Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Cyble's report details a ransomware surge in Europe during the first half of 2026, with 866 attacks and a concentration of power among five major threat actors. Qilin emerged as the top threat, targeting Germany heavily and focusing on construction and professional services.
This article describes a widespread phishing campaign using adversary-in-the-middle (AitM) techniques to hijack Microsoft 365 accounts and steal payroll-related emails. The attackers use residential proxies and legitimate services to bypass security filters and maintain access.
This article details an active phishing campaign using adversary-in-the-middle techniques to hijack Microsoft 365 accounts. The goal is to identify financial workflow personnel and gather related emails, using residential proxies to evade detection.
PortSwigger's AI-assisted HTTP Terminator system generated and validated new HTTP desynchronization attacks after testing 30,000 candidate vectors. The research found approximately 700 vulnerable targets, including banks and government infrastructure, and disclosed a zero-day in Apache Traffic Server.
[v2] PortSwigger researchers built an AI-assisted system called HTTP Terminator that discovered novel HTTP desynchronization techniques and identified a zero-day vulnerability in Apache Traffic Server, tracked as CVE-2026-63078. The system analyzed over 30,000 potential desync vectors across authorized bug bounty programs, identifying roughly 700 vulnerable targets including banks, government systems, and an airport.
Researcher Dirk-jan Mollema demonstrated that malware in a signed-in Windows session can silently use Windows Hello for Business keys to authenticate to Microsoft Entra ID. This allows attackers to gain persistent cloud access without extracting private keys or triggering biometric prompts, though no active exploitation has been reported.