Cybersecurity News
Latest updates from top security sources
1589 articles, page 1 of 53
A joint advisory from the FBI, the U.K.'s National Cyber Security Centre (NCSC), and the Netherlands' AIVD has exposed a Windows malware strain dubbed HEAVYGRAM (also tracked as CH...
Security researchers at Lumen Black Lotus Labs have uncovered a sophisticated multi-platform malware campaign dubbed BambooToken, which leverages the lightweight Message Queueing T...
A new report from Sysdig's Threat Research Team reveals that skilled human attackers can match machine-speed exploitation without any AI assistance. In one documented attack chain,...
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation...
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at in...
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access....
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeare...
The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Secur...
A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data...
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via...
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linkin...
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a t...
Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center....
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web....
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and ...
Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites a...
A critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privilege hosting account to escalate to root access on a shared-hosting server, cPanel warned in an a...
Cisco has disclosed that a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway is being actively exploited in the wild, enabling unauthenticated remote attack...
A China-linked threat actor tracked as UTA0560 has been observed weaponizing a recently patched zero-day exploit chain dubbed "BlueMoon" to compromise multiple non-governmental org...
Japan's Digital Agency has disclosed a major data breach affecting approximately 240,000 individuals, with hackers exploiting a known VPN vulnerability to infiltrate its Government...
The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnera...
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, ...
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack a...
Cisco has issued an urgent warning about a critical zero-day vulnerability, tracked as CVE-2026-76461, affecting its Secure Email Gateway (SEG) appliances. The flaw carries a CVSS ...
Threat intelligence firm Hunt.io has uncovered a sophisticated intrusion inside the network of 3BB, one of Thailand's largest broadband providers, where an attacker maintained pers...
Security researchers Denis Rostilov and Aleksander Rostilov of ExPatch disclosed a high-severity vulnerability in Telegram Desktop that allowed attackers to embed hidden JavaScript...
Russian state-sponsored threat group Sandworm has been observed chaining vulnerabilities in Cisco devices to deploy Cyclops Blink, an upgraded iteration of the botnet malware that ...
A maximum-severity vulnerability in GitLab is putting software supply chains worldwide at imminent risk. Tracked as CVE-2026-85706, the flaw is a path traversal vulnerability carry...
Five alleged members of the Nigerian-organized Black Axe cybercrime group have been extradited from South Africa to face federal charges in the United States. Perry Osagiede, Frank...
Researchers from KU Leuven, ETH Zurich, Durham University, and Google have disclosed DDRop, a new active hardware attack that defeats the memory integrity guarantees of Intel TDX, ...