From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

10/07/2026 0 Comments 0 tags

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report,

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

10/07/2026 0 Comments 0 tags

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation’s inner workings: the hacking tools, the activity logs,

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

10/07/2026 0 Comments 0 tags

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

10/07/2026 0 Comments 0 tags

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to

Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

10/07/2026 0 Comments 0 tags

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

10/07/2026 0 Comments 0 tags

A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

09/07/2026 0 Comments 0 tags

Datadog Security Labs is warning of “several overlapping campaigns” that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. “Operators rely on automated scraping tooling with

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

09/07/2026 0 Comments 0 tags

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one,

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

09/07/2026 0 Comments 0 tags

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

09/07/2026 0 Comments 0 tags

Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This