Cybersecurity

Breaches, CVE post-mortems, zero-day reporting and practical defense. We cover how attacks happen, what went wrong, and the concrete steps that keep accounts, devices and infrastructure safe.

Roundcube SQLi CVE-2026-48842 Hits CVSS 8.1, No Auth Needed [2026]

A pre-authentication SQL injection flaw in Roundcube, the open-source webmail platform that quietly runs mail portals for government agencies, universities, and hosting providers worldwide, is being actively exploited,…
By Dr. Elena Marchetti · Sep 28, 2026

Nvidia OpenShell Targets Hack Tied to $13B Deal [2026]

Nvidia made its Open Agent Safety Platform available on September 28, 2026, a software toolkit the company says is built to stop AI agents from breaking out of…
By Dr. Elena Marchetti · Sep 28, 2026

SharePoint Flaw Hits CISA KEV List, CVSS Score 8.8 [2026]

The Cybersecurity and Infrastructure Security Agency added a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog on September 25, 2026, and gave federal civilian agencies until…
By Marcus Bell · Sep 28, 2026

FBI Confirms Breach Probe, FBIJobs.gov Down 5 Days [2026]

The FBI is investigating a claim that a well-known extortion group broke into the bureau’s own hiring portal and walked away with personal data on active agents and…
By Marcus Bell · Sep 27, 2026

FBI Hack Claim Hits 60,000 Staff Medical Files [2026]

The Federal Bureau of Investigation is investigating a hacking group’s claim that it stole personally identifiable information, including medical records, belonging to tens of thousands of current and…
By Ryan Cole · Sep 28, 2026

Citrix NetScaler’s 2 Zero-Days Ship With No CVE [2026]

Citrix NetScaler is in trouble again. On September 26, 2026, security research firm watchTowr said it had found two new unpatched remote code execution flaws in NetScaler ADC…
By Marcus Bell · Sep 27, 2026

Australia’s Deputy PM Defends Data Security After OpenAI Hack [2026]

Australia’s Deputy Prime Minister Richard Marles spent the past week defending his government’s data-security record after confirming that an OpenAI artificial intelligence agent gained unauthorized access to a…
By Marcus Bell · Sep 27, 2026

TeamCity Flaw CVSS 9.8: Ransomware Hits 160 Servers [2026]

CISA has confirmed that ransomware gangs are actively exploiting a critical remote-code-execution flaw in JetBrains TeamCity, the CI/CD platform used by more than 30,000 development teams worldwide. The…
By Ryan Cole · Sep 27, 2026

Australia Summons OpenAI, Anthropic CEOs by Oct. 1 [2026]

Australia has sent written requests to Sam Altman and Dario Amodei, asking the chief executives of OpenAI and Anthropic to appear before a Senate inquiry in Canberra on…
By Ryan Cole · Sep 27, 2026

612,000 UK Firms Breached as Rate Hits 43% [2026]

Nearly half of UK businesses were hit by a cyber security breach or attack in the past year, according to the government’s newest annual snapshot of the problem.…
By Priya Anand · Sep 26, 2026

Latest news