UK Teen Hackers Jailed for TfL Cyberattack
Two young members of the Scattered Spider group received 5.5-year sentences for disrupting Transport for London services. The breach impacted thousands of employees and cost millions in recovery.
Read moreSecurity insights, vulnerability roundups, and updates from the Agent Breach team.
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Two young members of the Scattered Spider group received 5.5-year sentences for disrupting Transport for London services. The breach impacted thousands of employees and cost millions in recovery.
Read moreMultiple high-severity vulnerabilities found in Authlib could allow attackers to bypass authentication and perform unauthorized actions. These flaws impact JWT validation, token encryption, and OAuth integrations.
Read moreUbuntu addresses tar utility regression that prevented extraction of valid files. The fix resolves issues from previous security patch.
Read moreA critical SharePoint Server vulnerability, CVE-2026-58644, has been added to CISA's KEV catalog. Federal agencies must patch by July 19, 2026.
Read moreUbuntu has issued a security notice addressing several high-risk vulnerabilities in Apache Tomcat that could lead to authorization bypass, XSS, and reduced auditability. Organizations running Tomcat should apply updates immediately.
Read moreA critical input validation flaw in Sympa's single sign-on login enables remote path traversal attacks. Organizations using Sympa should patch immediately to prevent unauthorized access.
Read moreA stealthy malware framework compromises desktop apps to steal crypto seed phrases. Security teams should monitor for unusual wallet behaviors.
Read moreMultiple critical flaws in .NET impact authentication, XML encryption, and TLS handling. These issues may allow attackers to elevate privileges or trigger denial of service.
Read moreResearchers uncover TuxBot v3, an IoT botnet showing signs of LLM-assisted development. Despite AI involvement, the botnet's effectiveness remains limited due to poor implementation.
Read moreCritical flaws in Dnsmasq allow remote attackers to crash services or access sensitive data. Organizations using Ubuntu should update immediately.
Read more