Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Apple has released a significant round of security updates for its devices, including iOS/iPadOS 26.6, macOS Tahoe 26.6, Safari 26.6, and other operating systems, addressing dozens of vulnerabilities across kernel, WebKit, media frameworks, and core apps. These updates focus on security improvements rather than new features and are critical for users of iPhone 11 and later, iPad Pro 3rd generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, iPad mini 5th generation and later, Apple TV HD and Apple TV 4K, Apple Watch Series 6 and later, and Apple Vision Pro.
Apple has shipped a hefty round of July security patches, headlined by iOS/iPadOS 26.6, macOS Tahoe 26.6, and Safari 26.6, with dozens of vulnerabilities squashed...
The app, Click To Pray, was <a...
The Vatican’s Click To Pray app, endorsed by Pope Francis and developed by La Machi Communication for Good Causes, exposed personal data of over 700,000 users due to an Insecure Direct Object Reference (IDOR) vulnerability. Independent researcher BobDaHacker discovered in January 2026 that the app’s API endpoint leaked sensitive information—including email addresses, names, countries, and dates of birth—by allowing unauthorized access to sequential user IDs.
This article from Cisco Talos IR reports on Q2 2026 incident response trends. Phishing remained the top initial access vector, appearing in over half of engagements, while authentication abuse increased significantly.
Phishing was the leading initial attack vector in Q2 2026, accounting for over half of Cisco Talos IR engagements—up from a third last quarter. Attackers used QR code-embedded PDFs hosted on trusted cloud platforms to bypass email gateways, while authentication abuse surged to 65% of cases, with adversaries exploiting MFA weaknesses via AitM proxies, session-token theft, and MFA fatigue.