Cybersecurity News
Latest updates from top security sources
1595 articles, page 18 of 54
Hardware wallet manufacturer SafePal has disclosed a data breach affecting nearly 40,000 customers, triggered by an authorization flaw in a third-party order-tracking plug-in used ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Ray, tracked as CVE-2025-62593 with a CVSS score of 9.4...
Security researchers have uncovered a sophisticated Python-based malware framework dubbed “TwinLoot” that operates almost entirely from within Microsoft’s cloud infrastructure, rep...
A ransomware affiliate operating under the name Ransom Busters has been identified proactively emailing victim organizations and offering to delete stolen data from ransomware grou...
Cybersecurity researchers at OpenSourceMalware have uncovered a typosquatting campaign targeting the RubyGems ecosystem with a Windows-based information stealer dubbed StubMaker. F...
As organizations rapidly deploy autonomous AI agents to automate workflows, a new class of security incident is emerging — what Cloud Security Alliance Chief Analyst Rich Mogull ca...
Dark Reading’s Declassified docuseries offers a rare, behind-the-scenes look at the pressure faced by chief information security officers. Rather than reducing major cyber...
Security researchers have uncovered a novel "meta-hacking" technique dubbed CoSnitch that manipulates Microsoft's Copilot AI assistant into disclosing sensitive details about its u...
The University of Texas at San Antonio (UTSA), one of the largest universities in Texas serving 40,000 students across six campuses, was forced to take critical systems offline on ...
Varonis Threat Labs has disclosed three previously undisclosed vulnerabilities in Microsoft Copilot Personal that, when chained together, could allow a single click on a malicious ...
A critical zero-click vulnerability, tracked as CVE-2026-19478, has been disclosed in self-managed GitLab instances, sending security teams into a scramble as the absence of publis...
Argentine-born Nico Waisman never formally chose cybersecurity as a career—it chose him. Growing up in Buenos Aires in the 1980s, amid the lingering cultural residue of military di...
Federal cybersecurity agencies CISA and the FBI have updated their advisory on the Medusa ransomware gang, revealing that the group has compromised more than 500 victims as of Apri...
Two critical vulnerabilities in MLflow and FUXA are under active exploitation, with attackers leveraging the flaws to steal cloud credentials and pursue remote code execution on ex...
Security researchers at Anthropic and Switzerland's EPFL have published evidence that self-propagating payloads—dubbed "mind viruses"—can spread between autonomous AI agents by con...
A ransomware affiliate has been observed impersonating a legitimate incident-recovery firm in order to intercept and divert ransom payments from victims, according to researchers t...
Artificial intelligence is fundamentally reshaping the cybersecurity landscape, compressing patch-to-exploit timelines and forcing defenders to confront adversaries operating at ma...
Two Berlin state ministries have been isolated from the city government's IT network following a security breach detected last Friday. The Berlin Senate Chancellery confirmed on Mo...
Cybersecurity researchers at Ontinue have uncovered a previously undocumented Python implant framework dubbed TWINLOOT that weaponizes trusted Microsoft services to run its entire ...
A critical vulnerability in the Forminator Forms plugin for WordPress is leaving more than 300,000 websites exposed to remote code execution (RCE) attacks. Tracked as CVE-2026-1574...
A single attack infrastructure has been systematically extracting records from Salesforce and ServiceNow customer portals across multiple industries for more than a year, according...
Researchers have identified a Linux-focused botnet tracked as Evooo1Bot that draws on leaked Mirai source code yet dramatically broadens its operational scope. Unlike traditional M...
A recent security breach at Hugging Face, one of the most widely used machine learning model repositories, has sent shockwaves through the AI security community. Adam Shostack, pre...
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices powered by Unisoc modem firmware, trigger...
Anthropic has disclosed a striking safety incident involving three Claude-based AI agents that escalated into what researchers describe as a digital "turf war," ultimately producin...
A 52-year-old Ukrainian software developer is on trial at Zurich District Court over allegations that he helped an international ransomware group target companies with LockerGoga, ...
A critical security vulnerability has been disclosed in the Forminator Forms WordPress plugin, exposing more than 600,000 active installations to remote code execution attacks. Tra...
Threat actors are weaponizing a recently patched macOS authentication bypass, tracked as CVE-2026-65400, to gain root access on vulnerable systems and deploy Monero cryptominers. A...
Irregular, the AI evaluation company at the center of multiple incidents where frontier AI models broke out of contained testing environments and compromised real-world computer sy...
Cybersecurity researchers at Kaspersky have documented the continued evolution of the Cavern (aka Cav3rn) command-and-control framework, which is being actively deployed by Iranian...