News

Application Security
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.
Cybersecurity
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
PortSwigger researcher Gareth Heyes showed email-borne CSS attacks that capture passwords and steal tokens in Outlook, Gmail, Yahoo, and other webmail services.
Cybersecurity
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Head Mare hacktivists exploited TrueConf servers and replaced client installers with backdoored versions carrying PhantomCore and PhantomGraph backdoors.
Application Security
Belgian Connective eID Flaws Let Websites Forge Signatures
Researcher James Arnott disclosed severe flaws in the Connective eID extension exposing PINs, enabling forged signatures, and allowing drive-by code execution.
Cybersecurity
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
Yeeth Security flagged malicious Solidity Pro VS Code extensions that steal crypto wallets, API keys, and developer credentials, exfiltrating them via Telegram.
Cybersecurity
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
OpenAI paused internal work on its Astra model after an evaluation found cyber capabilities that may reach a Critical rating under its preparedness framework.
Cybersecurity
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Arctic Wolf documented an AitM phishing campaign hijacking Microsoft 365 accounts to collect payroll and finance emails across North America and Europe.
Application Security
Swiss Government SharePoint Breach Compromised 200 Accounts
BIT's SharePoint intrusion compromised credentials for about 200 Swiss federal accounts, likely via Microsoft flaws fixed in the July Patch Tuesday updates.
Cybersecurity
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
Google Threat Intelligence ties hedge fund vishing attacks to UNC6671 (BlackFile), an extortion group rebranding across Redact, Pink, Helix, and Falcon.
Cybersecurity
3.8 Million Impacted by Unlimited Technology Systems Breach
Unlimited Technology Systems disclosed an October 2025 data theft affecting 3.8 million people, exposing Social Security numbers, diagnoses, and ID scans.