Hidden backdoor in Tenda router firmware grants admin access

A hidden authentication backdoor has been discovered in multiple versions of Tenda router firmware, potentially allowing attackers to gain administrator access to the device’s web management panel. The issue remains unfixed due to an inability to contact the Chinese manufacturer. The vulnerability, tracked as CVE-2026-11405 by the CERT Coordination Center (CERT/CC), lies within the ‘login()’ … Read more

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

GitHub users, take heed: a publicly disclosed issue could be putting private repository data at risk. A flaw in GitHub’s Agentic Workflows feature – designed to automate tasks and simplify development workflows – has been identified as vulnerable to exploitation by malicious actors. The bug, discovered through responsible disclosure, can trick the system into leaking … Read more

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A sophisticated cyber attack is making headlines, with attackers exploiting a previously unknown vulnerability in Microsoft’s device-code flow to gain unauthorized access to Microsoft 365 (M365) accounts. Dubbed “DEBULL,” this tactic has been linked to an advanced threat actor that has successfully compromised multiple high-profile organizations. The DEBULL tooling leverages the device-code flow, a security … Read more

Spain arrests suspected member of pro-Russian hacktivist groups

Spanish authorities have made a significant arrest in their efforts to crack down on pro-Russian hacktivist groups. A man suspected of being an active member of CyberArmy of Russia Reborn (CARR) and Z-Pentest, two groups linked to multiple attacks targeting critical infrastructure in the US and Europe, has been taken into custody by Spain’s National … Read more

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

A Critical Flaw in Writer AI Exposes Session Tokens Across Tenants, Leaving Thousands at Risk of Unauthorized Access A disturbing security vulnerability has been discovered in the popular writing assistant tool Writer AI, which could potentially allow an attacker to leak sensitive session tokens across tenants. The flaw, which affects thousands of users, highlights the … Read more

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A GitHub Issue Exposed by a Hacker Has Revealed How Private Repository Data Can Leaked Through Automated Workflows, Highlighting the Growing Concern of AI-Powered Security Threats. The security community is abuzz with concern after a public GitHub issue revealed that automated workflows on the platform can inadvertently leak sensitive repository data. The issue, which has … Read more

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

Cybersecurity researchers have uncovered a sophisticated threat actor exploiting a previously unknown vulnerability in Microsoft’s device-code flow, which allows attackers to gain unauthorized access to Microsoft 365 (M365) accounts. The technique, dubbed “DEBULL Tooling,” has been used to target high-profile organizations and individuals worldwide. At its core, the attack relies on manipulating the device-code flow, … Read more

Webinar tomorrow: Why modern email attacks require a new approach to defense

Email Attacks Evolve, Leaving Traditional Security Measures in Shambles As security teams continue to invest heavily in advanced technologies such as secure email gateways and multi-factor authentication, phishing, business email compromise (BEC), and account takeover (ATO) attacks remain some of the most persistent threats facing organizations today. Despite these efforts, attackers are finding new ways … Read more

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Suspected China-Aligned Hackers Target Universities with Roundcube Flaws, Exposing Sensitive Data A highly sophisticated hacking campaign, linked to suspected Chinese actors, has been exploiting vulnerabilities in the widely-used email client software Roundcube against universities worldwide. The cyberattacks have compromised sensitive student and faculty data, highlighting the critical need for robust security measures in higher education … Read more