Cybersecurity News
Latest updates from top security sources
An analysis of Project Glasswing's findings on the Mythos vulnerability firehose has revealed a stark imbalance between discovery and remediation. Researchers identified a substant...
The bug bounty economy is undergoing a structural shift as AI-assisted vulnerability research floods platforms with low-quality submissions, driving down payouts and squeezing inde...
Cosmos Labs has disclosed that a critical balance-handling vulnerability in the shared Cosmos EVM module, tracked as GHSA-7g4w-cg88-2cq2, was actively exploited between August 20 a...
Cybersecurity researchers at Patchstack have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to upload PHP files and ...
A growing wave of ambiguous and outdated cybercrime legislation worldwide is putting ethical hackers and security researchers at legal risk, even when their work is conducted in go...
Security researcher James Arnott, founder of cybersecurity firm Bay Area Labs, disclosed severe vulnerabilities in the Connective digital identity system, a browser extension devel...
A new analysis of more than 6,000 AI-generated software patches has revealed that roughly half fail to deliver a true fix, raising serious concerns about the reliability of automat...
OpenAI has banned a coordinated set of ChatGPT accounts tied to a Cambodia-based scam operation that weaponized the model to run investment, romance, gambling, and law enforcement ...
Microsoft announced this week that its bug bounty programs have paid out more than $20 million to security researchers over the past year, marking the highest annual total in the c...
Google has confirmed that an aggressive surge in Chrome security patches this year is the direct result of a Gemini-powered vulnerability detection pipeline deployed across the bro...
Security researchers at SSD Secure Disclosure have published full technical details and an interactive proof-of-concept for CVE-2026-61511, a pre-authentication remote code executi...
Two critical command-injection vulnerabilities in Bing Images allowed specially crafted SVG files to execute arbitrary code as NT AUTHORITY\SYSTEM on Microsoft's production image-p...
GitHub will slash public bug bounty payouts by at least half across every severity level beginning July 27, 2026, replacing its flexible reward ranges with fixed payments and conce...
A newly disclosed vulnerability in the widely used 7-Zip archiver could allow attackers to execute arbitrary code when users open a maliciously crafted XZ archive. Tracked as CVE-2...
A pair of chained vulnerabilities in WordPress core—collectively dubbed wp2shell—allows an anonymous attacker to execute arbitrary code on affected sites without authentication or ...
Artificial intelligence is reshaping offensive security by giving practitioners the ability to read codebases, map attack surfaces, generate payloads, explain unfamiliar APIs, and ...
Nebula Security has disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free vulnerability that lets any local user escalate to full root on unpatched system...
A serious vulnerability in Opera GX, the gaming-focused browser from Opera, allowed a malicious website to silently install a browser modification and use it to extract sensitive d...
A newly disclosed Linux kernel vulnerability dubbed "Bad Epoll" (CVE-2026-46242) enables unprivileged users to escalate privileges and gain root access on affected systems. The fla...
A new remote access trojan dubbed ChocoPoC is targeting vulnerability researchers and bug bounty hunters through weaponized proof-of-concept (PoC) repositories on GitHub. Discovere...
Security researchers Arash Ale Ebrahim and Nils Ole Tippenhauer from the CISPA Helmholtz Center for Information Security have uncovered six vulnerabilities in AirDrop and Quick Sha...
Critical and high-severity vulnerabilities in Daktronics controllers could allow remote attackers to tamper with highway signs, electronic scoreboards, and digital billboards world...
Security researchers at application security firm Aikido have disclosed a severe authentication bypass vulnerability in phpBB, the widely used open-source forum platform, that h...
Google on Monday rolled out Chrome 149, a critical security update that patches 74 vulnerabilities, including a high-severity zero-day flaw actively exploited in the wild. The vuln...
Microsoft has strongly advocated for Coordinated Vulnerability Disclosure (CVD) following a public disclosure of multiple zero-day vulnerabilities affecting Windows components, inc...
The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new nomination form enabling security researchers, vendors, and industry partners to submit vulnerabiliti...
Google inadvertently exposed technical details of an unfixed Chromium vulnerability that allows JavaScript to persist in the background after the browser is closed, effectively giv...
The Hacker News (THN) has officially opened the call for entries for the Cybersecurity Stars Awards 2026, an initiative designed to shine a spotlight on the behind‑the‑scenes work ...
When Alex Rivera, "CISO of Globex Systems", commissioned a penetration test in Q3 2023, his first decision was to define a precise scope that included internal VLAN segmentation, c...
Google announced a major overhaul of its Android and Chrome vulnerability reward programs, raising the maximum payout to $1.5 million for the most sophisticated exploit chains targ...