Security news

Latest security news

24 of 1,256 storiesTopic: RegulationsClear all

Tue, 8 Sept 2026

  1. Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

    Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

    The Hacker News

Mon, 7 Sept 2026

  1. Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

    The Hacker NewsOracle, Progress
  2. Multiple Class Action Lawsuits Filed Against IDScan

    Several victims of a recent breach of driver’s license information have sued the company they believe responsible

    Infosecurity Magazine

Sat, 5 Sept 2026

  1. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

    The Hacker NewsAdobe

Fri, 4 Sept 2026

  1. IDScan sued over alleged data breach affecting 153 million drivers

    Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses.

    BleepingComputer

Thu, 3 Sept 2026

  1. Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

    Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.

    Unit 42

Wed, 2 Sept 2026

  1. FulcrumSec Claims Responsibility for Manchester Airport Group Breach

    Threat group FulcrumSec claims MAG breach and leaks 550GB of data online

    Infosecurity Magazine

Wed, 26 Aug 2026

  1. Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

    This new open standard offers hardware-attested runtime and compliance evidence for AI agents

    Infosecurity MagazineLinux

Wed, 19 Aug 2026

  1. Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America

    Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces. In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI – all without adding operational complexity. To help security leaders and practitioners address this complexity, Rapid7 is excited to announce a new strategic distribution partnership with Licencias OnLine (LOL) across Latin America. Helping organizations stay ahead of evolving threats In order to keep day-to-day business operations moving, organizations need security solutions that not only protect critical assets but also support innovation, regulatory compliance, and long-term digital transformation. Rapid7's AI-powered cybersecurity operations platform helps organizations strengthen cyber resilience by unifying continuous exposure management, AI-driven threat detection and response, and securit

    Rapid7 Blog

Tue, 18 Aug 2026

  1. New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

    You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Success going forward can’t be about patching as much as possible - it has to be about understanding what matters most and reducing the exposures attackers can actually reach. Here are the four trends that defined Q2 2026, and what they mean for your security program as you define priorities for Q3 and beyond: The volume of disclosures hit another milestone There were 8,539 new high- and critical-severity CVEs (CVSS 7.0–10.0) this quarter- double the number reported in the same quarter last year (4,268). Meanwhile, the number of newly exploited vulnerabilities held roughly steady (40). The takeaway isn’t that exploitation exploded - it’s that disclosure volume is far outstripping what any

    Rapid7 Blog

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets