Cybersecurity News
Latest updates from top security sources
1073 articles, page 3 of 36
Cisco has confirmed that a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being acti...
Security researcher Chaotic Eclipse has published a proof-of-concept exploit for a new Microsoft zero-day dubbed ShieldBreak, which the researcher claims fully bypasses the patch f...
SAP has rolled out emergency patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary c...
Two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, were published to the Python Package Index (PyPI) on March 24 and remained available for roughly 40 minutes between 10:3...
Walmart, the world's largest retailer by revenue, has overhauled its security operations center (SOC) by leaning into a culture-first model that prioritizes psychological safety, t...
Walmart has adopted a 'trusted agent' model for purple teaming, physically colocating its offensive red team and defensive blue team to break down silos and accelerate the detectio...
Threat actors are actively weaponizing a critical directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310, CVSS 9.8) to establish persistent remote access on c...
Enterprise defenses are having one of their strongest years on record at the network perimeter, but collapse almost entirely once an attacker is inside. According to Picus Labs' ne...
CISA has directed U.S. federal agencies to patch CVE-2026-68820, a Windows Winsock vulnerability actively exploited by North Korea's Lazarus Group, by August 25. The flaw, which ca...
Researchers have disclosed a critical design flaw in the reasoning APIs of OpenAI, Anthropic, and Google that allowed weaker AI models to decode the internal reasoning traces of st...
WhatsApp has begun a limited beta rollout of Scam Alert, an optional feature that uses an on-device machine learning model to flag suspicious messages sent by unknown contacts. The...
Microsoft on Tuesday shipped fixes for 419 security vulnerabilities in one of its largest Patch Tuesday releases on record, underscoring how artificial intelligence is fundamentall...
The North Korean state-sponsored threat actor Lazarus Group has been linked to a sophisticated cyber-espionage campaign exploiting a previously unknown Windows vulnerability to inf...
A long-running cyber-espionage operation dubbed "City-Forum" has been systematically exfiltrating sensitive data from enterprise Salesforce and ServiceNow instances since at least ...
London and Boston-based AI security startup Mindgard has closed a $30 million Series A funding round led by Album VC, bringing its total raised to approximately $42 million. Existi...
Britain's ACRO Criminal Records Office has been formally reprimanded by the Information Commissioner's Office (ICO) after suffering three separate cyber intrusions between July 202...
Security researchers at Socket have uncovered a sprawling campaign involving 737 malicious Chrome VPN and proxy extensions that impersonate 66 well-known privacy brands to intercep...
Colombia’s Ministry of Justice and Law was hit by a ransomware attack only days before the country’s presidential transition, according to Dark Reading. The incident disrupted the ...
Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass securit...
The FBI has issued a new public alert warning that threat actors are increasingly using social engineering and cyber intrusion techniques to compromise social media accounts belong...
Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute...
Global shipping and logistics provider Ceva Logistics, a subsidiary of France-based CMA CGM Group, suffered a cyberattack on July 29 that disrupted operations across eight European...
Cisco released emergency patches on Tuesday for a zero-day vulnerability, tracked as CVE-2026-20349, affecting firewalls running Secure Firewall Adaptive Security Appliance (ASA) a...
Security researchers Alejandro Hernando and Borja Martinez have demonstrated how Windows 11's Plug and Play (PnP) auto-installation can be weaponized into a SYSTEM-level compromise...
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power (CHP) plant serving roughly 50,000 residents by pivoting through a pr...
Cybersecurity researchers at Wordfence have disclosed a sophisticated supply chain attack targeting WordPress plugin vendor BdThemes, prompting the WordPress.org plugins team to...
Security researchers have demonstrated a new technique that allows a malicious Model Context Protocol (MCP) server to exfiltrate SSH keys, environment secrets, proprietary sourc...
A joint cybersecurity advisory from U.S. and South Korean agencies has warned that Gunra ransomware is actively targeting critical infrastructure sectors worldwide, including healt...
Mozilla has revoked the cryptographic signing key used to authenticate Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to one of th...
Security researchers from BCA LTD, NorthScan, and ANY.RUN ran a deliberate insider-threat experiment in 2026, posing as a cryptocurrency startup called Ballena Azul and recruiting ...