Microsoft Defender flags legitimate Google search links as malicious

Microsoft’s flagship security software, Defender for Office 365, has been mistakenly flagging legitimate Google search links as malicious. The issue, which was first acknowledged by Microsoft on September 2nd, is causing users to see warning messages when trying to open blocked hyperlinks. According to a service alert seen by CyberNews.work, the problem stems from an … Read more

Dropbox accounts breached through Lenovo email verification flaw

Dropbox users are facing a security breach that allows unauthorized access to their accounts through a flaw in Lenovo’s email verification process. The cloud storage provider has warned its users that an attacker exploited this vulnerability to register fraudulent Lenovo IDs and gain access to Dropbox accounts without needing the login password. The issue affects … Read more

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware attacks on Managed Service Providers (MSPs) have become increasingly common, with 143 such incidents reported in 2025 alone. These attacks not only disrupt business operations but also put sensitive customer data at risk. To combat this threat, MSPs need a robust ransomware protection service that goes beyond mere backup and endpoint detection. A recent … Read more

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Sangoma Switchvox Flaw Exposes Thousands to Remote Code Execution Attacks A critical security vulnerability in the Sangoma Switchvox VoIP platform is being actively exploited by hackers to deploy reverse shells, putting thousands of internet-exposed systems at risk. The flaw, identified as CVE-2026-9586, was discovered by security researchers at Horizon3 and reported to Sangoma back in … Read more

Dropbox accounts breached through Lenovo email verification flaw

Cloud Storage Company Dropbox Warns Users of Unauthorised Account Access via Lenovo ID Flaw Dropbox has alerted some users that their accounts were accessed by an unauthorized party due to a vulnerability in Lenovo’s email verification process. This allowed attackers to register fake Lenovo IDs and subsequently access the associated Dropbox account without needing the … Read more

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware protection for Managed Service Providers (MSPs) has become a top concern in recent years, as attacks have increased in frequency and severity. A recent report by Bleeping Computer highlights the importance of robust ransomware protection measures for MSPs, which can have far-reaching consequences if compromised. The report emphasizes that backup alone is not enough … Read more

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Malicious Software Installers Exploit Windows Vulnerabilities, Leaving Users Exposed A new wave of fake software installers has been discovered spreading across the web, designed to disable crucial security features on Windows operating systems. These malicious packages are not only targeting unsuspecting users but also severely weakening their defenses against sophisticated attacks. At its core, this … Read more

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google, Anthropic, and OpenAI have made significant strides in artificial intelligence (AI) research, but a newly revealed threat vector is putting users at risk. The issue lies in identity exposure, which can unlock active attack paths for malicious actors. This vulnerability affects a wide range of individuals, from tech-savvy professionals to everyday consumers who use … Read more

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A Critical Flaw in JFrog Artifactory Allows Hackers to Forge Admin Tokens, Potentially Compromising Entire Systems A recently discovered vulnerability in JFrog Artifactory, a popular repository manager used by software developers and organizations worldwide, is being exploited by hackers to gain administrative access. The critical flaw, identified as CVE-2026-82329, allows an unauthenticated attacker with network … Read more