Cybersecurity News
Latest updates from top security sources
2413 articles, page 11 of 81
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control an...
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware fo...
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte...
Over the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games....
Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the...
Romania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history."...
Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since...
A Russian-speaking threat actor tracked as "bandcampro" has been observed weaponizing Google's open-source Gemini CLI artificial intelligence tool to operate a live, small-scale bo...
Cybersecurity veteran Richard Bird has launched The Hacker in a Hoodie (HIH) Index, a public website that tracks disclosed material breaches pulled directly from SEC EDGAR 8-K fili...
A newly disclosed vulnerability in the widely used 7-Zip archiver could allow attackers to execute arbitrary code when users open a maliciously crafted XZ archive. Tracked as CVE-2...
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data B...
Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Watch on Deman...
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘Vu...
Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on Securi...
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on Sec...
In a striking case of the defender becoming the target, Hugging Face, the world's largest open-source AI model repository, disclosed on July 20, 2026, that an autonomous AI agent s...
Cybersecurity researchers at StepSecurity have uncovered a new software supply chain campaign dubbed SleeperGem targeting the Ruby ecosystem through three malicious RubyGems packag...
Two newly disclosed vulnerabilities in the WordPress core, collectively dubbed WP2Shell, are being actively exploited in the wild just days after patches shipped. Tracked as CVE-20...
F5 has released patches for a critical vulnerability in the NGINX web server, tracked as CVE-2026-42533, that allows remote unauthenticated attackers to trigger a heap buffer overf...
Russian state-sponsored threat actor UAC-0145, a sub-cluster within the GRU-linked Sandworm advanced hacking unit, has been observed weaponizing the ClickFix social engineering str...
An unattributed threat actor tracked as UTA0533 exploited two previously unknown vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000-series VPN appliances as zero-days beg...
A recently disclosed OpenSSL vulnerability dubbed “HollowByte” allows attackers to permanently fragment server memory using nothing more than an 11-byte TLS handshake message, forc...
Cybersecurity researchers at Checkmarx have uncovered a software supply chain attack targeting the Vite frontend tooling ecosystem, with seven malicious npm packages collectively d...
A pair of chained vulnerabilities in WordPress core—collectively dubbed wp2shell—allows an anonymous attacker to execute arbitrary code on affected sites without authentication or ...
The Inc Ransomware group has been observed weaponizing two previously undisclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances, chaining the flaws to...
Researchers at QiAnXin's XLab have documented a new Go-language botnet called NadMesh that emerged in early July 2026 and is actively scanning the public internet for exposed AI in...
Cybersecurity researchers at Expel have attributed the April 2026 DigiCert security incident to a threat activity cluster tracked as CylindricalCanine, a sub-group of the Chinese c...
Threat actors linked to North Korea's Contagious Interview campaign have weaponized steganography inside SVG image files to deliver a four-stage malware payload aligned with OtterC...
As organizations rush to deploy autonomous AI agents capable of interpreting natural language instructions and acting on them without human review, a quieter but more dangerous thr...
The White House has launched Gold Eagle, a new clearinghouse initiative designed to coordinate vulnerability disclosure and response across government and private sectors as artifi...