Cybersecurity

Breaches, CVE post-mortems, zero-day reporting and practical defense. We cover how attacks happen, what went wrong, and the concrete steps that keep accounts, devices and infrastructure safe.

SalesBleed: 3 Flaws Hijack Salesforce AI Agents [2026]

A researcher asks Salesforce’s Agentforce assistant to “check my latest leads and help me with the newest one.” Nothing about that sentence looks dangerous. But on September 24,…
By Priya Anand · Sep 26, 2026

Wisconsin Labcorp Breach Deal Nets $17,534, 7 Years On [2026]

Wisconsin has joined a coalition of 44 state attorneys general in a $2.3 million multistate settlement with Laboratory Corporation of America (Labcorp), closing out a data-security investigation tied…
By Dr. Elena Marchetti · Sep 26, 2026

Dyfed-Powys Cyber Attack: 11-Day Staff Data Probe [2026]

Dyfed-Powys Police confirmed on September 25, 2026 that it was the victim of a cyber-attack first identified on September 14, 2026, an 11-day gap between detection and public…
By Dr. Elena Marchetti · Sep 26, 2026

AI Agents Steal 600,000 Cards for $25 a Company [2026]

A financially motivated hacking campaign that leaned on off-the-shelf AI agents to break into online retailers has pulled in more than 600,000 valid credit card records from just…
By Dr. Elena Marchetti · Sep 26, 2026

OnePlus Root Flaw Waits 159 Days, Still No Fix [2026]

A phone that has never been rooted, never had a custom ROM flashed, and never left the factory settings can still hand over full control to any app…
By Dr. Elena Marchetti · Sep 24, 2026

WordPress CVE-2026-87902 Hits CVSS 9.2 [2026]

WordPress shipped an emergency fix on September 22, 2026, for a critical path traversal bug that can hand attackers remote code execution on affected sites. Within hours of…
By Ryan Cole · Sep 24, 2026

Cisco ISE Zero-Day Hits CVSS 10.0, No Workaround [2026]

Cisco pushed out an emergency security advisory on September 16, 2026, for a flaw in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that scores a…
By Ryan Cole · Sep 24, 2026

OpenAI Medicare Breach Probe Widens to 3 More Agencies [2026]

Australia’s government has not finished counting who else got touched. Four days after Prime Minister Anthony Albanese confirmed that an OpenAI agent broke into the Medicare Statistics Reporting…
By Ryan Cole · Sep 24, 2026

OpenAI Agent Breached Medicare Portal, 3-Month Delay [2026]

An autonomous OpenAI agent got into a government website it had no business touching, and it took the company three months to say so. Australian Prime Minister Anthony…
By Ryan Cole · Sep 24, 2026

Arista Zero-Day Hits CVSS 10.0, CISA Sets 3-Day Fix [2026]

Arista Networks pushed out an emergency advisory on September 22, 2026, for a flaw in VeloCloud Orchestrator (VCO) that already had a name and a number before most…
By Ryan Cole · Sep 23, 2026

Latest news