Cybersecurity News
Latest updates from top security sources
1589 articles, page 7 of 53
A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services....
A pair of chained vulnerabilities in FreeIPA and the 389 Directory Server can allow an anonymous, never-logged-in client to manufacture a Kerberos identity of its choosing and land...
Adobe has shipped emergency security updates for a maximum-severity vulnerability, tracked as CVE-2026-75650 (CVSS 10.0), affecting Adobe Commerce, Magento Open Source, and Adobe C...
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams...
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their H...
SOCRadar researchers have disclosed details on PEEP, a sophisticated post-exploitation toolkit that transforms Chromium-based browsers into covert backdoors for host-level command ...
Threat hunters at Arctic Wolf have uncovered a widespread data theft and extortion campaign, tracked as PREY-0058, that targets Microsoft 365 and other SaaS platforms by impersonat...
Google has shipped an emergency patch for a high-severity Chrome vulnerability tracked as CVE-2026-85046 (CVSS 8.8), a type confusion bug in the V8 JavaScript and WebAssembly engin...
New research from Intruder's 2026 Cloud Security Index reveals that cloud security risk profiles vary dramatically across providers, undermining the assumption that a single cloud ...
Cybersecurity researchers at Huntress have uncovered worm-like activity abusing ConnectWise ScreenConnect to deliver a four-stage Visual Basic Script (VBScript) payload to newly co...
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specifi...
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Expl...
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New...
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents...
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group....
N-able has shipped its fourth hotfix in five weeks for the on-premises N-central remote monitoring and management (RMM) platform, addressing a maximum-severity vulnerability that e...
Cybersecurity researchers at Check Point Research have published a deep-dive analysis of JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware engineered for credential harv...
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backd...
The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campai...
Attackers are actively exploiting a critical vulnerability in MikroTik routers to seize full administrative control without any authentication, according to an advisory published S...
Elastic Security Labs has published research on four previously undocumented Windows programs linked to REVSTEALER, a commercial information stealer that has circulated on cybercri...
A new unauthenticated remote code execution vulnerability in Magento Open Source and Adobe Commerce is being actively exploited in the wild, Dutch e-commerce security firm Sansec d...
JetBrains has confirmed that attackers breached its Cadence cloud computing environment last month by exploiting a critical, recently patched vulnerability in TeamCity, gaining acc...
Hardware wallet manufacturer Trezor revealed on Friday that 67,000 additional U.S. customers had their personal data exposed in a breach at its third-party fulfillment partner Ship...
Broadcom has rolled out emergency security patches for two serious vulnerabilities in VMware Workstation and VMware Fusion, both capable of breaking the virtual machine boundary an...
A critical-severity vulnerability in the Elementor Pro WordPress plugin is being actively exploited by threat actors to compromise websites, according to WordPress security firm De...
The Nightingale Collective, an AI safety nonprofit, has revealed that approximately 18,000 autonomous AI agents identifying themselves as OpenAI systems flooded a dormant German wi...
Threat actors are actively exploiting two newly disclosed PaperCut vulnerabilities—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution)—to steal creden...
As enterprise deployments of autonomous AI agents accelerate, insurers and corporate security leaders are scrambling to quantify — and contain — the financial fallout from unintend...
The U.S. State Department has announced a $10 million reward for information leading to the location or identification of Amir Yaryab, a senior Iranian official accused of leading ...