top of page
All Articles


Researchers identify a more capable DarkSword iPhone spyware variant
Mobile-security company iVerify says it found a previously unseen variant of DarkSword while investigating an infection on a customer’s iPhone in August. Its 8 October report calls the variant P7 DarkSword. This is new analysis of a real case, rather than proof that every iPhone is currently being t
2 hours ago1 min read


Three teams demonstrate remote Pixel 10 attacks at security contest
Three teams successfully demonstrated remote attacks against a Google Pixel 10 during the third day of Pwn2Own Ireland on 8 October. The Zero Day Initiative, which runs the supervised contest, recorded three separate successful attempts. One team combined multiple weaknesses; another used a two-bug
2 hours ago1 min read


New research explains how PaperCut print-server fixes were bypassed
Researchers at watchTowr have published a detailed account of flaws in PaperCut NG and MF, software that manages printing for schools, offices and other organisations. PaperCut warned of active attacks on 27 August. The new 9 October research explains how an authentication weakness could be combined
2 hours ago1 min read


Attack attempts target recently patched SonicWall remote-access devices
A security researcher says a monitoring network has seen requests consistent with attempts to exploit CVE-2026-102255, a serious flaw in SonicWall SMA 1000 remote-access appliances. These devices help staff connect to an organisation’s internal systems. The researcher told BleepingComputer that the
2 hours ago1 min read


Citrix urges updates for NetScaler login-system flaw
Citrix has urged customers to update affected NetScaler ADC and NetScaler Gateway appliances after disclosing CVE-2026-107406. These products can sit at the entrance to business applications and remote-access services. Citrix says a memory-handling flaw could allow remote code execution—running an a
2 hours ago1 min read


Backup software attacks continue after researchers revise patch advice
Huntress has observed attackers exploiting two flaws in AhsayCBS, software that helps IT providers manage customer backups. In five organisations it had seen targeted by 8 October, attackers used the flaws to run commands on exposed servers. They installed *web shells*—small files that provide remot
2 hours ago1 min read


Fake Claude download uses search adverts and a misleading copy button
Push Security has described a malicious advert shown for a search about Claude on a Mac. The sponsored result appeared to lead to Bing, a familiar search engine. A click passed through Bing’s normal result redirect, then a compromised retailer’s website, before arriving at a fake Claude download pag
2 hours ago1 min read


Microsoft sets out the steps needed before Windows Update certificates expire
Microsoft has explained how it will replace certificates that Windows Update uses to recognise trusted update services. Certificates are digital proofs of identity. The current set expires in May and June 2027, so this is a preparation notice, not a report that Windows Update has stopped working tod
2 hours ago1 min read


Android’s October security bulletin: how to check your phone is updated
Smartphone displaying a security shield and update arrows, surrounded by app and settings icons.
3 days ago2 min read


US utilities notify customers after breach affecting around 400,000 accounts
Utility customer account panel and contact-information envelope beside a residential neighbourhood.
3 days ago2 min read


Advantest confirms personal data theft in February cyberattack
Identity documents and an envelope inside a translucent shield beside semiconductor testing equipment.
3 days ago2 min read


WordPress plugin attacks can leave hidden administrator accounts
Website forms and shop panel with an amber data ribbon leading to a hidden administrator key.
3 days ago2 min read
bottom of page