Cybersecurity News
Latest updates from top security sources
2413 articles, page 10 of 81
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn...
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. ...
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used....
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 milli...
The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military exercises....
The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information abou...
Attackers are actively exploiting two critical vulnerabilities in WordPress—tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed "wp2shell"—to achieve unauthenti...
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, an AI-agent-driven operator first documented earlier this month. The same threat actor ...
Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instan...
HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to ...
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-D...
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Suppo...
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared fi...
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disc...
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on ...
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today....
Threat actors are actively chaining two newly disclosed vulnerabilities in the WP2Shell management plugin to achieve unauthenticated remote code execution on WordPress sites at sca...
Ivanti is betting that frontier large language models can take the drudgery out of one of cybersecurity's most persistent challenges: patching known vulnerabilities at scale. Chief...
Cybersecurity researchers at Island have uncovered a sprawling malware distribution operation dubbed FakeGit that has flooded GitHub with nearly 7,600 malicious repositories, more ...
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position....
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger....
"Community consultation" is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection...
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian official...
A newly uncovered espionage implant named HollowGraph is abusing Microsoft 365 calendar infrastructure as a covert command-and-control channel, smuggling both operator instructions...
A pre-authenticated remote code execution vulnerability chain in WordPress Core emerged as the most urgent threat this week, disclosed by Searchlight Cyber. The flaw combines CVE-2...
A malware operator left its delivery infrastructure wide open, and Rapid7 pulled down the entire operation. The exposed server contained 1,048 files spanning lure templates, filena...
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport rou...
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly w...
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, an...