Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: 2026

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

post, februari 2, 2026februari 4, 2026

Russia-linked attackers are already exploiting Microsoft’s latest Office zero-day, with Ukraine’s national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU. In an alert published on Sunday, CERT-UA says the activity is being driven by UAC-0001, better…

Continue Reading

Head of U.S. Cyber Defence Uploaded Sensitive Documents To ChatGPT

post, januari 29, 2026januari 30, 2026

The acting director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Madhu Gottumukkala, has sparked a high-stakes internal security review after uploading sensitive government contracting documents into the public version of ChatGPT, potentially exposing material not meant for broader dissemination. While the documents were not classified, they were marked…

Continue Reading

Microsoft Rushes Emergency Fix For Actively Exploited Office Zero-Day

post, januari 26, 2026januari 27, 2026

Microsoft has issued emergency, out-of-band security updates to address a high-severity zero-day vulnerability in Microsoft Office that is already being exploited in real-world attacks, underscoring the persistent security challenges facing one of the world’s most widely deployed productivity platforms. The flaw, tracked as CVE-2026-21509, is classified as a security feature…

Continue Reading

Fortinet Confirms Ongoing Exploitation of Critical FortiCloud SSO Flaw Despite Patch

post, januari 24, 2026januari 26, 2026

Fortinet has confirmed that a critical authentication bypass vulnerability affecting its FortiCloud Single Sign-On (SSO) implementation has not been fully remediated, even on systems that were previously believed to be fully patched. The disclosure follows mounting evidence from customers and security researchers that attackers have continued to successfully compromise FortiGate…

Continue Reading

Sandworm hackers linked to failed wiper attack on Poland’s energy systems

post, januari 24, 2026januari 26, 2026

A cyberattack targeting Poland’s power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. Sandworm (also tracked as UAC-0113, APT44, and Seashell Blizzard) is a Russian nation-state hacking group that…

Continue Reading

Belgian hospital AZ Monica shuts down servers after cyberattack

post, januari 13, 2026januari 26, 2026

Belgian hospital AZ Monica was forced to shut down all servers, cancel scheduled procedures, and transfer critical patients earlier today due to a cyberattack. The hospital, which operates campuses in Antwerp and Deurne, disconnected all servers at 6:32 AM after its systems were hit. The cyberattack also forced the hospital…

Continue Reading

‘Most Severe AI Vulnerability to Date’ Hits ServiceNow

post, januari 13, 2026januari 14, 2026

Authentication issues in ServiceNow potentially opened the door for arbitrary attackers to gain full control over the entire platform and access to the various systems connected to it. ServiceNow is a Fortune 500 company that, according to its promotional materials, acts as an IT services management platform for 85% of the…

Continue Reading

European Space Agency Confirms Cybersecurity Breach As Hackers Claim Theft of 200GB of Data

post, januari 5, 2026

The European Space Agency (ESA) has confirmed it is responding to a cybersecurity incident involving several externally hosted science servers, following claims by hackers that they exfiltrated up to 200 gigabytes of internal data. While ESA says no classified or mission-critical systems were affected, cybersecurity experts warn the incident highlights…

Continue Reading

FBI Identifies Lazarus Group Cyber Actors as Responsible for Theft of $41 Million from Stake.com

post, september 6, 2023juli 31, 2026

The FBI is issuing this release to warn the public regarding the theft of approximately $41 million in virtual currency from Stake.com, an online casino and betting platform. The FBI has confirmed that this theft took place on or about September 4, 2023, and attributes it to the Lazarus Group…

Continue Reading
  • Previous
  • 1
  • …
  • 15
  • 16

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes