Skip to content

Category: Beveiligingsnieuws

CaptiveCrunch: how Russian APT Wi‑Fi gateway hacks work

Microsoft reports the CaptiveCrunch Wi-Fi gateway campaign uses hacked public Wi‑Fi gateway appliances to manipulate captive portal traffic. Attackers intercept Microsoft 365 sign-ins and steal credentials and sessions.

PNLD data breach: leaked contact details revealed

The PNLD data breach confirmed that police, government, and customer contact details were exposed on the dark web. PNLD says there’s no evidence passwords or other credentials were compromised.

US Water Cyberattacks Spread Across States

New details suggest the US water cyberattacks extend well beyond Minnesota, with other states confirming malicious activity. Authorities also emphasize protections for OT systems.

N-central takeover: fix not enough

Attackers exploited an authentication bypass to take over N-central servers and reach managed endpoints. N-able’s initial fix didn’t fully close the gap, so every customer must upgrade to 2026.3.1.7.

Implicit trust in Chrome policy: new blocking plan

Google is working on a Chrome feature that blocks policy extensions on unmanaged devices when they take over the New Tab page or search engine. This reduces the likelihood of hijackers by limiting the “implicit trust” in local policy keys.

Rails Critical Vulnerability: RCE Risk Patched

A new Rails critical vulnerability (CVE-2026-66066) was patched after reports that unauthenticated attackers could read arbitrary server files. In some setups, that exposure could lead to remote code execution.

Adform crypto address swapping: what happened

Hackers modified an Adform JavaScript file to perform crypto address swapping on affected pages. If you visited during July 27, clear your cache and double-check any wallet address before sending funds.