Threats & incidents
-
Police reveal route into Odido breach
Dutch investigators say an attacker impersonated Odido’s IT department, captured an employee’s credentials and verification code, and gained access to data belonging to more than six million customers.
-
Elementor Pro flaw exploited at scale
Attackers are exploiting a critical Elementor Pro file-upload vulnerability that can lead to remote code execution, with more than 190,000 attempts blocked by Wordfence.
-
Knight Office steals Microsoft 365 sessions
Huntress has documented a Microsoft 365 phishing kit that steals authenticated sessions and can establish persistence through unauthorised Entra device registration.
-
Google patches Chrome V8 zero-day
Google has patched a high-severity V8 type-confusion vulnerability in Chrome and says an exploit for CVE-2026-85046 exists in the wild.
-
Magento zero-day exploited against live stores
Security researchers say attackers are exploiting an unpatched Magento and Adobe Commerce zero-day capable of unauthenticated remote code execution across current platform versions.
-
MEPs seek Serbia consequences over spyware
Twenty-nine European lawmakers are pressing Brussels to slow Serbia’s EU accession and freeze some funding after researchers documented a major wave of spyware targeting political and civil-society figures.
-
MikroTik flaws exploited against internet-facing routers
CERT Polska has disclosed six RouterOS vulnerabilities and confirmed active attacks using a two-flaw chain to take control of MikroTik devices exposed over SSH.
-
Berlin centralises response after stolen data published
Berlin has created a central unit to assess stolen government data after files taken in its recent cyberattack were published following an unsuccessful extortion attempt.
-
Kali365 abuses Microsoft authentication for account access
Kali365 phishing campaigns are abusing legitimate Microsoft authentication processes to obtain sessions and tokens, reducing the value of familiar warning signs around fake login pages and password theft.
-
Link11 sees fewer but heavier DDoS attacks
Link11 recorded fewer DDoS attacks against its European customer network in early 2026, but peak bandwidth, packet rates, and cumulative attack traffic all increased sharply.










