39 New Methods That Compromise Passkey Authentication

Passkey Authentication Under Siege: 39 New Methods Exposed A revolution in password-free security was supposed to make our online lives safer. Passkeys, touted as a replacement for traditional passwords, promised to bind credentials to legitimate services, keeping private keys out of reach from would-be attackers. However, the rapid evolution of cybersecurity threats has caught up … Read more

IDScan sued over alleged data breach affecting 153 million drivers

A Massive Data Breach Affects 153 Million Drivers, Raising Concerns About Identity Verification Company IDScan A staggering 153 million driver’s licenses have been compromised in a massive data breach involving identity verification company IDScan. The incident has sparked multiple lawsuits and investigations, with several law firms launching potential class-action litigation against the firm. The breach … Read more

Companies Have 6 Months to Prepare for Automated Attacks

Companies have just six months to prepare for a new era of automated cyberattacks, as frontier AI models continue to demonstrate their ability to autonomously compromise networks and systems with ease. The latest benchmarking efforts from Booz Allen and other cybersecurity experts confirm that these advanced machine learning models can execute end-to-end attacks at speeds … Read more

Exchange Online outage causes email delays, ‘Server busy’ errors

A critical outage in Microsoft’s Exchange Online service is causing email delays and “Server busy” errors for users sending and receiving emails from external domains. The issue, which was first acknowledged by Microsoft at 2:19 AM EDT, has left many wondering when normal email services will resume. Microsoft’s investigation into the cause of the outage … Read more

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

A Critical Zero-Day Exploit in CrowdStrike Falcon Enables System Privileges Escalation A severe zero-day vulnerability has been discovered in CrowdStrike’s popular endpoint security platform, Falcon. Dubbed “FalconFlank” by the anonymous security researcher who uncovered it, this exploit allows attackers to gain SYSTEM privileges on up-to-date Windows systems, including those running Windows 11 and Windows Server. … Read more

39 New Methods That Compromise Passkey Authentication

A New Era of Threats Emerge as Passkey Authentication Falls Short In a shocking revelation, researchers have uncovered 39 new methods that compromise passkey authentication, a supposedly secure alternative to traditional passwords. These techniques, some already implemented in proof-of-concept tools or demonstrated in real-world attack patterns, expose a fundamental flaw in the passkey system: its … Read more

IDScan sued over alleged data breach affecting 153 million drivers

A staggering 153 million driver’s licenses have been allegedly breached by hackers who offered to sell access to the sensitive information on a dark-web identity-theft service called “Nexus.” The compromised database is believed to belong to IDScan, an identity verification technology company that provides services to businesses across the US. If true, this would be … Read more

Microsoft says some users can’t open the Teams desktop client

Microsoft’s Microsoft Teams desktop client has been plagued by a known issue that’s causing some users to experience delays or even being blocked from opening the application on their Windows systems. The company acknowledged this problem on Thursday, advising affected customers to work around it by using the web or mobile platforms in the meantime. … Read more

Critical Citrix NetScaler auth bypass now leveraged in attacks

A Critical Citrix Flaw is Now Being Exploited in Real-World Attacks Citrix, a leading provider of secure networking solutions, has had its NetScaler appliance vulnerability exploited by attackers. The flaw, known as CVE-2026-19490, allows unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured in certain ways. This means that even if … Read more

New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A sophisticated backdoor has been discovered lurking inside HAProxy builds, putting thousands of organizations and their customers at risk of intercepted web traffic. The “Ted” backdoor, as it’s being called, exploits a vulnerability in HAProxy software to secretly siphon off sensitive data from unsuspecting users. The discovery was made by security researchers who analyzed various … Read more