Threat Intelligence
Community feed · News

Breaking Security News

The latest threat research aggregated from Breaking Security News — browse the feed inside NivX, click through to read the full article on the source site.

Article previews are curated from Breaking Security News. We show the title, cover image and a short snippet here; clicking any card opens the full article on the source site so the original authors get proper credit.
Threat Research

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue…

Oct 6, 2026
Read on News
Threat Research

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]…

Oct 6, 2026
Read on News
Threat Research

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluenc…

Oct 6, 2026
Read on News
Threat Research

ASOS confirms data breach after “HACKED” in-app notifications

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowfl…

Oct 6, 2026
Read on News
Threat Research

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser…

Oct 6, 2026
Read on News
Threat Research

How to secure RMM software: 8 controls MSPs should test

RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM s…

Oct 6, 2026
Read on News
Threat Research

Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]…

Oct 6, 2026
Read on News
Threat Research

Nikkei discloses breaches of employees’ Microsoft, Google email accounts

Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]…

Oct 6, 2026
Read on News
Threat Research

Engineer sentenced for locking over 3,000 devices on employer network

A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomwa…

Oct 6, 2026
Read on News
Threat Research

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]…

Oct 5, 2026
Read on News
Threat Research

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]…

Oct 5, 2026
Read on News
Threat Research

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposur…

Oct 5, 2026
Read on News
Threat Research

Denmark population registry data breach affects 8.8 million people

Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]…

Oct 5, 2026
Read on News
Threat Research

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]…

Oct 5, 2026
Read on News
Threat Research

South Korea probes bank breaches amid suspected AI-powered attacks

South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]…

Oct 5, 2026
Read on News