Cybersecurity News
Latest updates from top security sources
1589 articles, page 8 of 53
Microsoft's Security Research team has issued a warning about a high-volume phishing campaign that leverages invisible Unicode tag characters to evade email security filters. The t...
PostgreSQL has patched a severe security vulnerability—tracked as CVE-2026-6471 and dubbed "PostGREShell" by researchers at Cyera—that has lurked in the database engine's logical r...
Researchers at Rapid7 Labs have uncovered a previously undocumented Linux implant, dubbed "ted," compiled directly into trojanized HAProxy load balancers belonging to two South Kor...
Frontier AI models have crossed a critical threshold: they can now autonomously execute end-to-end cyberattacks without human guidance. According to recent reporting from Dark Read...
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks....
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued a...
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX ap...
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The p...
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the...
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old P...
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on Secur...
The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations....
In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, u...
Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses....
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin movi...
Threat actors have launched more than 440,000 exploit attempts against two critical remote code execution (RCE) vulnerabilities in widely deployed WordPress plugins—Super Forms and...
Streaming media platform Plex has issued an urgent advisory urging server administrators and desktop users to update to the latest software versions after patching multiple undiscl...
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, track...
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelli...
Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Exec...
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vu...
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026...
The recent AI warning letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it....
Cybersecurity researchers at Group-IB have disclosed a sophisticated Python-based Windows malware framework called BraZetsu that converts compromised hosts into inventory on an und...
Thomson Reuters disclosed on Wednesday that an unauthorized actor obtained files from C-Track, the court case management platform operated by its West Publishing Corporation subsid...
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campai...
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environme...
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration...
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in a...