Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland's Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT's security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform and closed the vulnerabilities being exploited. READ MORE...
Denim company Levi Strauss & Co on Friday disclosed a cyberattack that affected certain corporate data stored on employee computers. The incident, it said in a Form 8-K filing with the US Securities and Exchange Commission (SEC), was the result of social engineering and affected three employees' company-issued computers. The company says its immediate response and containment actions have resulted in the attackers' eviction from the compromised computers. READ MORE...
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected. READ MORE...
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. LexisNexis is a global data analytics company providing multiple legal and business services. READ MORE...
New Jersey and Alabama have joined the list of US states that confirmed their water and wastewater facilities have been targeted in a hacking campaign that started in late July. At least 12 states have reportedly been hit, but not all have been identified. Minnesota was the first to confirm that over 30 water systems had their operational technology (OT) systems targeted. Michigan, South Dakota, and Georgia later also confirmed being targeted. READ MORE...
As developers turn to AI models to generate an increasing amount of code, they are also relying on the systems to find vulnerabilities and generate patches. Unfortunately, the models just aren't very good at their jobs. Recent research suggests that even the latest AI systems only produce effective patches about half the time, according to a report published on Aug. 6 by identity management firm 1Password. READ MORE...
LAS VEGAS -Researchers have found fifteen previously unknown vulnerabilities that affect zero-touch provisioning in TP-Link Omada, which is widely used to provision network devices from a central location, according to a report by Forescout Research - Vedere Labs. Small to medium-sized companies use the technology to rapidly set up routers and firewalls, which in some cases involves thousands of devices. READ MORE...
N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first. The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform. READ MORE...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a very popular Application Delivery Controller (ADC) and server load balancer used by tech companies and government entities worldwide (e.g., Amazon, U.S. Air Force) to distribute incoming web traffic across multiple servers, optimize app performance, and ensure high service availability. READ MORE...