
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it alongCybersecurity intelligence, threat analysis, and national security reporting.

Grindr is shelling out $35 million to settle a UK lawsuit that claimed the company shared users' personal info, including their HIV status, with third parties without their consent. The settlement, which doesn't admit any wrongdoing, resolves a class-action suit filed on behalf of over 10,000 users.

A staggering 220 million traveler records, including passenger and crew information, were left vulnerable due to a misconfigured system linked to a Vietnamese organization. This massive data leak, discovered by Kinryū Labs, exposed sensitive information spanning nearly a decade.

A new partnership between Aurelius Capital, the state of Lower Saxony, and Volkswagen AG is set to transform the former VW site in Osnabrück into a cutting-edge defense hub, securing the location's future and creating a center of excellence for security and defense solutions. This bold move is a strategic win for the region, with Minister-President Olaf Lies hailing it as a genuine future perspective for the site.

Imagine a future that's already here, but only in glimpses - and discover how science fiction can help policymakers and analysts better prepare for what's to come. By challenging traditional predictive methods, science fiction offers a powerful tool to widen our aperture and anticipate the uneven arrival of future challenges.

The Royal Australian Air Force faces a pressing challenge: how to produce more combat-ready pilots without breaking the bank with costly frontline fighter jets that run A$60,000 per flight hour. Could turboprops offer a smart solution to boost pilot training capacity?

Sweden is supercharging its rocket artillery capabilities with a $732 million deal for Lockheed Martin's HIMARS system, which brings game-changing long-range precision firepower to the battlefield. The contract includes over ten launchers and a substantial stockpile of ammunition, with deliveries set to start in 2027.

Meet PEEP, a sneaky post-exploitation toolkit that disguises itself as a harmless bookmarks extension in Chrome and Edge, allowing hackers to execute commands on compromised devices. It requires prior admin access to install, cleverly bypassing security checks to forge a sense of legitimacy.

A newly discovered zero-day vulnerability, dubbed "StyleSmuggler," is being exploited in the wild to install a stealthy Linux backdoor on over 160,000 Magento and Adobe Commerce sites, including 14,000 of the top 1 million sites. This alarming attack has already hit a target running the latest security updates, leaving many sites vulnerable.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Google just revealed a high-severity Chrome zero-day vulnerability, CVE-2026-85046, that's being actively exploited by hackers, allowing them to execute malicious code inside the browser's sandbox. This type confusion bug in Chrome's V8 engine was reported by researcher Salvatore Gulizia on August 4, 2026.

Beware of fake IT calls that can trick you into giving away your Microsoft 365 login credentials - scammers are using a clever vishing scheme to steal account details and hold them for ransom. It starts with a convincing phone call from someone claiming to be from IT, directing you to a fake authentication page.

Pakistan's Heavy Industries Taxila (HIT) has just unveiled a cutting-edge drone production facility, marking a major milestone in the country's military tech advancements. The state-of-the-art Unmanned Aerial Systems Factory is set to churn out a range of innovative drones, from surveillance models to loitering munitions.

A recent test has raised eyebrows, showing that a specially designed camouflage can evade detection by Flock cameras and Axon body cameras, sparking questions about the effectiveness of other surveillance technologies. Will upgrades to these systems be enough to catch visually altered vehicles, or will new methods be needed to stay one step ahead?

As the UN General Assembly convenes, a pressing question looms: will institutions like the UN assert their authority to interpret their own rules, or will external forces dictate the terms? The fate of Taiwan's status hangs in the balance, tied to the interpretation of Resolution 2758.

BigBear 2.0, a sneaky phishing-as-a-service operation, has compromised 258 companies by bypassing multi-factor authentication (MFA) for Microsoft 365 users worldwide, swiping 5,137 credential records in the process. This cunning attack used an adversary-in-the-middle approach to intercept passwords, MFA tokens, and session cookies, allowing hackers to hijack authenticated sessions with ease.

Stay vigilant, especially on holidays like Labor Day - even company staff aren't immune to unexpected messages, as Nightwing's CEO recently proved when a message meant for employees somehow made its way to The Register. This incident serves as a reminder to always be cautious when receiving unsolicited messages.

Employees are increasingly turning to AI tools outside of company-approved systems, a phenomenon known as "shadow AI," which poses significant security risks. A staggering 71% of UK employees have already admitted to using unauthorized AI tools at work.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
A newly discovered flaw in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution, thanks to a publicly released proof-of-concept that combines an AES-CBC padding oracle with a type-resolution bug in the RadAsyncUpload control. When certain preconditions are met, this vulnerability can be easily leveraged for devastating effect.

A sneaky VBScript worm is spreading rapidly through new ScreenConnect connections, launching a four-stage attack chain that wreaks havoc on unsuspecting hosts. This malicious chain was triggered by three distinct initial access routes, including tech-support scams, phishing, and fake refund forms.

The cloud security landscape is far from equal, with a staggering 76% of AWS accounts showing exposed services, compared to just 8% on Google Cloud - a massive gap that highlights the limitations of one-size-fits-all cloud security checklists. This stark disparity underscores the need for a tailored approach to cloud security, one that takes into account the unique risks of each provider.

A critical vulnerability, CVE-2026-86218, was discovered in N-able's N-central platform, allowing unauthenticated attackers to execute code on the server - and a patch is now available in N-central 2026.3 Hotfix 4. Update now to prevent potential remote code execution attacks!

In a shocking twist, hackers made off with around $320 million in Bitcoin from the Liquid Network, but claim they're "white-hats" with good intentions. Roughly 4,000 BTC was drained from the federation wallet in a mysterious heist that's left the project reeling.

A massive data breach at Mathspace has compromised the personal information of over 1 million students, school staff, and parents or guardians across Australia, New Zealand, the US, and the UK. The breach exposed sensitive data, leaving thousands of people vulnerable to potential identity theft and security risks.

Trezor warned that nearly 81,000 customers are at risk of phishing scams after a data breach exposed sensitive information that could be used for fake emails, calls, or letters. If you're one of them, be on high alert for suspicious contact attempts!

The Rhysida ransomware gang has published stolen data from Berlin's government on the dark web after the city refused to pay a €2m ransom, defying the hackers' ultimatum. Berlin's government had stood firm, prioritizing the safety of its staff and citizens over giving in to blackmail.