Toggle light / dark theme

Accenture confirms breach after hacker offers stolen data for sale

IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company.

“We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery,” Accenture told BleepingComputer.

Accenture is a global professional services company that provides consulting, technology, cloud, engineering, and managed services to businesses and governments worldwide.

Detecting neutron sources by borrowing inference tools from cosmology

Neutron sources can be directly identified from measured spectra rather than proxies using inference tools adapted from cosmology, according to a University of Michigan Engineering study published in Physical Review Applied. The method can improve nuclear security by helping intercept materials at ports or borders or guide first responders during emergency response.

Directly detecting and characterizing a neutron source remains a challenge because most nuclear materials emit neutrons with energy patterns, called neutron spectra, that look similar to one another—whether from a benign industrial isotope or fissile material.

“This problem sits at the intersection of fundamental physics, statistics and real-world nuclear security. There is a very practical need to identify unknown neutron-emitting materials, but there is also a deep scientific challenge: How do you extract reliable information from signals that are weak, noisy and highly similar?” said David Breitenmoser, a postdoctoral research fellow of nuclear engineering and radiological sciences at U-M and lead author of the study.

Opera rolls out Paste Protect feature to fight ClickFix attacks

Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering.

ClickFix is a widely used technique where victims are deceived into copying dangerous code or commands to the clipboard and then executing them in the command-line interface.

Typically, the ruse is a verification process or some form of problem-fixing instructions. However, they are only designed to trick the target into performing dangerous actions.

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

The issues have been addressed in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10. Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure have been credited with discovering and reporting CVE-2026–48283, CVE-2026–48313, and CVE-2026–48307.

Separately, Adobe has also shipped fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9,396 and earlier for Windows and Linux that could result in arbitrary code execution.

The vulnerability, tracked as CVE-2026–48286 (CVSS score: 10.0), is a case of incorrect authorization that could enable an attacker to execute arbitrary code on affected systems. It has been patched in version ACC v7: 7.4.3 build 9397.

Adobe patches seven max severity ColdFusion, Campaign flaws

Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform.

All these vulnerabilities can be exploited in low-complexity attacks that don’t require user interaction and were tagged with priority 1, indicating a high risk of being targeted.

“This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform. Adobe recommends administrators install the update as soon as possible. (for example, within 72 hours),” Adobe says.

Microsoft accelerates quantum-safe roadmap as risks grow

Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today’s encryption standards sooner than previously expected.

Although today’s quantum computers cannot crack modern encryption, security researchers have warned about “harvest now, decrypt later” attacks. In these attacks, encrypted data that is stolen today is stored until future quantum computers become powerful enough to decrypt it, exposing sensitive information.

As a result, companies including Apple, Google, and Signal have begun integrating post-quantum cryptography (PQC) to replace existing public-key encryption algorithms with quantum-resistant versions.

/* */