CyberSecure Specialist

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are tracked together under single CVEs. Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The critical security defects are rooted…

Read More

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations,…

Read More

I’ve been deepfaked: What do I do?

Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal Phil Muncaster 02 Sep 2026  •  , 5 min. read Tackling deepfakes has become something of a common cause across the political spectrum, in America and elsewhere. That’s down in part to the fact these fabricated videos and images are becoming both more commonplace and realistic. Thanks to generative AI (GenAI) tools, it’s…

Read More

OpenLeash Adds a Human Check to Risky AI Agent Actions

AI Agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled. Max Brin is developing a product he describes as an ‘AV for AI’. The analogy with antivirus can be a little confusing since this product is nothing like a traditional antivirus – but the designation is at least well-known, and the purpose of protecting networks from software mishaps is well understood by security practitioners. The name of…

Read More

This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month’s cybersecurity news 31 Aug 2026 With August coming to a close, it’s time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month. Here’s some of what caught Tony’s attention: OpenAI has disclosed more details about how its agents…

Read More

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau…

Read More

Palo Alto Networks Acquires AI Agent Platform Console

Palo Alto Networks (NASDAQ: PANW) on Tuesday announced that it has acquired Console, an AI-native platform designed to help organizations build agentic workflows and automate operational tasks using natural language. The cybersecurity giant said Console will deepen the agentic capabilities of its Cortex platform, allowing security teams to investigate signals, prioritize work, and automatically take action across enterprise environments. Console’s technology enables users to describe an operational objective in natural language, with AI agents then…

Read More

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws.  The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being…

Read More

AI-driven OSINT in the wrong hands – and why everyone could be a target for fraud

It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control. Phil Muncaster 27 Aug 2026  •  , 5 min. read AI is changing the threat landscape, one model at a time. The pace at which the technology is evolving means activities that once took a skilled cybercriminal several hours or even days to achieve can now be done in a fraction of that time by someone with little…

Read More

Hasbro Data Breach Exposed Employee Personal Information

Toy and game giant Hasbro is notifying employees that their personal information may have been compromised in a data breach. The notifications sent to affected individuals contain little detail, but they indicate that the exposed information, which varies by individual, may include names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information.  The information comes from notification letters that Hasbro submitted to the Massachusetts Attorney General’s Office.  It’s unclear how many individuals…

Read More