Meta Removes End-to-End Encryption from Instagram Direct Messages
Meta has officially removed end-to-end encryption for Instagram direct messages, granting the company the ability to access user content and sparking backlash from privacy advocates.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,734 stories synthesized.
Meta has officially removed end-to-end encryption for Instagram direct messages, granting the company the ability to access user content and sparking backlash from privacy advocates.
TrustCloud has updated its TrustLens platform with agentic AI designed to automate third-party risk assessments and shift the industry away from static, questionnaire-based models.
The ShinyHunters ransomware group has escalated its attack on Instructure's Canvas LMS by defacing hundreds of institutional login pages with ransom demands after an initial deadline passed.
Apple has released watchOS 26.5 (build 23T570) on May 11, 2026, including security fixes for undisclosed vulnerabilities.
Apple has released iPadOS 15.8.8 (build 19H422) as a security update for older iPad models, addressing unspecified vulnerabilities.
Apple has released iPadOS 17.7.11 (build 21H461) as a security update addressing unspecified vulnerabilities, urging users to apply the patch promptly.
Apple released iPadOS 26.5 (build 23F77) on May 11, 2026, addressing undisclosed security vulnerabilities in the operating system.
Apple has released visionOS 26.5 (build 23O471) for the Apple Vision Pro, addressing security vulnerabilities in the operating system.
Apple released iOS 18.7.9 (build 22H355) on May 11, 2026, as a security-focused update addressing undisclosed vulnerabilities in the operating system.
Apple has released iOS 16.7.16 (build 20H392) for older iPhone models, addressing undisclosed security vulnerabilities in the iOS 16 operating system.
Apple has released iPadOS 16.7.16 (build 20H392) on May 11, 2026, addressing security vulnerabilities in the operating system.
Apple has released iOS 15.8.8 (build 19H422) as a security update for devices that cannot run the latest iOS 18, patching undisclosed vulnerabilities in the older operating system.
The ransomware ecosystem has shifted toward a consolidated model in early 2026, with a small number of dominant groups now responsible for the vast majority of global attacks.
A malicious, backdoored version of the Checkmarx Jenkins AST plugin was uploaded to the Jenkins Marketplace by the threat group TeamPCP, marking the third supply-chain compromise of the firm in as many months.
A new report from F-Secure reveals that cybercriminals are increasingly weaponizing artificial intelligence to poison search results and automate the creation of highly convincing, deceptive content.
A new variant of the TrickMo Android banking malware is using The Open Network (TON) blockchain to hide its command-and-control traffic, allowing it to evade traditional network detection and takedown efforts.
The ShinyHunters group breached Zara, compromising over 197,000 customer records after stealing authentication tokens from analytics provider Anodot.
Instructure has confirmed that the Canvas learning platform was breached twice by the ShinyHunters extortion group, leading to a global outage and a subsequent agreement to secure the destruction of stolen data.
A university student successfully disabled Taiwan's entire bullet train system for nearly an hour by exploiting vulnerabilities in the aging TETRA radio communication standard using low-cost, off-the-shelf hardware.
A high-severity local privilege escalation vulnerability affecting the Linux kernel is currently being exploited in the wild, prompting urgent patch releases across major distributions.
A malicious Hugging Face repository impersonating OpenAI's Privacy Filter model successfully infected over 244,000 users with a Rust-based information stealer.
WhatsApp has released an urgent security update to patch two critical vulnerabilities that could allow attackers to compromise user devices via malicious file delivery.
A new open-source endpoint detection agent named Rustinel has been released, offering a unified, user-mode approach to telemetry collection and threat detection across Windows and Linux systems.
The second edition of *Foundations of Cybersecurity* by Jason Andress has been released, offering an updated curriculum that integrates modern security challenges, including AI-specific threats and evolving operational requirements.