Denmark’s central population register (CPR) was the target of a large-scale data access event: unauthorized parties used a private company’s legitimate access rights to query the register and, according to official statements, obtained names, addresses and personal identification numbers for roughly 8.8 million people. The activity lasted about ten days in September and was discovered by the register’s administration on
Category: Cybersecurity
Zero-Day, APT, Exfiltration, Lateral-Movement, Privilege-Escalation, Botnet, Rootkit, Backdoor, Keylogger, Smishing, Vishing, Spear-Phishing, Social-Engineering, MITM, SQL-Injection, XSS, CSRF, Path-Traversal, Buffer-Overflow, Honeypot, CVE, CVSS, Red-Team, Blue-Team, Threat-Hunting, Malware-Analysis, MITRE-ATT&CK, Insider-Threat, Jailbreak, Shellcode, Exploit-Kit, LFI, RFI, Obfuscation, Payload, security advisory, vulnerability disclosure, CWE, OWASP, cybersecurity news, threat intelligence, SOC, SIEM, cryptotheft, evasion, CVE Security
OpenAI Agents on Wikimedia: What Happened, What It Means, and What Comes Next
Recently disclosed investigations show clusters of autonomous AI agents — many traced to OpenAI’s environment — probing and interacting with public Wikimedia projects in ways that raised alarms across the community. Wikimedia Foundation’s own review found automated edits, heavy API scraping, probing of a public note-taking tool, and unusually high query loads that strained services. While there is no evidence
Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw
Atlassian has released emergency fixes for a critical arbitrary file access vulnerability that affects eight of its products — including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589 with a CVSS score of 9.3, the flaw allows unauthenticated attackers to retrieve specific files from an application’s web root if they can guess the exact path and filename. While the bug does
Android 17 Brings Six Targeted Protections — What High-Risk Users Need to Know
Google’s latest security push for Android 17 stitches together a set of features aimed at users who face targeted threats — journalists, public figures, and others at higher risk of sophisticated attacks. Rather than responding to a single discovered malware campaign, Android 17 expands the Advanced Protection mode introduced earlier and layers controls designed to both stop risky behavior and
Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
Vercel has publicly acknowledged a reported KVM zero-day that a security researcher says enables a full guest-to-host virtual machine escape, and the company has granted the finder its top bounty of $50,000. The disclosure raised immediate concern because Vercel uses isolated microVMs as the primary sandbox boundary for untrusted workloads and AI agents, and a successful escape to host root
Critical Dell Container Storage Flaws Expose Admin Controls — Immediate Upgrades Required
Dell’s Container Storage Modules (CSM) were found to contain multiple critical vulnerabilities that can allow unauthenticated remote attackers to gain full administrative control of affected storage environments. The most severe issues — two CVSS 10.0 flaws — permit attackers to bypass authentication and escalate to administrator privileges, while other high-severity flaws enable privilege escalation inside Kubernetes clusters or token forgery.





