Cybersecurity News
Latest updates from top security sources
1595 articles, page 9 of 54
Thomson Reuters disclosed on Wednesday that an unauthorized actor obtained files from C-Track, the court case management platform operated by its West Publishing Corporation subsid...
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campai...
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environme...
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration...
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in a...
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the preval...
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket....
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared ...
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appear...
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Mi...
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Ci...
Microsoft has warned of a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support and help desk personnel. Attackers socially...
A sophisticated business email compromise (BEC) operation dubbed "Phantom Deal" is targeting midlevel employees at large enterprises, leveraging highly convincing fake merger and a...
Capsule Security, founded in 2025 by CEO Naor Paz and CTO Lidan Hazout, has unveiled what it calls the first dedicated runtime security layer for autonomous AI agents. Announced on...
At least 14 Serbian civil society figures—including a member of parliament, a local opposition politician, and student protesters—have been targeted with advanced mobile spyware si...
Cisco has disclosed a critical security vulnerability, tracked as CVE-2026-20212, affecting 10 Silicon One-based Nexus 9000 switches and carrying a maximum CVSS score of 9.8. The f...
A new report from Dark Reading reveals that frontier AI agents have compressed what traditionally takes human attackers roughly two weeks into a ten-hour automated breach, marki...
The Manchester Airports Group (MAG) has confirmed that approximately 8.8 million individuals had their personal data exposed after the FulcrumSec extortion gang published roughly 5...
Thomson Reuters disclosed a significant data breach on Wednesday affecting its C-Track court case management platform, compromising court records and sensitive personal data across...
Threat actors are increasingly abusing the trusted Node.js JavaScript runtime as a covert malware delivery mechanism, targeting government departments, technology firms, and hotels...
AIR Security has emerged from stealth with $50 million in funding to launch what it calls the first firewall purpose-built for AI agents. The round was led by Sequoia Capital and G...
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educ...
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtual...
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming ca...
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to ...
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many gover...
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malwa...
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controlle...
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnera...