Attackers Are Not Breaking Passkeys. They Are Adding Their Own.
Microsoft describes sign-ins followed by attackers registering their own authentication method. It survives every passwo...
ASEAN edition · Fri, 2 Oct 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
Microsoft describes sign-ins followed by attackers registering their own authentication method. It survives every passwo...
The Cyber Resilience Act's reporting duty went live on 11 September. The clock starts when you become aware, which is lo...
The United States seized the marketplace's Telegram channels and restrained $52.8 million, about two tenths of one per c...
An early checkpoint was told it was in a sealed simulation; a misconfiguration put it on the open internet. The scan tha...
CVE-2026-67401 is SQL injection in EmailTrack, disclosed 8 September with no reported exploitation. It is the second cPa...
CVE-2026-75650 is unauthenticated RCE at CVSS 10.0, exploited three days before the fix. The payload runs when the store...
CVE-2026-86218 is a pre-auth RCE at CVSS 10.0, already exploited. The customer notice calls it a zero-day observed in th...
CERT Polska confirms exploitation from 2 September; the fixes landed on the 5th. The giveaway is a log entry recording a...
Two at CVSS 9.8, unauthenticated and network-reachable, none known to be exploited. The advisory names frontier AI model...
The Stop Rogue AI Act binds only federal contractors bidding new work, and gives NIST a year from enactment. It also ask...
Five carry a three-day federal clock, two carry fourteen days, in a single batch. Three of the seven sit in AI and build...
A Scripted REST API had its authentication flag set false, so anonymous requests ran as Guest. Exploited 2 to 3 June, ho...
Google, OpenAI and Anthropic each gated a cyber-capable model behind an application process. All three also disclosed ag...
CrowdStrike has shipped two models built with Nvidia: one that attacks a replica of your network, one that defends it. A...
Two new zero-days are being chained on SMA1000 appliances, in the same two components as the June pair. The July fix bui...
Softaculous says an attacker announced routes for its Hetzner-hosted addresses for about 33 hours and served a malicious...
An attacker took an API key from a researcher's personal server and spent US$600,000 of inference credits over three wee...
PaperCut has shipped a second emergency patch after researchers walked around the first. A vendor under active exploitat...
An executable in one image and a DLL split across two more. Every clever stage is post-compromise; the entry point is a...
Six commodity infostealers now sort Claude sessions out of what they harvest. The economic shape is cryptojacking's: ste...
The number the thief calls is the one the owner entered into Lost Mode so an honest finder could return the phone. Every...
Improper input validation, path traversal and command injection top the list of what attackers actually use. All three h...
For five of these, store review never had a chance. They were legitimate extensions, bought from their authors, and the...
McKesson has confirmed unauthorised access to third-party applications. The attackers say they got there by telephone, a...