-
Security researchers have obtained a 153GB archive containing credentials allegedly stolen during the March LiteLLM supply-chain attack. The data reportedly links to almost 2,500 organisations, including AWS, Cisco, Samsung, Salesforce and other major companies. The LiteLLM breach archive contains cloud credentials, access tokens, AI provider keys and other sensitive data. However, exposure in the dataset…
-
Twitch has introduced a setting that lets Amazon use channel content to train generative AI models. The platform turns it on by default, so creators must opt out if they do not want to take part. The Twitch AI training setting has angered streamers who say creators should decide before a platform uses their videos,…
-
Microsoft has released security updates for the LegacyHive vulnerability, a Windows zero-day flaw that could allow a local attacker to gain administrator privileges. Tracked as CVE-2026-62832, the issue affects the Windows User Profile Service. Microsoft fixed it in the August 2026 Patch Tuesday updates after a public proof-of-concept exploit appeared shortly after July’s patches. LegacyHive…
-
A growing number of tools now claim to remove AI watermarks from text and files. However, almost none can show that they defeat Anthropic’s new invisible Claude watermark. The market emerged soon after Anthropic introduced content marking across its latest Claude models. It includes open-source projects, newly registered websites and commercial AI-detection evasion services. Yet…
-
Attackers are actively exploiting a critical VMware vCenter vulnerability to install a reverse SSH tool that provides persistent remote access to compromised systems. The VMware vCenter RCE flaw, tracked as CVE-2026-59310, affects the vCenter Syslog Server. Researchers have identified 361 affected IP addresses across 47 countries, with many victims located in Germany, the United States,…
-
Hardware wallet maker Trezor has disclosed a data breach affecting almost 14,000 customers after attackers accessed systems belonging to its shipping and logistics provider, ShipMonk. The Trezor data breach exposed customer order information, including names, email addresses, phone numbers and shipping addresses. Trezor said its own systems were not compromised and that customers’ hardware wallets…
-
The White House has directed the National Coordination Center to create a programme that could allow vetted private cybersecurity firms to carry out limited offensive cyber operations against foreign criminal groups. The new private hack-back program would operate under US government authority and target transnational organisations linked to ransomware, phishing, fraud, sextortion and impersonation scams.…
-
WhatsApp has started testing Scam Alert, a new optional security feature that warns users when an incoming message may be part of a scam. The tool runs directly on a user’s device and does not send message content to WhatsApp or Meta for analysis. The WhatsApp Scam Alert feature is currently available to a limited…
-
Security researchers have disclosed Plug and Pwn, a new attack technique that abuses Windows Plug and Play to install vulnerable vendor software and gain SYSTEM-level access. The attacks can use emulated USB devices, while one demonstration works remotely through RDP USB redirection without connecting physical hardware to the target. Windows can install vendor software as…
-
North Korean-linked Lazarus hackers exploited a Windows zero-day vulnerability to target defence, aerospace and aviation organisations in Europe and India. Microsoft patched the flaw in its August 2026 security updates after confirming that attackers had already used it in the wild. Lazarus used a Windows privilege-escalation flaw The vulnerability, tracked as CVE-2026-68820, affects the Windows…










