Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Microsoft has reminded IT administrators that Windows Server 2022 will reach the end of mainstream support on October 13, 2026, transitioning to extended support (security updates only) until October 14, 2031. The company strongly recommends upgrading to Windows Server 2025, the latest Long-Term Servicing Channel (LTSC) release, which offers mainstream support through November 14, 2034.
Ukraine’s Main Intelligence Directorate (HUR) claimed responsibility for a cyberattack on Russia’s largest online marketplace, Wildberries, conducted in cooperation with the Cyber Corps hacker group. The attack targeted Wildberries’ customer service, contact centers, and payment infrastructure, causing widespread disruption despite the company’s strong security measures.
As organizations adopt AI agents through the Model Context Protocol (MCP), enterprise secrets face new exposure vectors: plaintext credentials in config files, credential sprawl across ungoverned servers, prompt injection tricking agents into leaking secrets, and over-permissioned deployments that violate least privilege. The article recommends centralized secret management, short-lived credentials, least-privilege enforcement, human-in-the-loop gates, and full audit logging to secure the MCP layer.
This article reports that the Clop ransomware gang has claimed data theft attacks against General Electric (GE), Philips, and Shell, exploiting a critical improper input validation vulnerability (CVE-2026-12569) in internet-exposed PTC Windchill and FlexPLM enterprise platforms. GE confirmed it is investigating the claim, while Philips acknowledged a breach of an internal enterprise server but stated the incident was contained and did not affect customers.
This article from Malwarebytes warns users about fraudulent TikTok-branded rewards pages that promise large cash payouts for daily check-ins, completing small tasks, and earning points. These sites display enormous balances and countdown timers to create urgency, but when users attempt to withdraw, they are met with endless additional requirements—such as referring more friends, watching videos, completing sponsored offers, or downloading a separate app for "identity verification." The article clarifies that TikTok does have a legitimate Creator Rewards Program, but it is limited to eligible creators in certain countries who earn rewards for original videos, not for check-ins or tasks on external websites.
The Dutch NCSC warned that CVE-2026-65400, an authentication-bypass flaw in macOS Screen Sharing, is being actively exploited to install Monero cryptominers. Apple patched the vulnerability on August 6 across macOS Tahoe, Sequoia, and Sonoma.