IP-camera security against spying
Russian state actors—along with hacktivists and criminals—abuse IP cameras for spying and attacks. Discover practical steps for organizations and home users.
Russian state actors—along with hacktivists and criminals—abuse IP cameras for spying and attacks. Discover practical steps for organizations and home users.
Dora Horjus is per 1 juli benoemd als programmamanager bij NCSC. In die rol stuurt ze bestuurlijke samenwerking én de weg naar een fysiek House of Cyber rond 2030.
A new Office update alert warns of multiple Microsoft Office vulnerabilities across Word, Excel, PowerPoint, and SharePoint. One SharePoint flaw is actively exploited, so installing updates fast is critical.
The NCSC reports severe WordPress Core vulnerabilities that have already been exploited. If you run WordPress, install the security updates as soon as possible.
The NCSC reports multiple critical vulnerabilities in Oracle Fusion Middleware components. Because they can be exploited remotely without authentication, organizations should install Oracle security updates immediately.
The GoSerpent backdoor campaign targeted government and diplomatic entities in Southeast Asia, combining stealthy remote access with staged credential dumping and file exfiltration.
Two recent incidents in Latin America show a new extortion pattern: attackers encrypt disks with BitLocker and trigger ransom notes via office printers. The cases also reveal recurring misuse of RDP, MSSQL misconfigurations, and RMM tools.
GenieLocker ransomware has been active since March 2026 and targets victims across multiple sectors. It runs on Windows, Linux and ESXi and uses a custom encryption mechanism.
In Central Asia, since January 2025, two new backdoors have been observed: OctLurk and SilkLurk. The attackers use customized loaders, heavy obfuscation, and additional functionality via plug-ins and LurkProxy.
Rapid7 has published a Python PoC to test for CVE-2026-16232. This SmartConsole auth bypass lets attackers obtain an admin login token if the setup allows unauthenticated access.