ThreatVectr — cybersecurity news: breaches, vulnerabilities, ransomware and AI security

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators
A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

Microsoft names Storm-2570, the affiliate hopping between Qilin, DragonForce and other ransomware crews
The same intruder, the same toolkit, four different ransom notes. Microsoft says defenders who chase payloads keep missing the person behind them.

Botslab G980H Dashcams Ship With 13 Unpatched Flaws and the Vendor Has Gone Quiet
CISA lists authentication and session bugs in a popular Chinese dashcam line. The company hasn't responded.

Meltdown and Spectre Opened a Door That Won't Fully Close
Seven years on from the chip flaws that rewrote the rules of hardware security, dozens of variants keep arriving. Here's what ordinary users need to understand about vulnerabilities baked into the silicon itself.

Microsoft is switching off text-message logins for work accounts in February 2027
Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

GitLab's Per-User Issue Email Is a Password in Disguise
The private address you use to file issues by email can also push code and start pipelines as you. Treat it like a credential, because it is one.


The podcast
Threat Vectr Weekly, with Marcus & Elena
The week's biggest cybersecurity stories in ten minutes. New episode every Monday.
