
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentCybersecurity intelligence, threat analysis, and national security reporting.

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

In just 13 minutes, a scammer can use a single phone call to trick victims into installing malware, allowing them to commit card and loan fraud - all thanks to the cunning WindRelay malware. This sneaky software uses NFC relay attacks to enable live-call loan fraud, leaving victims none the wiser.

Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Uber Freight is investigating a data security incident after a hacktivist group claimed to have breached its systems, but fortunately, the issue has been identified, contained, and resolved, with operations now secure and running smoothly. The breach hasn't disrupted daily operations, and the company is working to put customers' minds at ease.

Scammers are exploiting gaps in the hiring process to land remote jobs, using stolen credentials and impersonating others to get their hands on sensitive corporate information. They're taking advantage of the rise of remote work to gain access to company networks and exfiltrate proprietary data.

Beware: cybercriminals are on the hunt for intimate content on social media and online accounts, using stolen images and videos to blackmail victims or sell them on shady marketplaces. Once they have your secrets, they can use them to extort and exploit you, often without you even knowing.

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

While defenses at the network perimeter are getting stronger, with a 69% prevention rate, the harsh reality is that attackers who breach this outer layer can still wreak havoc inside, with a surprisingly low 37% prevention rate. The latest Blue Report 2026 reveals a concerning gap in enterprise security, highlighting the need for stronger internal defenses.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

A shocking data breach at the UK's Criminal Records Office has left 11,000 individuals vulnerable after sensitive information was exposed due to basic cyber security failings. The breach went undetected for seven months, highlighting the devastating consequences of neglecting online security.

A shocking security flaw in AI APIs has been uncovered, exposing sensitive secrets like API keys, passwords, and private keys across major models from OpenAI, Anthropic, and Google. Researchers decoded hundreds of thousands of "thinking" blocks, revealing a treasure trove of confidential data.

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

The US government's quest to modernize the National Vulnerability Database is underway, and it's seeking your input - with an October 13 deadline to share innovative ideas on how to bring this critical cybersecurity resource into the automation age. NIST wants to hear your forward-looking perspectives on how to scale the NVD and supercharge its support for automated security workflows.

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

The London Underground has become the latest testing ground for live facial recognition, with British Transport Police rolling out the technology at Victoria station, sparking concerns that millions of innocent faces will be scanned. This move has civil liberties groups sounding the alarm, with Big Brother Watch director Silkie Carlo calling it a "disturbing and dystopian" expansion.

Adobe has patched critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including a zero-day flaw with a perfect 10.0 CVSS score that could allow hackers to execute arbitrary code or escalate privileges. These high-severity flaws, including operating system command injection and eval injection, require immediate attention to prevent exploitation.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Say goodbye to the hassle of manually verifying safety numbers - Signal's new Automatic Key Verification feature adds an extra layer of protection to ensure your encrypted chats remain private and secure. This innovative update lets you confirm your chats haven't been intercepted, without needing to meet in person or use another channel.

A security researcher known as Nightmare Eclipse has unveiled a new exploit, ShieldBreak, which can bypass Microsoft's patch for the RoguePlanet vulnerability and grant SYSTEM privileges on fully patched Windows systems. This alarming development highlights a significant gap in Microsoft Defender's defenses, leaving users vulnerable to potential attacks.

In a chilling cyberattack, Russian hackers infiltrated a Polish power plant by breaching a wind farm's VPN and firewall, then exploited a cellular router to gain control of the plant's systems. The attackers forced a combined heat and power plant into a controlled shutdown, overriding its operations with a password-protected lock.

Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks vulnerable to disruption.

Australia is being urged to join the Defence Security Bank, a proposed multilateral lender that will boost allied defence capabilities by mobilising private finance for defence manufacturers and their suppliers. By backing the bank, Australia can help strengthen its own defence industry and play a key role in supporting global security.