Cybersecurity News
Latest updates from top security sources
2415 articles, page 22 of 81
North Korean threat actors tied to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist, Go, and the Google C...
Security research firm runZero has disclosed seven previously unpatched vulnerabilities in FatFs, a lightweight FAT/exFAT filesystem library embedded in the fir...
Blackpoint Cyber researchers Nevan Beal and Sam Decker have uncovered Avalon, a previously undocumented modular malware framework that consolidates credential harvesting, lateral m...
A newly disclosed Linux kernel vulnerability dubbed "Bad Epoll" (CVE-2026-46242) enables unprivileged users to escalate privileges and gain root access on affected systems. The fla...
Security researchers at JFrog have uncovered a new North Korea-linked software supply chain campaign targeting JavaScript developers through malicious npm packages disguised as leg...
A coordinated law enforcement and industry operation has dismantled NetNut, one of the world's largest residential proxy networks, cutting off access to an estimated two million co...
A previously undocumented advanced persistent threat group dubbed Armored Likho has been conducting cyber-espionage and financially motivated intrusions against government agencies...
Cisco Talos researchers have uncovered a phishing-as-a-service (PhaaS) platform named “ARToken” that operates as an affiliate of the EvilTokens ecosystem, exposing a sophisticated ...
Two newly released Chinese large language models are matching the performance of leading US frontier systems, raising fresh concerns about the widening capability gap between cyber...
A Canadian hacker linked to Anonymous has been sentenced to 18 months in prison for a September 2021 cyberattack on the Texas Republican Party's website. Aubrey Cottle, 39, of Osha...
A former Member of the European Parliament who served on a committee investigating commercial spyware abuse was herself repeatedly targeted with NSO Group's Pegasus spyware, accord...
A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...
A threat actor tracked as JadePuffer has executed what cloud security firm Sysdig describes as the first fully agentic AI-driven ransomware campaign, exploiting a critical missing ...
In April, ShinyHunters accessed the company’s corporate IT systems and stole patients’ personal and medical information. The post Medtronic Data Breach Impacts 3.8 Million People a...
Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments. Th...
NetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNu...
The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critic...
Anthropic has moved to reassure Claude users that its most powerful model, Fable 5, will not be a permanent pay-to-play exclusion from standard subscription tiers. Following the re...
A phone belonging to former Greek Member of the European Parliament Stelios Kouloglou was infected with Pegasus spyware on at least two occasions during his tenure on the PEGA C...
Anthropic has released Claude Fable to all subscribers following the lifting of a Department of Commerce export ban, but the restored model is drawing sharp criticism from develope...
Google has significantly disrupted NetNut, one of the largest residential proxy networks in operation, in a coordinated takedown with the FBI, Lumen's Black Lotus Labs, and acad...
The FBI and IRS Criminal Investigation have seized hundreds of domains associated with NetNut, a sprawling residential proxy service operated by publicly-traded Israeli company Ala...
Threat actors tied to the Anubis ransomware-as-a-service (RaaS) operation have been actively exploiting Citrix Bleed 2 (CVE-2025-5777), a critical authentication-bypass flaw in Cit...
Improved institutional safeguards and stricter regulations have pushed the burdens of protection and risk reduction on to Australian businesses....
Expect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit....
After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug....
The ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere....
The plan had been due for publication on Monday, the sources said. It has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July...
Kaspersky researchers have uncovered a sophisticated new malware dubbed Umbrij, attributed to the advanced persistent threat group ToddyCat, which leverages the Google API and OAut...
Enterprise identity lifecycle management was architected around a human employee with an HR record, a reporting manager, and a defined departure date. AI agents possess none of the...