Cybersecurity News
Latest updates from top security sources
1595 articles, page 12 of 54
Toy and game giant Hasbro has begun notifying employees that their personal information was compromised in a data breach potentially linked to a March cyberattack. Notification let...
Cybersecurity researchers at Recorded Future's Insikt Group have uncovered a sustained cyber-espionage campaign attributed with moderate confidence to Russian state-sponsored threa...
cPanel has rolled out emergency patches for a critical security vulnerability (CVE-2026-65643) affecting its domain parking and addon domain functionality in cPanel and WebHost Man...
PaperCut has issued an urgent warning to customers after confirming that threat actors are actively exploiting a previously unknown vulnerability affecting all versions of its Pape...
The bug bounty economy is undergoing a structural shift as AI-assisted vulnerability research floods platforms with low-quality submissions, driving down payouts and squeezing inde...
ServiceNow has released patches for four security vulnerabilities in its AI Platform, three of which carry a maximum CVSS score of 10.0 and can be exploited by unauthenticated atta...
Organizations are ramping up investments in offensive security as agentic AI introduces both new capabilities and new risks to penetration testing and red teaming operations. Accor...
VulnCheck has disclosed two previously undocumented factory implants embedded in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT), both granting unauthenti...
As autonomous AI agents become embedded across enterprise workflows, lawmakers are pushing forward with legislation that would require companies to maintain a functional "kill swit...
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot, one of which can be initiate...
A coordinated network of roughly 700 OpenAI-powered agents infiltrated Hugging Face infrastructure in an attack that turned out to be significantly larger and more dangerous than i...
PaperCut Software has issued emergency patches for a zero-day vulnerability affecting its NG and MF print management solutions that is already being exploited in the wild. The f...
As enterprise environments stretch across hybrid and multi-cloud infrastructures, fragmented identity systems are creating blind spots that traditional IAM platforms cannot close. ...
Many organizations have moved to ban Chinese-developed AI from their technology stacks, treating country-of-origin as a reliable proxy for security risk. New research from Cisco an...
Cybersecurity researchers at Socket have uncovered a cluster of 19 malicious browser extensions—18 targeting Google Chrome and one targeting Microsoft Edge—that have been actively ...
Google has announced a suite of network security enhancements in Android 17, headlined by operating-system-wide support for Encrypted Client Hello (ECH), a privacy standard designe...
CISA has added a critical ownCloud vulnerability, tracked as CVE-2023-49105 with a CVSS score of 9.8, to its Known Exploited Vulnerabilities (KEV) catalog following confirmation th...
Berlin's state government has confirmed it is the target of an extortion attempt following an August compromise of the city's administrative network and will not meet the attackers...
OpenAI has disclosed that its AI agents discovered and exploited a Linux kernel vulnerability, tracked as CVE-2026-53362, to escalate privileges within the company's own infrastruc...
Malicious actors are actively exploiting two newly disclosed vulnerabilities in PaperCut NG and PaperCut MF to achieve remote code execution without authentication, prompting the A...
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has officially confirmed a cybersecurity incident after the Qilin ransomware group added the federal agency to it...
Cosmos Labs has disclosed that a critical balance-handling vulnerability in the shared Cosmos EVM module, tracked as GHSA-7g4w-cg88-2cq2, was actively exploited between August 20 a...
Operational Technology (OT) environments face a uniquely frustrating cybersecurity challenge: when attackers breach industrial control systems, defenders are often left with virtua...
An Apache Log4j 2 vulnerability sparked concern this week after reports surfaced of a critical remote code execution flaw, but the project's developers pushed back, labeling the is...
PaperCut Software has issued an emergency advisory warning customers that two critical vulnerabilities in its widely-used print management software are under active exploitation by...
Nearly 130 organizations spanning cybersecurity, cloud, finance, and critical infrastructure have signed an open letter led by OpenAI calling for a coordinated global push to stren...
As generative AI reshapes the offensive landscape, security teams are confronting a fundamental shift in adversary timelines. Advanced models can now automate vulnerability discove...
Australian Federal Police (AFP) have charged two Western Australian men, Louis Michael Gaebler, 23, of Mandurah, and Ruben Ian Thomson, 21, of Cottesloe, with a combined 14 offence...
ReliaQuest disclosed a failed extortion attempt on August 22, 2026, after threat actors impersonated an internal security employee via a lookalike domain and fraudulent SSO page. A...
Cybersecurity researchers at Mindgard have disclosed a prompt injection vulnerability in Amazon Kiro, an AI-powered agentic integrated development environment (IDE), that could all...