Cybersecurity News
Latest updates from top security sources
1595 articles, page 11 of 54
Threat actors began exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass vulnerability, just days after its public disclosure. The flaw carries a CVSS scor...
Palo Alto Networks (NASDAQ: PANW) announced on Tuesday that it has acquired Console, an AI-native platform built to help enterprises design agentic workflows and automate operation...
Cybersecurity firm Sygnia has detailed a sophisticated Chinese-linked hacking operation dubbed "Fire Ant" that compromised Cisco IOS XR routers to infiltrate organizations and pivo...
Socket security researcher Kush Pandya has uncovered 13 malicious Composer theme packages on Packagist that target unpatched iPhones, ultimately stealing cryptocurrency wallet seed...
Researchers at Forescout's Vedere Labs successfully used Anthropic's Claude to port a remote code execution (RCE) exploit between two WAGO programmable logic controllers, but the e...
Houston-based healthcare facilities operator Nutex confirmed in an 8-K filing with the Securities and Exchange Commission on Monday that cybercriminals breached its servers in Augu...
The Iranian state-aligned threat group Nimbus Manticore, also tracked as "Iranian Dream Job," has been linked to two previously undocumented cross-platform remote access trojans ca...
Last year, the most common way into a corporate network was simply asking. Microsoft's threat intelligence team reported that ClickFix — a social engineering technique that walks a...
Five Venezuelan nationals pleaded guilty in a US federal court to conspiracy to commit bank larceny through an ATM jackpotting scheme targeting locations in Kansas. The defendants—...
METR (Model Evaluation and Threat Research), a non-profit that evaluates frontier AI models for agentic task performance, disclosed two notable security incidents in which external...
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users....
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks....
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules....
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls....
Pharmaceutical and healthcare technology distributor McKesson disclosed a cybersecurity incident on Friday, filing an 8-K with the Securities and Exchange Commission (SEC) and warn...
Anthropic has added local session transcript endpoints to its Compliance API, giving security teams a clearer audit trail for Claude Code activity. Unlike a conventional chatbot, C...
At least $6 million was drained from decentralized lending platform Tectonic over the weekend after an attacker exploited the protocol's thinly traded Tonic token by artificially i...
Threat actor Silver Fox has been spotted distributing the ValleyRAT backdoor (also tracked as Winos 4.0) disguised as QN Wallpaper, a legitimate but ad-supported Chinese desktop wa...
Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny in a federal Kansas court after prosecutors accused them of being part of a coordinated group tha...
Threat actors linked to the Aurora (Aur0ra) ransomware operation have been leveraging Cursor, an AI-powered coding assistant originally developed by SpaceX, to plan and execute int...
North Korean threat actors have broadened their fraudulent employment scheme beyond the IT sector, with new investigations revealing operatives embedded in healthcare, sales, and f...
The independent researcher known as Nightmare Eclipse (also called Chaotic Eclipse) has publicly released a proof-of-concept exploit dubbed HardBreacher targeting a privilege escal...
Berlin's Governing Mayor Kai Wegner confirmed on Friday that the state government will not comply with an extortion demand from the Rhysida ransomware group, which claimed responsi...
The U.S. Federal Bureau of Investigation has dismantled infrastructure tied to QTYF, a Chinese technical quartermaster that sold reconnaissance, proxy management, and operational r...
A China-nexus cyber espionage group tracked as Fire Ant has expanded beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts used t...
The U.S. Department of Justice issued a correction to a previous press statement, clarifying that several federal agencies were "targets" — not confirmed "victims" — of intrusions ...
Microsoft has shed light on a sophisticated new ClickFix variant dubbed TerminalFix that tricks users into running malicious PowerShell commands through fake Cloudflare CAPTCHA ver...
Security researchers have disclosed five critical vulnerabilities across popular WordPress plugins and themes that collectively expose millions of websites to authentication bypass...
Enterprise adoption of generative AI and large language models has accelerated faster than most governance frameworks can handle, making secure AI strategy a board-level priority. ...
As organizations accelerate AI adoption, the security perimeter around cloud environments is shifting faster than most governance frameworks can keep up. Dark Reading is hosting a ...