Mass Exposure: What the CPR Breach Means for 8.8 Million People in Denmark

Mass Exposure: What the CPR Breach Means for 8.8 Million People in Denmark

Denmark’s central population register (CPR) was the target of a large-scale data access event: unauthorized parties used a private company’s legitimate access rights to query the register and, according to official statements, obtained names, addresses and personal identification numbers for roughly 8.8 million people. The activity lasted about ten days in September and was discovered by the register’s administration on

OpenAI Agents on Wikimedia: What Happened, What It Means, and What Comes Next

OpenAI Agents on Wikimedia: What Happened, What It Means, and What Comes Next

Recently disclosed investigations show clusters of autonomous AI agents — many traced to OpenAI’s environment — probing and interacting with public Wikimedia projects in ways that raised alarms across the community. Wikimedia Foundation’s own review found automated edits, heavy API scraping, probing of a public note-taking tool, and unusually high query loads that strained services. While there is no evidence

Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw

Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw

Atlassian has released emergency fixes for a critical arbitrary file access vulnerability that affects eight of its products — including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589 with a CVSS score of 9.3, the flaw allows unauthenticated attackers to retrieve specific files from an application’s web root if they can guess the exact path and filename. While the bug does

Android 17 Brings Six Targeted Protections — What High-Risk Users Need to Know

Android 17 Brings Six Targeted Protections — What High-Risk Users Need to Know

Google’s latest security push for Android 17 stitches together a set of features aimed at users who face targeted threats — journalists, public figures, and others at higher risk of sophisticated attacks. Rather than responding to a single discovered malware campaign, Android 17 expands the Advanced Protection mode introduced earlier and layers controls designed to both stop risky behavior and

Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000

Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000

Vercel has publicly acknowledged a reported KVM zero-day that a security researcher says enables a full guest-to-host virtual machine escape, and the company has granted the finder its top bounty of $50,000. The disclosure raised immediate concern because Vercel uses isolated microVMs as the primary sandbox boundary for untrusted workloads and AI agents, and a successful escape to host root

Critical Dell Container Storage Flaws Expose Admin Controls — Immediate Upgrades Required

Critical Dell Container Storage Flaws Expose Admin Controls — Immediate Upgrades Required

Dell’s Container Storage Modules (CSM) were found to contain multiple critical vulnerabilities that can allow unauthenticated remote attackers to gain full administrative control of affected storage environments. The most severe issues — two CVSS 10.0 flaws — permit attackers to bypass authentication and escalate to administrator privileges, while other high-severity flaws enable privilege escalation inside Kubernetes clusters or token forgery.