A major breach at Nordic/Benelux IT supplier Dustin has led it to take systems offline. Webshops are down, and orders and deliveries have stopped.
Attackers are exploiting a Chrome V8 zero-day.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
Tails 7.12 is out as the first release under the project’s new two-week cadence, bringing Tor Browser 15.0.21, Electrum 4.8.1, and updated firmware.
US military disables ad trackers on devices amid location-data targeting concerns
US military officials have said they disabled advertising trackers on a range of phones and computers, according to letters released on Friday by US Senator Ron Wyden and statements provided to Reuters. The move follows reports that commercially available location data had been used to target US forces in West Asia.
US military officials have said they disabled advertising trackers on a range of phones and computers, according to letters released on Friday by US Senator Ron Wyden and statements provided to Reuters. The move follows reports that commercially available location data had been used to target US forces in West Asia.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog.
Cyber Dispatch™️
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog.
Singapore police outfit Digital Disruption Centre blocks VestoFX Trader Investment App.
PostgreSQL releases since 2014 contain a severe vulnerability that allows attacker with low privileges to take over databases and servers, cybersecurity firm Cyera reports.
Tracked as CVE-2026-6471 (CVSS score of 7.2) and referred to as PostGREShell, the recently identified security defect can be exploited for remote code execution and privilege escalation.
Tracked as CVE-2026-6471 (CVSS score of 7.2) and referred to as PostGREShell, the recently identified security defect can be exploited for remote code execution and privilege escalation.
Palo Alto Networks CEO: ~$1 Trillion in Cybersecurity Infrastructure May Need to Be Modernized for the AI Era.
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted.
COURT RULING: X Corp. blocks "Twitter" use, but loses "tweet" — Operation Bluebird rebrands and launches "Tweet" app live.
The legal twist? Bluebird's co-founder is a former Twitter trademark attorney who exploited abandonment claims. X has countersued.
App features AI fact-checker VERA, charges $20 for usernames.
Case ongoing. Trademark abandonment law in the spotlight.
The legal twist? Bluebird's co-founder is a former Twitter trademark attorney who exploited abandonment claims. X has countersued.
App features AI fact-checker VERA, charges $20 for usernames.
Case ongoing. Trademark abandonment law in the spotlight.
Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
TOR BROWSER 15.0.21 AND TAILS 7.12 RELEASED — IMPORTANT SECURITY UPDATES INCLUDED
The Tor Project has released Tor Browser 15.0.21, followed by Tails 7.12, bringing important browser security fixes and beginning a faster update cycle for the privacy-focused ecosystem.
TOR BROWSER 15.0.21
Released September 1, the new Tor Browser version includes important security updates inherited from Firefox.
Key changes include:
* Firefox updated to 140.15.0 ESR on Windows, macOS and Linux
* GeckoView updated to 140.15.0 ESR on Android
* Security fixes backported from Firefox 155
* OpenSSL updated to 3.5.8
* NoScript updated to 13.6.32.1984
* Go updated to 1.25.14 for Windows, Linux and Android builds
* Additional TorConnect fixes
TAILS 7.12
Released September 3, Tails 7.12 incorporates the new Tor Browser release and several additional updates.
* Tor Browser updated to 15.0.21
* Electrum updated from 4.7.2 to 4.8.1
* Firmware packages updated
* Improved compatibility with newer graphics cards, Wi-Fi hardware and other devices
* Automatic upgrades available from Tails 7.0 or later
But another important change is happening behind the scenes:
TOR BROWSER AND TAILS ARE MOVING TO A TWO-WEEK RELEASE CYCLE.
Firefox is switching to a two-week release cadence beginning in September.
Tor Browser and Tails are following that schedule, with Tails 7.12 becoming the first Tails release under the new cadence.
Analyst Note:
For privacy-focused systems, browser security updates carry particular importance.
Tor Browser sits directly between the user and potentially hostile web content, while Tails is specifically designed for environments where privacy, anonymity and operational security can be critical.
A shorter release cycle can reduce the time between upstream Firefox security changes and their arrival in the Tor/Tails ecosystem.
For journalists, researchers, activists, threat-intelligence analysts and others relying on these platforms:
Anonymity does not replace endpoint security.
Keeping Tor Browser and Tails current remains part of the security model.
Official sources:
Tor Project — Tor Browser 15.0.21
https://blog.torproject.org/new-release-tor-browser-15021/
Tails — Version 7.12
https://tails.net/news/version_7.12/
The Tor Project has released Tor Browser 15.0.21, followed by Tails 7.12, bringing important browser security fixes and beginning a faster update cycle for the privacy-focused ecosystem.
TOR BROWSER 15.0.21
Released September 1, the new Tor Browser version includes important security updates inherited from Firefox.
Key changes include:
* Firefox updated to 140.15.0 ESR on Windows, macOS and Linux
* GeckoView updated to 140.15.0 ESR on Android
* Security fixes backported from Firefox 155
* OpenSSL updated to 3.5.8
* NoScript updated to 13.6.32.1984
* Go updated to 1.25.14 for Windows, Linux and Android builds
* Additional TorConnect fixes
TAILS 7.12
Released September 3, Tails 7.12 incorporates the new Tor Browser release and several additional updates.
* Tor Browser updated to 15.0.21
* Electrum updated from 4.7.2 to 4.8.1
* Firmware packages updated
* Improved compatibility with newer graphics cards, Wi-Fi hardware and other devices
* Automatic upgrades available from Tails 7.0 or later
But another important change is happening behind the scenes:
TOR BROWSER AND TAILS ARE MOVING TO A TWO-WEEK RELEASE CYCLE.
Firefox is switching to a two-week release cadence beginning in September.
Tor Browser and Tails are following that schedule, with Tails 7.12 becoming the first Tails release under the new cadence.
Analyst Note:
For privacy-focused systems, browser security updates carry particular importance.
Tor Browser sits directly between the user and potentially hostile web content, while Tails is specifically designed for environments where privacy, anonymity and operational security can be critical.
A shorter release cycle can reduce the time between upstream Firefox security changes and their arrival in the Tor/Tails ecosystem.
For journalists, researchers, activists, threat-intelligence analysts and others relying on these platforms:
Anonymity does not replace endpoint security.
Keeping Tor Browser and Tails current remains part of the security model.
Official sources:
Tor Project — Tor Browser 15.0.21
https://blog.torproject.org/new-release-tor-browser-15021/
Tails — Version 7.12
https://tails.net/news/version_7.12/
Berlin has launched a crisis response after hackers published data stolen from the city government.
The cyberattack affected two government departments, the ransomware group Rhysida claims it stole around 5.79 TB of data from Berlin’s systems, including thousands of contracts and other documents.
The cyberattack affected two government departments, the ransomware group Rhysida claims it stole around 5.79 TB of data from Berlin’s systems, including thousands of contracts and other documents.
Attackers hijack MikroTik routers through internet-exposed SSH. No authentication required.
A critical VMware flaw can turn local VM admin access into host code execution.
Broadcom fixed CVE-2026-59346 and an HGFS flaw in Workstation and Fusion 26H1u1. Both affect 25H2 and 26H1, with no workarounds or known exploitation.
Broadcom fixed CVE-2026-59346 and an HGFS flaw in Workstation and Fusion 26H1u1. Both affect 25H2 and 26H1, with no workarounds or known exploitation.
Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores.
No login required. No published CVE. No Adobe patch yet.
No login required. No published CVE. No Adobe patch yet.
Attackers breached JetBrains Cadence via an unpatched TeamCity server, extracting AWS IAM credentials from a 2024 backup and accessing user data and S3 files.
JetBrains is urging users to rotate secrets and treat all Cadence executions as untrusted.
JetBrains is urging users to rotate secrets and treat all Cadence executions as untrusted.
Attackers are exploiting a PaperCut authentication bypass and RCE chain against schools and universities in the U.S. and Europe.
The attacks enable credential theft, privileged account creation, registry hive collection, and Meterpreter deployment.
The attacks enable credential theft, privileged account creation, registry hive collection, and Meterpreter deployment.