The secret ballot is one of the load-bearing walls of democracy. In Georgia, as in most states, this allows you to know whether your neighbor voted, but never who they voted for. This simple guarantee allows for transparent elections while deterring voter intimidation. Yet, in multiple states including Georgia, that guarantee is actively at risk. To keep the published record anonymous, ballot scanners shuffle the electronic records randomly before releasing them. READ MORE...
Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United States and Canada. READ MORE...
Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition (M&A) deals. It's one of the oldest gambits in cybersecurity - the advance fee scam - for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. READ MORE...
Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. READ MORE...
A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. READ MORE...
Cloud-based AI models operated by OpenAI, Anthropic, xAI, and Google suffered a rare and overlapping set of significant service interruptions over a period of hours Thursday morning. Anthropic first reported a "partial outage" related to "elevated errors on requests to Claude Mythos 5.1, Claude Fable 5.1, and Claude Opus 5" at 9:23 am (all times Eastern). The company reported that it had "identified the cause" of the error roughly 15 minutes later. READ MORE...
"Free" movies and TV could cost you your privacy, bandwidth, and control of your home network. We've warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. Besides affecting connectivity, this can mean that a household's public IP address becomes associated with activity it did not initiate. READ MORE...
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike's Falcon endpoint security platform - albeit with a Windows link. FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature. READ MORE...
PostgreSQL releases since 2014 contain a severe vulnerability that allows attacker with low privileges to take over databases and servers, cybersecurity firm Cyera reports. An open source relational database system offering support for both relational (SQL) and non-relational (JSON) queries, PostgreSQL is one of the most popular databases, being used by tens of thousands of companies, including large enterprises. READ MORE...
Passkeys were introduced with a strong security proposition. Replace passwords with public key cryptography, bind the credential to the legitimate service, keep the private key away from the server, and many of the phishing and credential theft attacks that have plagued enterprise security for decades become dramatically harder. All of that is true. But the security conversation has changed very quickly. READ MORE...