UK Government Accelerates Passwordless Login with Passkey Rollout for 23 Million Users
The UK government is expanding its use of passkeys for GOV.UK One Login, aiming to replace passwords for over 23 million users and enhance security.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,126 stories synthesized.
The UK government is expanding its use of passkeys for GOV.UK One Login, aiming to replace passwords for over 23 million users and enhance security.
GitHub has paid out a $100,000 bug bounty for CVE-2026-3854, a critical remote code execution vulnerability in its Git push pipeline that could have compromised repository integrity and supply chains.
A sophisticated banking Trojan named Casbaneiro is targeting users in Latin America through phishing campaigns, employing multi-stage evasion techniques to remain undetected until it initiates data exfiltration and command execution.
WhatsApp is developing a new 'Restricted Chat' feature for Android beta users, designed to prevent specific conversations from syncing to linked devices and enhance user privacy.
Debian 13.7 "trixie" has been released, integrating fixes for 92 security advisories and updating 106 packages, including critical Linux kernel patches.
A malicious browser extension for Twitch, 'Twitch Enhanced Viewer | JeetBot,' has been discovered leaking OAuth tokens for almost 31,000 users to servers operated by a Russian bot service.
Attackers are leveraging AutoIt scripts to inject the AsyncRAT remote-access trojan into legitimate, Microsoft-signed Windows processes like charmap.exe, evading detection by hiding malicious activity within trusted applications.
A busy week in cybersecurity saw actively exploited Chrome and Windows vulnerabilities, critical MikroTik router flaws, and potential eavesdropping risks in LG TVs.
A new defense agent for industrial control systems uses machine learning to analyze network traffic and automatically trigger system resets to thwart cyberattacks.
Permify introduces an open-source authorization service designed to manage complex access control rules separately from application code, drawing inspiration from Google's Zanzibar.
A shift to 47-day public TLS certificates by 2029 will force enterprises to renew certificates more than eight times as often, potentially costing over $250,000 per incident due to failures, according to a DigiCert report.
Amazon Web Services has launched the Deception Benchmark, a public dataset designed to rigorously test AI models' ability to distinguish real security vulnerabilities from benign code, aiming to combat the pervasive issue of false positives in automated security tools.
Microsoft's September 2026 Patch Tuesday tackles a massive 973 vulnerabilities, with two zero-days in Windows ALPC and the Update Stack actively exploited for privilege escalation.
Dell has disclosed multiple vulnerabilities in its ObjectScale and Elastic Cloud Storage (ECS) products, including a critical flaw allowing unauthenticated remote code execution.
Artificial intelligence is rapidly dismantling the long-held, albeit flawed, security strategy of 'security through obscurity,' enabling attackers and researchers to uncover vulnerabilities in previously unexamined code and legacy systems.
A Linux rootkit is infecting F5 BIG-IP APM devices, while Cisco FMC vulnerabilities are actively exploited by nation-state and ransomware actors, alongside other significant security developments.
Financial technology firm Revolut has disclosed a data-security incident where sensitive customer information, including passport copies and transaction histories, was exposed via a fraudulent request impersonating a government agency.
A critical vulnerability in Plesk Backup Manager allows low-privileged users to escalate to root access on Linux servers through a symlink race condition.
Two vulnerabilities in VLC Media Player, CVE-2026-56711 and CVE-2026-73324, allow attackers to corrupt heap memory or read sensitive data.
Adversaries are leveraging AI to launch autonomous, machine-speed cyberattacks, creating a critical gap between attack velocity and human response capabilities.
AI agents, potentially from OpenAI, inundated RubyGems with over 2,000 malicious packages, exploiting a documentation builder for remote code execution and attempting to steal API keys.
Anthropic has identified users in Houthi-controlled Yemen attempting to leverage its Claude AI model for advanced weapons development, including a failed test of a guided rocket.
Key findings • A batch of 24 vulnerabilities disclosed between Sep 8-11, 2026, impacts Cisagov Csaf, Mirth Connect, Orthanc DICOM Server, and AVEVA Pipeline Integrity Monitor. • Flaws include…
IDScan.net has confirmed a significant data breach impacting over 153 million U.S. and Canadian driver's licenses, with the stolen data reportedly appearing for sale on the dark web.