Cybersecurity News
Latest updates from top security sources
2409 articles, page 2 of 81
CISA has issued an urgent advisory urging water and wastewater system (WWS) operators to safeguard operational technology (OT) following a wave of cyberattacks targeting programmab...
Bank of America announced on Thursday that it will acquire MDSec Consulting Limited, a UK-based technical information security consultancy headquartered in Macclesfield, England. T...
The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection an...
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is s...
The last two versions of Chrome have included more patches than the previous 23 combined....
Threat actors continue refining their tradecraft this week, blending social engineering with multi-stage loaders to compromise organizations across manufacturing, finance, and reta...
A now-patched vulnerability in Microsoft Azure Cosmos DB could have granted attackers full read and write access to databases across customer tenants, according to cloud securit...
Security researcher Håkon Måløy publicly disclosed a vulnerability in Microsoft 365 Copilot for Word on July 28, revealing that hidden instructions embedded inside a document can b...
Check Point Software Technologies has unveiled what it calls the industry's first AI Network Firewall, a new class of network security designed to inspect, detect, and govern AI-dr...
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they sec...
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is ...
The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models ch...
The company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline ...
The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Milli...
The company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on Sec...
The Series B funding round brings the total raised by Onyx Security to $153 million. The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared fir...
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI...
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidenc...
A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found....
Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including n...
A joint advisory from South Korea's Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute war...
The Chinese-linked threat actor Silver Fox has been linked to a new campaign targeting a Japanese industrial manufacturer using a three-driver bring-your-own-vulnerable-driver (BYO...
The Russia-linked threat cluster tracked as Laundry Bear (also known as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) has been weaponizing a now-patched cross-site scripting ...
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new model...
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer ph...
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Discloses Data Breach appeared...
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rog...
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers...
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology. The post US and Allies Update SBOM Guidance appeared first on Se...
The major browser update resolves roughly 80 critical- and high-severity security defects. The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek....