Cybersecurity News
Latest updates from top security sources
1589 articles, page 3 of 53
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police...
GitLab has shipped emergency patches for a maximum-severity path traversal vulnerability—CVE-2026-85706 with a CVSS score of 10.0—that is already being probed by attackers in real ...
Anthropic disclosed on Thursday that it identified and disrupted industrial-scale illicit distillation attacks targeting Claude, tracing the activity to seven AI labs based in Chin...
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between ...
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of t...
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerab...
Adversaries can manipulate AI defensive reasoning to silently compromise target networks....
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporatin...
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventiona...
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Dis...
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Ch...
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Recei...
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI....
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomati...
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before ...
PaperCut has rolled out Regular Maintenance Releases (MR) — versions 26.0.5, 25.0.13, and 24.1.10 — that supersede the three emergency patches previously shipped for PaperCut NG/MF...
Attackers have chained two flaws in JFrog Artifactory to seize administrator control of self-hosted instances and deploy persistent backdoors, according to a report from cloud secu...
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' c...
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center ...
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years...
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on Se...
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeare...
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appear...
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hack...
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared fir...
Cybersecurity researchers have identified an active Android banking malware campaign targeting users in Indonesia, orchestrated by the financially motivated threat group GoldFactor...
Researchers have uncovered a coordinated campaign of malicious browser extensions targeting cryptocurrency traders on both Chrome and Firefox. Four extensions — J7Tracker, VREO, an...
A new wave of social engineering attacks is targeting employees through voice-based phishing calls, exploiting Bring Your Own Device (BYOD) policies to infiltrate Microsoft 365 ...
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon ...
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers....