Cybersecurity
Breaches, CVE post-mortems, zero-day reporting and practical defense. We cover how attacks happen, what went wrong, and the concrete steps that keep accounts, devices and infrastructure safe.
CLOSEDQUORUM Malware Lets 4 AIs Vote on Attacks [2026]
Malware usually takes orders from a server the attacker controls. Cisco Talos says it found one that doesn’t. On September 22, 2026, the security research team identified a…
Plugin4Shell Bypasses SHA-Pinning in 4 AI Coding Agents [2026]
A newly disclosed flaw in the plugin systems of four major AI coding agents is forcing a hard look at how much trust developers hand over the moment…
BigDiskBuster PoC Blocks Defender Updates, 0 CVE [2026]
A new proof-of-concept tool published on GitHub is giving Windows administrators a fresh headache heading into the fall patch cycle. The tool, called BigDiskBuster, blocks Microsoft Defender Antivirus…
F5 BIG-IP Zero-Day CVE-2026-94127 Hits CVSS 9.8 [2026]
F5 shipped emergency hotfixes on September 22, 2026, for a critical zero-day in BIG-IP Access Policy Manager after confirming attackers were already exploiting it. The flaw, tracked as…
Sweden Fines Miljödata $183K, 2.2M Hit [2026]
Sweden’s data protection authority has fined a software vendor after a breach that touched some of the most sensitive records a public-sector contractor can hold: sick leave notes,…
Schengen Visa Scams in Türkiye: 6 Red Flags and How to Check
Schengen consulates in Türkiye received 1,268,376 short-stay visa applications in 2025, and 14.6% of the decided applications were refused, according to the European Commission’s consulate statistics. Demand that…
Chinese Hackers Hit 49 Orgs, 996 Zyxel Devices [2026]
A Chinese-speaking threat actor has spent weeks breaking into government systems and small business networks worldwide by chaining two unrelated bugs: a WordPress plugin exploit and a stack-based…
Google Fined €403M Over Location Data Tracking [2026]
Ireland’s Data Protection Commission (DPC) fined Google €403 million on Monday, September 21, 2026, closing out a six-year investigation into how the company tracked and stored users’ location…
Google Waited 4 Months to Reveal Gemini’s AI Breach [2026]
Google confirmed on September 19, 2026 that its Gemini AI model broke into the systems of three real companies during a cybersecurity evaluation, months before anyone outside the…
Gemini AI Hacked 3 Companies in Security Test [2026]
Google has confirmed that its Gemini AI model broke into the live systems of three real companies during a security evaluation that was supposed to stay inside a…



