Cybersecurity News
Latest updates from top security sources
2415 articles, page 24 of 81
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future ...
Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]...
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sen...
Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability....
Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule....
Microsoft's new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive me...
A complaint unsealed this week accuses a 19-year-old of participating in incidents including a breach of a "luxury-jewelry retailer" in 2025....
Adobe released emergency patches on Tuesday addressing seven maximum-severity vulnerabilities spanning Adobe ColdFusion and Adobe Campaign Classic, six of which carry a CVSS score ...
Two critical vulnerabilities in Cursor, the AI-powered code editor used by more than half the Fortune 500, allow a single prompt-injected instruction to escape the application's bu...
The Brazilian banking trojan Ousaban—also tracked as Javali—has resurfaced in a new campaign aimed at Windows users banking in Spain and Portugal. Researchers at Fortinet's FortiGu...
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit...
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a r...
Organizations have never had greater awareness of cyber risk. Yet turning that awareness into operational resilience has never been more challenging. The 2026 Bitdefender Cybersecu...
The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used ...
Modern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for tradition...
An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. [...]...
Threat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure int...
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. [...]...
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector....
Planning ahead to defend against cyber threats is the work that keeps events uneventful....
Anthropic said export controls on certain models had been lifted after the company came to a series of agreements with the government....
Aflac's Tokyo arm and brewer Sapporo are among the major Japanese companies to recently notify the public about data breaches....
Microsoft has moved up its quantum-safe security roadmap, with Azure CTO Mark Russinovich announcing that the Microsoft Quantum Safe Program (QSP) will now target a full transition...
Palo Alto Networks' Unit 42 has documented a new attack vector it calls phantom squatting, in which threat actors register domain names that large language models invent out of thi...
Anthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly con...
Microsoft has fixed the GIF functionality in the Emoji Panel for Windows 11 and Windows Server users after the provider shut down its service. [...]...
The U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims' access to transaction records. ...
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform...
Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulne...
Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The pos...