Microsoft reports the CaptiveCrunch Wi-Fi gateway campaign uses hacked public Wi‑Fi gateway appliances to manipulate captive portal traffic. Attackers intercept Microsoft 365 sign-ins and steal credentials and sessions.
The PNLD data breach confirmed that police, government, and customer contact details were exposed on the dark web. PNLD says there’s no evidence passwords or other credentials were compromised.
New details suggest the US water cyberattacks extend well beyond Minnesota, with other states confirming malicious activity. Authorities also emphasize protections for OT systems.
Attackers exploited an authentication bypass to take over N-central servers and reach managed endpoints. N-able’s initial fix didn’t fully close the gap, so every customer must upgrade to 2026.3.1.7.
OpenAI hints at Astra, its next major model, reporting internal results on 10 long-unsolved math and computer science problems. It also describes formal proofs verified via Lean certificates.
Google is working on a Chrome feature that blocks policy extensions on unmanaged devices when they take over the New Tab page or search engine. This reduces the likelihood of hijackers by limiting the “implicit trust” in local policy keys.
A Coldcard hardware wallet flaw was linked to the rapid theft of about $70M in Bitcoin. Research explains how a weak seed-generation path could let attackers guess seeds offline.
A new Rails critical vulnerability (CVE-2026-66066) was patched after reports that unauthenticated attackers could read arbitrary server files. In some setups, that exposure could lead to remote code execution.
Hackers modified an Adform JavaScript file to perform crypto address swapping on affected pages. If you visited during July 27, clear your cache and double-check any wallet address before sending funds.
Researchers warn that hijacked hotel wi-fi can redirect guests to fake browser or OS update pages. These can deliver surveillance malware and token-stealing payloads.