❌

Normal view

As agents run amok, CrowdStrike's $740M SGNL deal aims to help get a grip on identity security

8 January 2026 at 23:09

Authentication is basically solved. Authorization is another thing entirely...

CrowdStrike has signed a $740 million deal to buy identity security startup SGNL. The move underscores the growing threat of identity-based attacks as companies struggle to secure skyrocketing numbers of non-human identities, including AI agents.…

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit

8 January 2026 at 19:43

No reports of active exploitation … yet

Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with admin-level privileges to access sensitive information - and warned that a public, proof-of-concept exploit for the flaw exists online.…

ESA calls cops as crims lift off 500 GB of files, say security black hole still open

7 January 2026 at 19:02

Two weeks, two major data leaks … not a good look for the European Space Agency

exclusiveΒ  The European Space Agency on Wednesday confirmed yet another massive security breach, and told The Register that the data thieves responsible will be subject to a criminal investigation. And this could be a biggie.…

HackerOne 'ghosted' me for months over $8,500 bug bounty, says researcher

7 January 2026 at 01:17

Long after CVEs issued and open source flaws fixed

Last fall, Jakub Ciolek reported two denial-of-service bugs in Argo CD, a popular Kubernetes controller, via HackerOne's Internet Bug Bounty (IBB) program. Both were assigned CVEs and have since been fixed. But instead of receiving an $8,500 reward for the two flaws, Ciolek says, HackerOne ghosted him for months.…

One criminal, 50 hacked organizations, and all because MFA wasn't turned on

6 January 2026 at 08:01

Crim used infostealer to get cloud credentials

If you don't say "yes way" to MFA, the consequences can be disastrous. Sensitive data belonging to about 50 global enterprises is listed for sale – and, in some cases, has already been sold – on the dark web following a major infostealer campaign, with apparent victims including American utility engineering firm Pickett and Associates; Japan's homebuilding giant Sekisui House; and Spain's largest airline Iberia.…

Congrats, cybercrims: You just fell into a honeypot

5 January 2026 at 21:21

A subpoena has been issued, apparently

Resecurity offered its "congratulations" to the Scattered Lapsus$ Hunters cybercrime crew for falling into its threat intel team's honeypot – resulting in a subpoena being issued for one of the data thieves. Meanwhile, the notorious extortionists have since removed their claims of gaining "full access" to the security shop's systems.…

Cybercrook claims to be selling infrastructure info about three major US utilities

2 January 2026 at 19:34

For the bargain price of 6.5 bitcoin

A cybercrook claims to have breached Pickett and Associates, a Florida-based engineering firm whose clients include major US utilities, and is selling what they claim to be about 139 GB of engineering data about Tampa Electric Company, Duke Energy Florida, and American Electric Power.Β The price is 6.5 bitcoin, which amounts to about $585,000.…

❌