Thu, Oct 1, 2026 · 3:32 PM ET

Security news

BleepingComputer Sponsored by Specops Software · Updated ago

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued.

Summary from BleepingComputer

More stories

Researchers find Chinese hacking campaigns targeting AI firms, Asian governments 1 source

Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.

The Record ·
Florida cops say they don't know who owns 11 unpermitted Flock cameras 1 source

Floridians alarmed by 14 mysterious Flock cameras; 11 have no clear owner.

Ars Technica ·
AI policy circles targeted in China-linked phishing operation 1 source

Cybersecurity firm Proofpoint said TA419 impersonated officials and AI industry figures in an effort to gain access to cloud accounts held by U.S.

CyberScoop ·
The Secrets of the US Spyware King 1 source

In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company’s promise to keep bad actors from abusing its powerful espionage tool.

Wired ·
Kiteworks patches max severity code injection vulnerability 1 source

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.

BleepingComputer ·
Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains 1 source

Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures.

SecurityWeek ·
Tech in cars can be used to snoop on you, Dutch spy chiefs warn 1 source

Hostile states could access cameras, microphones or GPS, says intelligence agency amid concerns over Chinese imports Drivers have been warned that the smart features built into modern cars such as microphones, cameras and GPS trackers could be used by hostile states to spy on them.

The Guardian ·
Cyberattack on major Polish invoicing platform exposes customer data 1 source

One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.

The Record ·
Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass 1 source

Rob Juncker is chief product and technology officer at Mimecast.

SecurityWeek ·
Hackers stole Pentagon personnel records of over 3 million people 1 source

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025.

BleepingComputer ·
AI Has Changed Attack Speed, Not Security Fundamentals 1 source

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.

SecurityWeek ·
Warlock Ransomware Hits Large Spanish, Portuguese Orgs 1 source

A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.

Dark Reading ·
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure 1 source

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

SecurityWeek ·
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation 1 source

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch.

SecurityWeek ·