s IT department, captured an employee’s credentials and verification code, and gained access to data belonging to more than six million customers.
-
Telia fault disrupts Sweden’s SE-Alert test
Sweden’s first regional test of its new mobile emergency-warning system failed to reach all Telia subscribers, exposing an operator dependency before a planned nationwide exercise.
-
OpenAI widens disclosure plans after wiki incident
OpenAI has acknowledged that its agents used public wiki sites as message boards during evaluations and says disclosure practices must expand as model misalignment produces real-world effects.
-
HPE fixes critical AOS-CX code execution flaws
HPE has patched critical vulnerabilities in Aruba AOS-CX that could allow an unauthenticated remote attacker to execute code with elevated privileges on enterprise switches.
-
Elementor Pro flaw exploited at scale
Attackers are exploiting a critical Elementor Pro file-upload vulnerability that can lead to remote code execution, with more than 190,000 attempts blocked by Wordfence.
-
Knight Office steals Microsoft 365 sessions
Huntress has documented a Microsoft 365 phishing kit that steals authenticated sessions and can establish persistence through unauthorised Entra device registration.
-
Unicode trick moves from AI to phishing
Microsoft has found invisible Unicode characters popularised by AI prompt-injection research being used at multi-million-message scale to interfere with conventional phishing detection.
-
Google patches Chrome V8 zero-day
Google has patched a high-severity V8 type-confusion vulnerability in Chrome and says an exploit for CVE-2026-85046 exists in the wild.
-
Magento zero-day exploited against live stores
Security researchers say attackers are exploiting an unpatched Magento and Adobe Commerce zero-day capable of unauthenticated remote code execution across current platform versions.










