CISA orders feds to prioritize patching Langflow auth bypass flaw

Federal Agencies Ordered to Patch Critical Vulnerability in Popular AI Development Tool The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to prioritize patching a recently discovered vulnerability in Langflow, a widely used visual framework for building artificial intelligence agents. The flaw, tracked as CVE-2026-55255, is being actively … Read more

Telco giant KDDI says data breach affects over 12 million people

A staggering 12 million people have had their sensitive information compromised in a massive data breach at Japanese telecommunications giant KDDI, one of the country’s largest mobile providers. The breach, which was first discovered on June 17, exposed email addresses and passwords of millions of customers across five internet service providers (ISPs) in Japan. KDDI, … Read more

Mount Royal University confirms breach as hackers claim attack

Mount Royal University Falls Victim to Cyberattack, Exposing Sensitive Data A disturbing breach has hit Mount Royal University in Calgary, Alberta, Canada, leaving thousands of students and employees vulnerable. Hackers claiming affiliation with the threat group CMD Organization have accessed a university network, stolen sensitive data, and even deleted some files to hinder recovery efforts. … Read more

DuckDuckGo browser now blocks YouTube video ads

In a significant move that’s likely to be welcomed by YouTube users worldwide, DuckDuckGo has rolled out a new feature that blocks most video ads on the popular platform. The ad-blocking mechanism is built into the latest versions of the browser for iOS, Mac, and Windows, while Android users can enable it manually through their … Read more

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

**AI-Powered Service Desk Attacks: The Growing Threat** A recent report from IBM found that a staggering 16% of breaches involve attackers using AI-powered tools, with phishing and deepfake impersonation attacks being the most common. This trend has significant implications for security teams, particularly when it comes to the service desk. As a critical entry point … Read more

Hackers exploit Roundcube flaw to spy on academic researchers

A China-linked threat cluster has been exploiting a vulnerability in Roundcube webmail servers at universities across the United States and Canada, stealing credentials and deploying backdoor malware. The campaign, tracked by cybersecurity researchers at Proofpoint as “UNK_MassTraction,” has been active since May and targets physics, engineering, and national security-related research departments. Researchers have identified a … Read more

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

A Sneaky Credential Thief Has Been Lurking on Popular Package Managers A group of malicious packages has been discovered on both the Node Package Manager (npm) and the Python Package Index (PyPI), compromising the credentials of users who rely on popular payment platforms such as Paysafe, Skrill, and Neteller. These fake software development kits (SDKs) … Read more

Mount Royal University confirms breach as hackers claim attack

A Calgary University Hit with Cyberattack, Hackers Demand $1.9 Million Ransom Mount Royal University in Calgary has confirmed a breach of its network after hackers stole and then deleted data from its file storage systems. The attack, which occurred on June 17, disrupted various university systems, including online services and internal systems. The university has … Read more

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Service desks around the world are increasingly becoming a target for sophisticated social engineering attacks, thanks in part to the growing use of artificial intelligence (AI) by malicious actors. A recent report found that 16% of data breaches studied involved attackers using AI tools, with phishing and deepfake impersonation attacks being among the most common … Read more

Entra passkey enrollment vishing targets Microsoft 365 users

**Threat Actor Exploits Microsoft Entra Passkey Feature to Phish Users** A sophisticated threat actor has been targeting organizations across various sectors with a clever voice phishing scam, convincing victims to enroll a new Entra passkey under their control. The attackers are taking advantage of a recent security feature introduced by Microsoft in May, which allows … Read more