Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Coinbase confirms insider breach linked to leaked support tool screenshots

post, februari 4, 2026

Coinbase has confirmed an insider breach after a contractor improperly accessed the data of approximately thirty customers, which BleepingComputer has learned is a new incident that occurred in December. “Last year our security team detected that a single Coinbase contractor improperly accessed customer information, impacting a very small number of…

Continue Reading

Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days

post, februari 3, 2026februari 4, 2026

In the latest illustration of how quickly attackers can exploit newly disclosed flaws, Russia’s notorious APT28 cyber-espionage group has begun abusing a recently patched Microsoft vulnerability to steal emails and deploy malicious payloads against organizations in Central and Eastern Europe. CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office…

Continue Reading

DOJ Reveals Jeffrey Epstein Employed An Elite Hacker With Global Cyber Connections

post, februari 3, 2026februari 4, 2026

Newly disclosed Department of Justice documents suggest that convicted sex offender Jeffrey Epstein may have maintained a close relationship with a highly skilled and internationally connected hacker, according to statements made by a confidential informant to the Federal Bureau of Investigation in 2017. The claims, contained in a heavily redacted…

Continue Reading

Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users

post, februari 2, 2026februari 2, 2026

The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility’s update mechanism to redirect update traffic to malicious servers instead. “The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” developer Don Ho said. “The compromise occurred at the hosting…

Continue Reading

How the KGB Discovered Computer Viruses

post, februari 2, 2026februari 4, 2026

A 1989 internal memo warned the Soviet security apparatus about a new threat: malicious software that was spreading among users across the USSR and even within the KGB itself. In this post I will review an archival KGB document on computer viruses available through the Lithuanian Genocide and Resistance Research…

Continue Reading

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

post, februari 2, 2026februari 4, 2026

Russia-linked attackers are already exploiting Microsoft’s latest Office zero-day, with Ukraine’s national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU. In an alert published on Sunday, CERT-UA says the activity is being driven by UAC-0001, better…

Continue Reading

Head of U.S. Cyber Defence Uploaded Sensitive Documents To ChatGPT

post, januari 29, 2026januari 30, 2026

The acting director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Madhu Gottumukkala, has sparked a high-stakes internal security review after uploading sensitive government contracting documents into the public version of ChatGPT, potentially exposing material not meant for broader dissemination. While the documents were not classified, they were marked…

Continue Reading

Microsoft Rushes Emergency Fix For Actively Exploited Office Zero-Day

post, januari 26, 2026januari 27, 2026

Microsoft has issued emergency, out-of-band security updates to address a high-severity zero-day vulnerability in Microsoft Office that is already being exploited in real-world attacks, underscoring the persistent security challenges facing one of the world’s most widely deployed productivity platforms. The flaw, tracked as CVE-2026-21509, is classified as a security feature…

Continue Reading

Fortinet Confirms Ongoing Exploitation of Critical FortiCloud SSO Flaw Despite Patch

post, januari 24, 2026januari 26, 2026

Fortinet has confirmed that a critical authentication bypass vulnerability affecting its FortiCloud Single Sign-On (SSO) implementation has not been fully remediated, even on systems that were previously believed to be fully patched. The disclosure follows mounting evidence from customers and security researchers that attackers have continued to successfully compromise FortiGate…

Continue Reading

Sandworm hackers linked to failed wiper attack on Poland’s energy systems

post, januari 24, 2026januari 26, 2026

A cyberattack targeting Poland’s power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. Sandworm (also tracked as UAC-0113, APT44, and Seashell Blizzard) is a Russian nation-state hacking group that…

Continue Reading
  • Previous
  • 1
  • …
  • 15
  • 16
  • 17
  • …
  • 47
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes