Exchange Online outage causes email delays, ‘Server busy’ errors

A critical outage in Microsoft’s Exchange Online service is causing email delays and “Server busy” errors for users sending and receiving emails from external domains. The issue, which was first acknowledged by Microsoft at 2:19 AM EDT, has left many wondering when normal email services will resume. Microsoft’s investigation into the cause of the outage … Read more

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

A Critical Zero-Day Exploit in CrowdStrike Falcon Enables System Privileges Escalation A severe zero-day vulnerability has been discovered in CrowdStrike’s popular endpoint security platform, Falcon. Dubbed “FalconFlank” by the anonymous security researcher who uncovered it, this exploit allows attackers to gain SYSTEM privileges on up-to-date Windows systems, including those running Windows 11 and Windows Server. … Read more

39 New Methods That Compromise Passkey Authentication

A New Era of Threats Emerge as Passkey Authentication Falls Short In a shocking revelation, researchers have uncovered 39 new methods that compromise passkey authentication, a supposedly secure alternative to traditional passwords. These techniques, some already implemented in proof-of-concept tools or demonstrated in real-world attack patterns, expose a fundamental flaw in the passkey system: its … Read more

IDScan sued over alleged data breach affecting 153 million drivers

A staggering 153 million driver’s licenses have been allegedly breached by hackers who offered to sell access to the sensitive information on a dark-web identity-theft service called “Nexus.” The compromised database is believed to belong to IDScan, an identity verification technology company that provides services to businesses across the US. If true, this would be … Read more

Microsoft says some users can’t open the Teams desktop client

Microsoft’s Microsoft Teams desktop client has been plagued by a known issue that’s causing some users to experience delays or even being blocked from opening the application on their Windows systems. The company acknowledged this problem on Thursday, advising affected customers to work around it by using the web or mobile platforms in the meantime. … Read more

Critical Citrix NetScaler auth bypass now leveraged in attacks

A Critical Citrix Flaw is Now Being Exploited in Real-World Attacks Citrix, a leading provider of secure networking solutions, has had its NetScaler appliance vulnerability exploited by attackers. The flaw, known as CVE-2026-19490, allows unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured in certain ways. This means that even if … Read more

New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A sophisticated backdoor has been discovered lurking inside HAProxy builds, putting thousands of organizations and their customers at risk of intercepted web traffic. The “Ted” backdoor, as it’s being called, exploits a vulnerability in HAProxy software to secretly siphon off sensitive data from unsuspecting users. The discovery was made by security researchers who analyzed various … Read more

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

A Critical Vulnerability in PostgreSQL Has Been Patched After 12 Years PostgreSQL, a popular open-source database management system, has just released patches for a long-standing vulnerability that allows attackers to execute malicious code on systems using its replication feature. The flaw, discovered in 2014 but not previously addressed, is particularly concerning due to the sensitive … Read more

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Millions of Email Users Targeted in Sophisticated Phishing Campaign Using Invisible Unicode A massive phishing campaign has been underway, sending out millions of emails that have managed to evade traditional spam filters. The attackers’ cunning trick? They’re using invisible Unicode characters to conceal their malicious links and attachments. At the heart of this operation is … Read more

Microsoft says some users can’t open the Teams desktop client

Microsoft’s Microsoft Teams desktop client has been plagued by a known issue that prevents some users from opening it on their Windows systems. The company acknowledged the problem on Thursday and advised affected customers to work around it by using the web or mobile platforms until a fix is released. The issue, tracked as TM1466820, … Read more