Cybersecurity News
Latest updates from top security sources
1595 articles, page 17 of 54
Three suspected Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—have been leveraging legitimate authentication flows to compromise individuals working in academia, a...
The NSA, CISA, FBI, Department of Energy, and EPA jointly issued an advisory this week warning of an active, AI-assisted campaign targeting critical infrastructure organizations...
A recently patched vulnerability in N-able's Passportal password manager has raised serious concerns about the security of cloud-based credential vaults used by managed service pro...
Poland's CERT Polska has confirmed active in-the-wild exploitation of a recently patched vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570. The high-severi...
Two U.S. senators are demanding answers from TikTok after media reports revealed the social media giant intentionally disabled critical safety features for a subset of users to mea...
Cybersecurity researchers at Adversa AI have disclosed a new attack technique dubbed "Cryptographic Context Injection" that can trick xAI's Grok chatbot into exfiltrating sensitive...
Security researchers at Cycode have disclosed a chain of severe vulnerabilities in NASA's open-source AIT-GUI, the browser-based operator console used by the Jet Propulsion Laborat...
Cisco on Wednesday disclosed patches for 15 vulnerabilities spanning multiple product lines, including several critical-severity flaws in Crosswork and Secure Workload that could e...
Researchers have identified a significantly enhanced version of the ToxicPanda Android banking trojan, also known as TgToxic, with 167 remote commands and expanded global targeting...
ReliaQuest researchers have uncovered a sophisticated JavaServer Pages (JSP) web shell specifically engineered to compromise PTC Windchill and FlexPLM servers, the enterprise Produ...
As organizations race to deploy autonomous AI agents across their workflows, a new class of insider threat is taking shape, one that operates not from malicious intent but from the...
The U.S. Department of Justice unsealed a 14-count superseding indictment on Tuesday charging 17 individuals linked to Iran's Islamic Revolutionary Guard Corps (IRGC) with running ...
Phishing has evolved through three distinct phases, and defenders are still catching up. Phishing 1.0 was about malicious payloads: bad links, infected attachments, and spam that s...
A new AI platform branded "Kriminal" is drawing sharp scrutiny from security researchers for offering an unfiltered large language model that openly assists with social engineering...
The Cl0p ransomware group has published the names of more than 40 organizations allegedly compromised in a campaign exploiting a critical flaw in PTC's Windchill and FlexPLM produc...
The NSA, FBI, and other federal agencies issued an urgent advisory warning that unidentified threat actors are using AI-generated exploit scripts to target Siemens S7 Series progra...
Microsoft Defender Experts have correlated more than 30 web domains to the MacSync Stealer, a macOS-focused information stealer, by tracing recurring endpoint and network behaviors...
Cybersecurity researchers have disclosed a practical remote Spectre side-channel attack against Cloudflare Workers that exfiltrated a JSON Web Token (JWT) from a co-located Worker ...
The US Department of Justice has charged 17 members of the Iran-based Mabna Institute with conducting a massive cyber-espionage campaign that compromised roughly 8,000 professor em...
Healthcare technology provider CareCloud has disclosed a major data breach impacting 3,756,469 individuals, according to filings with the U.S. Department of Health and Human Servic...
OpenAI confirmed on Tuesday that it paused reinforcement learning (RL) training for its most advanced artificial intelligence models for two weeks, citing the need to strengthen in...
A previously undocumented cyber-espionage operation dubbed SilkParasite has been targeting government bodies across Central Asia with seven remote access tool (RAT) families—five o...
A Chinese-nexus advanced persistent threat (APT) group tracked as SilkParasite has launched a targeted spear-phishing campaign against government, diplomatic, and private-sector or...
CodeSecCon, the premier virtual conference uniting developers and cybersecurity professionals, is set to take place today with over 1,500 registered attendees. The event focuses on...
Latvia's Road Traffic Safety Directorate (CSDD) has confirmed that hackers stole personal and financial data tied to more than 1.2 million individuals and 200,000 businesses—roughl...
Cybersecurity researchers at Hunt.io have uncovered Operation CameraSwarm, a large-scale campaign that compromised more than 14,530 Dahua surveillance devices between June 17 and J...
Cybersecurity researchers at Check Point Research have uncovered a sprawling global cybercrime operation, dubbed StopAndProtect, that weaponizes nearly 2,000 compromised WordPress ...
A Chinese-language threat actor has executed what researchers are calling the first near-autonomous nation-state cyberattack, leveraging a sophisticated artificial intelligence fra...
London-based AI-powered data fabric company Prevalent AI has secured $22 million in growth funding from Integrity Growth Partners (IGP), marking its first major capital injection a...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threa...