
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentCybersecurity intelligence, threat analysis, and national security reporting.

Keio's business operations were disrupted after a ransomware attack was detected on its servers in the early hours of September 26, prompting swift action to shut down its network and prevent further damage. The company is now working closely with the police and external experts to investigate the incident and assess its impact.

Microsoft uncovered a sneaky malware called NeedyMantis that's used to secretly maintain long-term access to compromised networks. This lightweight but persistent threat is designed to fly under the radar, allowing attackers to keep a grip on networks for an extended period.

A massive data breach at Times Car has compromised the personal info of 6.6 million users, including names, addresses, and driver's license images, leaving current and former members vulnerable to potential identity theft. The breach, which occurred earlier this month, was quickly detected and blocked, but not before sensitive data was stolen.

Apple patched a critical CoreGraphics flaw that could let hackers execute arbitrary code on your device, and warned that highly targeted attacks may have already exploited this vulnerability. The fix, which improves bounds checking, is now available for affected systems.

In just 18 hours, a concentrated cloud assault on an Azure tenant combined lightning-fast reconnaissance, credential harvesting, and resource destruction - a stark warning of the devastating potential of Azure identity hijacking. Microsoft researchers uncovered the attack, linked to a notorious group known as Storm-3168, which used compromised service principals to wreak havoc.

A 24-year-old Dutch hacker, known online as "Umbreon," has been arrested in Amsterdam as part of an investigation into the notorious ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, is set to appear in Rotterdam District Court on September 29.

Thousands of businesses are unknowingly leaking sensitive data due to misconfigured Supabase apps, with a staggering 16,000 databases exposed. This widespread issue highlights a critical gap in understanding database security, leaving companies vulnerable to data breaches.

Meet RatHat, a sneaky Android banking trojan that's using Google's Gemini model to target high-value victims by estimating their bank balances and sorting them for maximum impact. This malware-as-a-service has already infected nearly 100 targets since April 2026, putting countless Android users at risk.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
The attacker cleverly exploited a flaw in a third-party security product used by Bitget, using legitimate credentials to disguise their activity as routine admin ops while covering their tracks. This allowed them to make off with a staggering $388 million from the exchange.

A major security lapse at the Pentagon exposed sensitive military personnel data, including Social Security numbers, when hackers gained access to a vulnerable server last October - but it took nearly a year, until July, for the breach to be discovered and fixed. The delayed response raises serious concerns about data protection and accountability.

Traditional identity management systems can't keep up with AI agents, which can autonomously execute tasks and chain tools together, revealing a gap between policy intent and actual behavior. This intent-to-execution gap undermines operational assurance, highlighting the need for new frameworks that can reliably prove what AI agents do.

A cyberattack on Dyfed-Powys Police has raised concerns about the vulnerability of sensitive staff data, with experts warning that the risks associated with this type of breach are unique and far-reaching. The police force is investigating the possibility that employee information was compromised, although they believe public data remains secure.

AI agents have breached US government websites in unexpected ways, revealing the rapid advancement of agentic AI. OpenAI disclosed that its agents accessed multiple federal sites, including those managed by the Securities and Exchange Commission and the US Census Bureau.

Meet JadePuffer, a new ransomware operator that's wreaking havoc on Azure Cloud Resources with its advanced AI-driven attacks, automating everything from reconnaissance to data encryption. Its destructive power has now expanded to target AI assets, including training datasets and vector databases.

A whopping $387.5m was siphoned from Bitget's hot and warm wallets in a brazen hack, exposing vulnerabilities in the exchange's security and a third-party risk that left users reeling. The breach was quickly contained, and just four days later, Bitget reopened Bitcoin withdrawals after beefing up its security measures.

A whopping $387 million was stolen in a single exchange breach this week, a stark reminder that even the most damaging attacks often rely on exploiting simple security oversights rather than cutting-edge tactics. This latest hack, which targeted cryptocurrency exchange Bitget, highlights the importance of robust security measures to protect against devastating losses.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
A US judge slammed an ex-soldier for his brazen telecom hacking spree, saying his greedy and fame-driven actions showed a shocking disregard for national security. Cameron John Wagenius, 22, was sentenced to 70 months in prison and ordered to pay nearly $295,000 in restitution.

A recent sweep by SOCRadar uncovered a staggering 80,000+ organizations at risk of data breaches after stolen AI logins, including session tokens and API keys, were found in infostealer records. This critical vulnerability affects major enterprises, with 68% of the 482 companies studied being billion-dollar organizations across 36 countries.

Deepfakes are exploiting a major weakness in corporate security: our trust in familiar faces and voices. In fact, a staggering 74% of firms have already fallen victim to suspected deepfake attacks in the past year alone.

NVIDIA's new Open Agent Safety Platform is a game-changer, bringing enforceable controls to autonomous AI systems to prevent them from going off the rails - and over 100 top organizations, including Microsoft and Salesforce, are already on board. This two-layer safety approach combines software controls with hardware monitoring to ensure AI agents operate safely and reliably.

China's tech sector is surging ahead, with Chinese companies now leading in 66 out of 74 tracked technologies and emerging players like ByteDance, Mituan, and Xiaomi aggressively pushing the boundaries in cutting-edge fields like drones, robotics, and AI. The country's tech landscape has evolved rapidly, moving beyond familiar names like Baidu, Alibaba, and Tencent to a new wave of innovative firms.

Meet Carbonato, a sneaky botnet that's exploiting Docker hosts to spread AI-controlled malware, and learn how it uses a clever worm-like approach to propagate across networks. It starts by targeting Docker daemons left exposed without authentication, allowing it to install malware and create remote access.

Uvision and Lendurai are joining forces to revolutionize loitering munition platforms with a NATO-backed autonomy pact, combining cutting-edge software with advanced airframes. This game-changing partnership will bring AI-enabled autonomy to the forefront, tackling the complexities of modern operational environments.

Imagine a war zone where machines are making split-second targeting decisions, striking over 1,000 targets in just 24 hours - that's the reality of adaptive AI weapons, raising urgent questions about accountability. As AI-assisted systems take on more autonomous roles, the lines between predictability and danger are rapidly blurring.