Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Android’s latest operating system update, version 17, has quietly introduced a new feature that significantly enhances user privacy. Dubbed “OS-Wide ECH” – short for Encrypted Client Hello – this innovation allows Android devices to conceal website visits from network providers and other entities that might be monitoring internet traffic. The way it works is relatively … Read more

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Cybersecurity researchers have uncovered a sophisticated attack vector that exploits two previously unknown vulnerabilities in popular printing management software PaperCut. The attackers are chaining these flaws together to execute malicious code on affected systems without requiring user authentication, posing a significant threat to organizations worldwide. The vulnerability lies within PaperCut’s architecture, which allows for cross-domain … Read more

Toy-making giant Hasbro disclose data breach affecting employees

A Major Toy Maker Exposes Employee Data in Latest Cybersecurity Mishap Toy giant Hasbro has revealed that a group of attackers gained access to sensitive employee information, leaving a significant number of staff members vulnerable to identity theft and financial loss. The company, which owns beloved brands such as Monopoly, Nerf, and Transformers, filed data … Read more

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Gitea servers remain vulnerable to code execution attacks despite a critical security fix being available since July. Cybersecurity watchdog Shadowserver has identified nearly 8,400 Internet-exposed Gitea instances that are still unpatched against a serious flaw exploited in ongoing remote code execution attacks. The vulnerability, known as CVE-2026-60004, was reported by Salesforce researcher Shai … Read more

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

As AI-powered vulnerability discovery tools accelerate the rate at which new vulnerabilities are identified, cybersecurity defenders are facing a daunting challenge: can they keep up with the sheer volume of threats? A recent update to the National Vulnerability Database (NVD) has introduced changes that prioritize newer vulnerabilities over older ones, but this shift comes with … Read more

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

A wave of malicious Chrome and Edge extensions has been discovered, exposing millions of users to the risk of wallet-stealing and crypto-draining attacks. The extensions, which have been downloaded over 30 million times, were found to contain code that exploits vulnerabilities in popular web applications, allowing hackers to drain cryptocurrency wallets and steal sensitive user … Read more

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Gitea servers remain vulnerable to code execution attacks, with nearly a third still unpatched against a critical security flaw that allows attackers to execute arbitrary shell commands with elevated privileges. This vulnerability, reported by Salesforce researcher Shai Rod and tracked as CVE-2026-60004, can be exploited even by unauthenticated visitors who register an account … Read more

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

As AI-powered tools accelerate vulnerability discovery, cybersecurity defenders are facing an unprecedented challenge. With thousands of new vulnerabilities being published each month, traditional methods of managing risk are struggling to keep up. The National Vulnerability Database (NVD), a critical resource for defenders, has been forced to introduce changes in response to the growing volume of … Read more

Key Reasons Why Identity Fabric Matters in 2026

As we enter the mid-point of 2026, a growing trend is emerging in the world of cybersecurity: identity exposure. A recent analysis of over 11 real-world cases has revealed that compromised identities are often the starting point for active attack paths, allowing hackers to move laterally within an organization’s network with ease. The concept of … Read more