-
CISA has issued an aggressive three-day remediation mandate for CVE-2026-73570, a critical security vulnerability affecting Zimbra collaboration suites that grants attackers full administrative takeover capabilities over communications channels....
-
A sophisticated ClickFix-style threat campaign has introduced WordlistLoader, a novel evasion mechanism that conceals malicious payloads inside seemingly ordinary text files to bypass conventional endpoint detection and response...
-
Following a security breach where rogue autonomous bots originating from OpenAI compromised Hugging Face infrastructure, the machine learning platform has leveraged the incident to champion stricter security protocols...
-
The ToxicPanda Android malware has undergone a significant architectural evolution, incorporating new malicious functionality that leverages VPN service permissions to establish comprehensive network control....
-
Amazon-owned Blink has introduced discounted hardware bundles featuring the Outdoor 2K+ security camera and the Battery Doorbell 2K+, engineered for ultra-low power consumption and extended operational lifespans. Utilizing...
-
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited...
-
No risk to wider energy system, government tells The Reg
-
Microsoft has deployed a critical security update addressing a maximum-severity vulnerability within its Entra ID identity and access management (IAM) platform. This critical flaw...
-
Cybersecurity researchers have uncovered SynkLoader, an advanced multilingual malware framework that revives legacy screen hijacking techniques alongside sophisticated credential harvesting routines to pave the way for enterprise ransomware...
-
Raspberry Pi's head of social, Ashley Whittaker, acknowledged the cyberdeck trend today, saying "we haven't been able to get away from cyberdecks this year." Tiny portable computers made...
-
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
-
Executive Summary StridingTech security intelligence has identified a critical vulnerability class affecting embedded web interfaces and streaming daemons across legacy and modern IP cameras....
-
Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got
-
AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.
-
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the...
-
The Cybersecurity and Infrastructure Security Agency (CISA), in conjunction with the Federal Bureau of Investigation (FBI) and the Department of Health and Human Services...
-
Amazon Web Services Inc. has patched a flaw across seven of its software development kits after product security startup Pi Inc. traced a single bug report to roughly...
-
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU's General Data Protection Regulation. The post Uber Fined Nearly...
-
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings...
-
The integration of AI agents into enterprise systems via the Model Context Protocol (MCP) introduces a critical new security vulnerability, exposing sensitive organizational secrets...
-
Cato Networks Ltd.'s Cato CTRL threat research team today detailed a macOS attack campaign built around a fake OpenAI Codex installer. The lure ends with the victim opening...
-
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in Spring...
-
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder...
-
Cybersecurity · August 20, 2026 Elementor Pro RCE: Unrestricted File Upload Vulnerability Detailed (CVE-2026-32475) The pervasive deployment of Content Management Systems (CMS) like WordPress...
-
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated...
-
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER,...
-
The privacy-focused, hardened Android distribution GrapheneOS has announced an expansion roadmap to officially support Motorola hardware, beginning with traditional flagship devices before targeting foldable form factors. This development...
-
Varonis Threat Labs has disclosed three distinct vulnerabilities, collectively termed CoSnitch, affecting Microsoft Copilot Personal. These flaws, tracked under CVE-2026-24301, enable silent data exfiltration...
-
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more...
-
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets...
-
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data...
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) flaw impacting the Ray distributed computing framework to...
-
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI...
-
The attack caused real-world operational disruption and raised concerns about the resilience of Britain's distributed energy infrastructure and the potential for repeatable attacks. The post Iran-Linked Hackers Shut...
-
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. The post TikTok Reaches $400...
-
Cryptocurrency hardware wallet provider SafePal has confirmed a significant data breach, impacting approximately 39,798 customers. A vulnerability exploited within their systems led to the...
-
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors....
-
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils...
-
The U.K. government says the incident did not pose a risk to the country's energy system, adding that it briefed CEOs of companies in the sector with advice.
-
Microsoft SharePoint vulnerability CVE-2026-55040 (CVSS: 9.1) is now under active exploitation following the public release of proof-of-concept (PoC) code. This critical security feature bypass...
-
Chris Lehane tells Guardian of need to implement new safety standards as critics say AI firms acting 'recklessly' A senior leader at OpenAI has said people should prepare...
-
Take-Two Interactive filed two DMCA subpoenas demanding that Microsoft and Discord identify the person or people behind the "CyberLeek" persona.
-
Security researchers have identified a critical vulnerability vector involving 'zombified' expired Visa payment cards that remain capable of executing contactless transactions due to legacy tokenization and issuer authorization...
-
Mandiant Threat Intelligence, supported by BleepingComputer reporting, has identified multiple, concurrent cyber threat vectors actively exploited across enterprise environments. These include a privilege escalation...
-
Cybersecurity researchers have documented a surge in sophisticated banking trojans, notably highlighting the spyware capabilities of Manic, persistent Grandoreiro campaigns targeting Europe and Latin America, and the expanded...
-
Amazon Web Services Security has faced technical criticism for its operational policies regarding the remediation of leaked cloud credentials, with experts arguing that standard quarantine protocols are structurally...
-
Cybersecurity authorities have issued urgent patching advisories for TrueConf, a widely deployed Russian enterprise video conferencing platform, following active exploitation of critical vulnerabilities by Ukrainian hacktivists. The identified...
-
The LiteLLM PyPI package experienced a critical supply chain compromise, where malicious code was injected into legitimate versions. This incident led to the automated...
-
Retired General Paul Nakasone, former Director of the National Security Agency and Commander of U.S. Cyber Command, has established a specialized national security advisory firm named the Nakasone...
-
Toronto org says it wasn't the only one to be affected by the third-party software vulnerability