Former ransomware negotiator gets 4 years for BlackCat attacks

A former employee of a cybersecurity incident response company has been sentenced to four years in prison for his role in orchestrating BlackCat (ALPHV) ransomware attacks against U.S. companies, collecting an estimated $300 million in ransom payments from over 1,000 victims between November 2021 and September 2023. Angelo Martino, a 41-year-old former employee of DigitalMint, … Read more

Zimbra urges customers to patch critical web client XSS flaw

**Critical Web Client Vulnerability Hits Zimbra Users** Zimbra, a popular email and collaboration software suite used by hundreds of millions worldwide, is urging its customers to patch a critical vulnerability affecting its Classic Web Client. The flaw, which has yet to receive a CVE ID, allows attackers to steal sensitive information through specially crafted emails … Read more

Jen Ellis: Connecting Cyber Community With Political Machinery

Jen Ellis, a stalwart advocate for security researchers, has made waves in the cybersecurity community with her tireless efforts to reform laws that stifle legitimate research. Her dedication and unyielding spirit have earned her numerous accolades, including a recent honor from the British Crown. Ellis’s journey as a champion of cybersecurity policy began over a … Read more

Zimbra urges customers to patch critical web client XSS flaw

Zimbra’s Classic Web Client Hit by Critical XSS Flaw, Patch Urged for Millions of Users A severe vulnerability has been discovered in Zimbra’s Classic Web Client, a widely used email and collaboration software suite that serves hundreds of millions of people worldwide. The security flaw, which allows attackers to execute malicious code through specially crafted … Read more

The Replicant in Your Directory: AI Agents and the Identity Security Gap

In a growing concern for organizations worldwide, artificial intelligence (AI) agents are exposing a gaping hole in identity security. These non-human entities, which include service accounts, OAuth applications, and machine identities, already outnumber human users by as much as 50 to one in many enterprise environments. The issue lies in the fact that identity security … Read more

Money launderer accused of stealing seized crypto while in prison

A shocking case has emerged in the US, highlighting a brazen attempt to steal government-seized cryptocurrency while an individual was behind bars. Rossen G. Iossifov, a Bulgarian national serving a 121-month prison sentence for helping launder millions stolen from American victims of online fraud, has been charged with stealing $290,000 in seized crypto. Iossifov’s alleged … Read more

Hackers exploit critical auth bypass in Gitea Docker image

Critical Vulnerability Exploited in Gitea Docker Image, Leaving Thousands of Instances at Risk A severe security vulnerability in the official Docker image for Gitea, a popular self-hosted Git service alternative to GitHub and GitLab, has been actively exploited by hackers. The flaw, tracked as CVE-2026-20896, allows attackers to impersonate any user, including administrators, on affected … Read more

The Replicant in Your Directory: AI Agents and the Identity Security Gap

In the past few years, cybersecurity teams have been facing a growing challenge: non-human entities with access to sensitive data and systems. These “replicants” are AI agents, service accounts, OAuth applications, workload identities, and machine identities that already outnumber people in many enterprise environments. The issue isn’t new, but it’s gaining urgency as these entities … Read more

Money launderer accused of stealing seized crypto while in prison

A Shocking Case of Crypto Theft: Money Launderer Accused of Swiping Seized Funds from Prison In a stunning example of brazen audacity, a Bulgarian national has been charged with stealing over $290,000 in government-seized cryptocurrency while serving time in prison for his role in laundering millions stolen from American victims. Rossen G. Iossifov, 53, is … Read more