Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

eSecurity Planet
esecurityplanet.com > threats > news-asos-account-takeover-138828-customers

ASOS Account Takeover Attack Exposes Data of 138,828 Customers

12+ hour, 6+ min ago   (499+ words) ASOS says attackers used credentials stolen elsewhere to access customer accounts, exposing personal data belonging to an estimated 138,828 people. ASOS says attackers used login credentials obtained outside the company to access customer accounts, exposing personal information belonging to an estimated…...

eSecurity Planet
esecurityplanet.com > threats > the-toolchain-is-the-target-securing-software-development-in-the-agentic-era

The Toolchain Is the Target: Securing Software Development in the Agentic Era

16+ hour, 26+ min ago   (955+ words) JFrog finds AI development tools are expanding the software supply chain and creating new attack paths for organizations. For most of my career, software supply chain security meant scrutinizing what developers pull in: dependencies, base images, third-party packages. That framing…...

eSecurity Planet
esecurityplanet.com > newsletter > cybersecurity-insider > 2026-08-25

ReliaQuest Targeted

1+ day, 3+ hour ago   (613+ words) Trust is becoming the attack surface. Today’s threats are exploiting everything from forgotten cloud credentials and convincing phishing lures to trusted software and nearby devices. Read past newsletters here. Thousands of Leaked AWS Keys Still Work Thousands of publicly exposed…...

eSecurity Planet
esecurityplanet.com > threats > news-toxicpanda-2-android-malware-349-financial-apps

ToxicPanda 2.0 Blocks Google Play

1+ day, 13+ hour ago   (656+ words) ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control. ToxicPanda 2.0 is giving attackers deeper remote control over infected Android phones, including a new way to keep Google Play out of the…...

eSecurity Planet
esecurityplanet.com > cybersecurity-threats > news-android-car-malware-software-update-botnet

Android Car Systems Infected With Malware Through Software Updates

1+ day, 11+ hour ago   (705+ words) Kaspersky uncovered malware spreading via software updates on Android-based car head units, turning infected systems into proxy nodes in a botnet. Your car’s software update is supposed to fix problems, not quietly recruit its infotainment system into a botnet. Kaspersky…...

eSecurity Planet
esecurityplanet.com > threats > microsoft-patches-entra-id-rce-vulnerability-exploited-in-attacks

Microsoft Patches Entra ID RCE Vulnerability Exploited in Attacks

5+ day, 15+ hour ago   (472+ words) Microsoft patched an Entra ID RCE vulnerability exploited in attacks that required no authentication or user interaction. A maximum-severity vulnerability in Microsoft Entra ID allowed unauthenticated attackers to remotely execute code and was exploited in attacks before Microsoft mitigated the…...

eSecurity Planet
esecurityplanet.com > weekly-roundup > critical-patches-ai-driven-attacks-and-data-theft-define-the-week-in-august-2026

Critical Patches, AI-Driven Attacks, and Data Theft Define the Week in August 2026

5+ day, 15+ hour ago   (151+ words) Federal courts will report spyware authorizations: Beginning with 2028 data published in 2029, the annual U.S. Wiretap Report will include a category for spyware and hacking. The change will create a public tracking baseline, but it will not identify individual operations, include pre…...

eSecurity Planet
esecurityplanet.com > newsletter > cybersecurity-insider > 2026-08-21

943 Oracle Fixes

5+ day, 9+ hour ago   (517+ words) Some threats call for patches. Others call for cutting the cable. Today’s news spans over 900 Oracle patches, exposed gateways, evolving infostealers, AI hitting the brakes, and a telecom defense that took “disconnect the threat” quite literally. Read past newsletters here....

eSecurity Planet
esecurityplanet.com > threats > news-alation-cyberattack-customer-data-exposure

Alation Confirms Cyberattack: What Security Teams Need to Know

5+ day, 17+ hour ago   (604+ words) Alation confirms unauthorized activity in one of its systems, leaving key questions about customer exposure, stolen data, and the attack’s scope. Alation has confirmed unauthorized activity inside its systems, turning an earlier service disruption into a much bigger security question....

eSecurity Planet
esecurityplanet.com > cloud-security > news-cloudflare-workers-remote-spectre-jwt-leak

Remote Spectre Attack Leaks Cloudflare Worker JWT

6+ day, 9+ hour ago   (636+ words) Researchers used a remote Spectre attack to leak a JWT between co-located Cloudflare Workers. Cloudflare says the technique is now mitigated. A remote Spectre attack successfully pulled a JWT from a co-located Cloudflare Worker, showing how CPU side channels can…...