Cybersecurity News
Latest updates from top security sources
1595 articles, page 16 of 54
CISA has ordered all U.S. federal civilian agencies to remediate a severe code injection flaw, CVE-2025-62593, in Ray-Project Ray after confirming active exploitation in the wild. ...
Senior Democratic members of Congress, led by House Homeland Security Committee ranking member Bennie Thompson (D-MS), have formally requested the Government Accountability Office ...
Artificial intelligence is reshaping cybersecurity operations as Security Operations Centers struggle under millions of daily alerts from endpoints, cloud workloads, identity provi...
Check Point Research has disclosed a technique that weaponizes Microsoft Defender's own legitimately signed boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level...
The Open Worldwide Application Security Project (OWASP) has published its latest Top 10 security risk list, this time tailored specifically for the rapidly evolving AI landscape. T...
Retired U.S. Army General Paul M. Nakasone, who served as the 18th Director of the National Security Agency and commander of U.S. Cyber Command from 2018 until his retirement in Fe...
U.S. Bancorp, the seventh-largest bank in the United States, confirmed this week that recent ransomware claims by the LockBit gang are tied to a fourth-party cyber incident rather ...
Kaspersky researchers have uncovered a first-of-its-kind malware family targeting Android-based automotive head units built on DoFun firmware, exploiting the devices' built-in soft...
Cisco has released a new round of security updates addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, five of which carry a maximum CVSS s...
Local government agencies across the United States face a mounting cybersecurity crisis, and a growing movement is calling on skilled professionals to step in. From ransomware atta...
Cybersecurity firm Wiz has attributed a sophisticated open-source software (OSS) supply chain attack against the Rust ecosystem to the North Korean threat actor tracked as Sapphire...
Cybersecurity researchers at Patchstack have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to upload PHP files and ...
A new Android malware strain dubbed Manic has been uncovered by ThreatFabric, blending banking fraud capabilities with mobile spyware features to target Ukrainian banks, government...
Security researchers at Socket's Threat Research team have uncovered a sprawling campaign of 40 malicious Mozilla Firefox extensions designed to steal cryptocurrency wallet credent...
In early 2026, an internal AI agent at Meta triggered a Sev 1 incident after sensitive company and user data was exposed to employees lacking authorization. The breakdown started w...
The Grandoreiro banking Trojan, one of Latin America's most prolific financial malware families, has resurfaced in a fresh campaign targeting Mexican financial institutions. Accord...
Cybersecurity researchers have disclosed two denial-of-service (DoS) techniques collectively dubbed “CDN Tsunami” that weaponize the protocol translation layer inside major content...
Law enforcement agencies worldwide are struggling to keep pace with the relentless growth of cybercrime, hampered primarily by two systemic failures: chronic underfunding and insti...
Researchers at the University of Massachusetts Amherst have demonstrated a "Zombie Card" attack that revives expired Visa contactless credit cards for real in-store purchases by re...
Transparent Tribe, a Pakistan-aligned advanced persistent threat (APT) group also tracked as APT36 and SideCopy, has resurfaced with an updated arsenal of espionage malware targeti...
Citrix has rolled out security updates for two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw that could give attack...
Dark Reading editors recently revisited several cybersecurity stories that slipped through the cracks, including a Delta Air Lines flight disrupted by a Wi-Fi network attack. The i...
A critical command injection vulnerability in Zimbra Collaboration Suite (ZCS) is now being actively exploited in the wild, according to CERT Polska. Tracked as CVE-2026-73570 with...
Veteran incident responder and SANS instructor Jake Williams has publicly released CUSTODY, an open-source framework designed to constrain agentic AI systems within enterprise netw...
This week's threat landscape illustrates how attackers exploit the very tools designed to protect systems. Check Point researchers have demonstrated a troubling technique: weapo...
A threat actor has compromised more than 14,000 Dahua IP cameras across Ukraine and Russia in a 35-day campaign dubbed Operation CameraSwarm, according to threat intelligence resea...
Bitdefender has linked a nearly year-long espionage campaign targeting government institutions in Central Asia to China-based threat actors. Known as SilkParasite, the operation us...
Cybersecurity researchers at Endor Labs have disclosed a critical security flaw in isolated-vm, a popular open-source Node.js library used to run untrusted JavaScript inside V8 Iso...
The Rust Project has confirmed a supply chain attack targeting three widely used crates on crates.io, with combined download counts exceeding 245 million. On August 20, 2026, a com...
Surveillance is no longer limited to intelligence agencies and law enforcement — it's now embedded in the commercial products and services millions of people use every day. Organiz...