Cybersecurity News
Latest updates from top security sources
2409 articles, page 1 of 81
A Chinese-speaking threat actor has been linked to a sustained cyber espionage campaign targeting government organizations across Central Asia, including entities in Afghanistan, K...
The Cybersecurity and Infrastructure Security Agency (CISA) has released a substantial update to its Software Bill of Materials (SBOM) guidance, introducing approximately two dozen...
Anthropic's Claude large language model has been documented producing functional malicious code and deploying it against at least three real-world organizations, according to a rep...
Cybersecurity researchers at Blackpoint Cyber have disclosed a targeted spear-phishing campaign against an unspecified law firm that weaponized a previously undocumented Go-based l...
Bitsight researchers have uncovered a supply-chain operation called "Fuyao" that ships pre-installed on low-cost Android TV boxes, transforming consumer hardware into a dual-purpos...
Google has fixed an extraordinary 1,442 security vulnerabilities across Chrome versions 149, 150, and 151—more than the combined total of the prior 23 milestones. Chrome 149 and 15...
Researchers from Singapore's Nanyang Technological University have uncovered 84 security flaws across 4G and 5G core network implementations, including a critical vulnerability tha...
The most valuable move any security team can make is building a certificate and key inventory....
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out....
The Delete Request and Opt-out Platform (DROP) launches Aug. 1 and hundreds of thousands of California residents already registered. Other states could follow if the process goes s...
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athl...
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Oth...
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Offic...
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Allowed to Azure Cosmos DB Pwnage ...
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) f...
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC)....
Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet....
Finland stopped power transmissions with Russia at the start of the war in Ukraine, and two related telecom connections will stop at the end of this year, authorities said....
Device code phishing, the abuse of the OAuth 2.0 device authorization grant to hijack access tokens, has escalated from a niche red-team technique into an industrial-scale threat i...
Palo Alto Networks' Unit 42 has revealed that a Chinese-speaking threat actor tracked under the aliases knaithe and KnYuan used the DeepSeek reasoning model through the open-source...
Anthropic has disclosed that three of its AI models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, unauthorizedly accessed the production infrastructure of th...
Google has confirmed that an aggressive surge in Chrome security patches this year is the direct result of a Gemini-powered vulnerability detection pipeline deployed across the bro...
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The pos...
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models H...
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appe...
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on ...
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in Tea...
North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware ...
A suspected Iran-linked advanced persistent threat (APT) group has launched cyberattacks against more than 30 community water utilities across Minnesota, exposing deep vulnerabilit...
Modern AI deployments rarely rely on a single model or framework. Instead, they depend on sprawling "AI harness" architectures that combine orchestration engines like LangChain and...