Cybersecurity News
Latest updates from top security sources
1595 articles, page 15 of 54
Cybersecurity researchers at Seqrite Labs have identified a China-nexus cyber espionage campaign, codenamed Operation QUICSILVER, targeting Myanmar's government and information tec...
Enterprise security teams are quietly accumulating what researchers call "remediation debt" as AI coding assistants accelerate development cycles and flood software stacks with new...
CISA has added a critical Zimbra Collaboration Suite vulnerability—tracked as CVE-2026-73570—to its Known Exploited Vulnerabilities (KEV) catalog, ordering federal agencies to appl...
Industry surveys consistently show CISO tenure falling short of other C-suite roles, and a persistent double standard is largely to blame. During recruitment, boards prioritize tec...
The U.S. Treasury Department announced sanctions on Monday against several Iranian nationals tied to state-sponsored cyber operations targeting American critical infrastructure, ju...
Cybersecurity researchers at McAfee Labs have uncovered an ongoing campaign in which the Weedhack malware family is being distributed to gamers through fraudulent Minecraft client ...
A wave of AI-driven attacks and supply-chain compromises dominated this week's cybersecurity headlines, underscoring how quickly threat actors are weaponizing automation and truste...
Cybersecurity firm ReliaQuest has confirmed it was targeted by hackers affiliated with the ShinyHunters group in a social engineering campaign, though the company maintains that th...
Kaspersky researchers have uncovered what appears to be the first documented malware campaign designed specifically to compromise Android-based car head units, targeting devices ma...
Cybersecurity researchers at Gen Digital have identified two newly tracked malware families—WordlistLoader and SynkLoader—being deployed to harvest Windows credentials and stage ne...
Researchers at Cisco Talos have exposed a Chinese-speaking cybercrime operation dubbed UAT-10147 that is weaponizing artificial intelligence to automate large-scale intrusions agai...
Broadcom has rolled out a sweeping security update for its Spring application development framework, addressing 91 vulnerabilities in a single release cycle. The patch batch spans ...
A 27-year-old Venezuelan national has been sentenced to 96 months in federal prison for his role in an ATM jackpotting operation that caused more than $3.5 million in losses, the U...
Apollo Global Management has disclosed a data breach that exposed sensitive personal information following a social engineering attack. According to a breach notice sent to affecte...
The U.S. Department of Justice announced on Friday that ByteDance-owned TikTok has agreed to pay $400 million to settle a 2024 lawsuit accusing the social media platform of violati...
Three major banking trojan families—Manic, Grandoreiro, and an updated ToxicPanda variant—are actively targeting financial institutions and end users across multiple continents, ac...
Time-Sensitive Networking (TSN), a family of IEEE 802.1 standards originally designed to deliver deterministic Ethernet for audio, video, and automotive applications, is rapidly ga...
Federal agencies were put on alert this week after the US Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities in TrueConf Server to its Known...
Microsoft on Thursday released 22 security updates addressing severe vulnerabilities across its product portfolio, headlined by an actively exploited zero-day in Entra ID. Tracked ...
Major hardware manufacturers are accelerating the rollout of post-quantum cryptography (PQC) as the cybersecurity community braces for "Q-Day"—the moment when cryptographically rel...
Two new industry surveys reveal a widening gap between perception and reality across the defense industrial base: defense contractors are reporting record confidence in their cyber...
A critical-severity type confusion vulnerability in the isolated-vm Node.js library could allow threat actors to achieve remote code execution (RCE) on the underlying host system, ...
A sophisticated phishing toolkit dubbed iAuthFlow V2 is raising alarm across the cybersecurity community for its ability to maintain persistent access to compromised Gmail accounts...
Russian network monitoring software developer Microolap confirmed that hackers compromised several of its systems this week, but pushed back against claims by a pro-Ukraine hacking...
A critical code injection vulnerability in GitLab, tracked as CVE-2026-19478 with a CVSS score of 9.4, has come under active in-the-wild exploitation just days after public disclos...
Researchers at Adversa AI have identified a novel attack technique dubbed Cryptographic Context Injection that successfully circumvents safety guardrails in major AI platforms, inc...
Canada's largest pediatric health center, the Hospital for Sick Children (SickKids), has disclosed a second major cybersecurity incident in three years, with attackers stealing per...
Microsoft has patched a maximum-severity vulnerability in its Entra ID cloud identity service that could allow remote code execution over a network. Tracked as CVE-2026-69836 with ...
Cybersecurity researchers at TrendAI, the enterprise security arm of Trend Micro, have uncovered 14 trojanized npm packages that masquerade as legitimate calendar, streak-tracking,...
OpenAI has introduced a suite of new security controls for its platform, a move that industry observers say is overdue following last month's disclosure that an internal Hugging Fa...