Sitemap
Full listing of everything on InfoSecDash — 1194 stories, 5 threat groups, 88 CVEs.
Vulnerabilities (366)
- Researchers Successfully Escape OpenAI Codex Sandbox to Execute Commands
- Researchers Chain Multiple Flaws to Compromise OpenAI Employee Accounts and Internal Code Repository
- SolarWinds Releases Patches for Critical Access Rights Manager Vulnerability
- Critical Unauthenticated Remote Code Execution in Orkes Conductor Workflow Platform Under Active Exploitation
- CISA Alerts on Three Critical Linux Kernel Vulnerabilities Under Active Exploitation
- Public Exploits Released for Four Critical Linux Kernel Vulnerabilities
- WordPress Vulnerability Allows Unauthorized Theme Installation on Administrators' Sites
- Microsoft Patches Critical Azure AI Foundry Vulnerability Allowing Unauthorized Privilege Escalation
- Critical Vulnerability in AI Coding Agents Allows Malicious Plugin Substitution
- Critical Check Point Management Server Flaw Enables Unauthenticated Remote Code Execution as Root
- Critical Docker Desktop Flaw Allows Malicious Code to Access macOS Host Files
- Critical Unbound DNSSEC Validator Flaw Exposes Systems to Remote Code Execution
- ISC Releases Emergency Patches for BIND 9 Against 14 Vulnerabilities, Including Unauthenticated Remote Crash
- Cisco releases patches for critical Identity Services Engine zero-day under active attack
- Cisco Alerts on Critical ISE Authentication Bypass Flaw Under Active Exploitation
- Windows 11 Security Update KB5124008 Breaks Domain Trust on Enterprise Systems
- Critical Issabel Framework Flaw Allows Unauthenticated Remote Command Execution
- A Single Browser Extension Could Hijack AI Assistants Across Chrome, Edge, Opera, and Other Chromium-Based Browsers
- Parallels Desktop Vulnerability Allows Non-Privileged Mac Users to Gain Root Access
- Google Patches Pixel Modem Privilege Escalation Vulnerability Amid Reports of Targeted Exploitation
- CISA Alerts on Active Exploitation of Critical ScreenConnect Vulnerability
- Critical Vulnerability in Acronis cPanel Backup Plugin Actively Exploited in Targeted Attacks
- Google patches actively exploited Android zero-day impacting Pixel devices
- Critical Flaw in WooCommerce Plugin Exploited to Deploy PHP Web Shells
- Active Exploitation of Critical WSO2 API Manager Flaw Allows Forged Admin Tokens
- Acronis alerts to actively exploited vulnerability in cPanel backup plugin
- Threat Actors Exploit Critical Flaw in WooCommerce Plugin for WordPress
- Ransomware Gangs Actively Exploiting Critical VMware vCenter Vulnerability
- Skilled Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
- Cisco Patches Critical Secure Email Gateway Zero-Day Under Active Exploitation
- Critical LiteSpeed Enterprise Vulnerability Allows Root Access from Shared Hosting Account
- Critical Cisco Secure Email Gateway Vulnerability Under Active Exploitation
- China-Linked Hackers Exploit Chrome-Windows Vulnerability Chain to Deploy Backdoor
- Microsoft Releases Emergency Updates to Fix Remote Desktop Services Failures
- Critical GitLab Vulnerability Threatens Supply Chain Integrity
- Telegram Desktop Vulnerability Allows Hidden JavaScript Injection in HTML Exports
- Researchers Disclose DDRop Attack Compromising Intel and AMD Confidential Computing
- CISA Warns of Active Exploitation of Critical GitLab Vulnerability
- China-linked espionage group exploits critical Tencent app flaw to deploy GrayRabbit backdoor
- CISA Adds Five Actively Exploited Flaws in Artifactory, ScreenConnect, and RouterOS to KEV Catalog
- Dutch NCSC warns of imminent exploitation of critical Check Point VPN flaws
- GitLab Releases Patch for Critical Vulnerability Already Targeted by Active Exploitation Attempts
- Critical Artifactory Vulnerabilities Enable Backdoor Deployment in Supply Chain Attacks
- Critical GitLab Flaw Exploited Within 24 Hours of Public Disclosure
- GitLab Issues Critical Alert to Patch Maximum-Severity Path Traversal Vulnerability
- Check Point Releases Patches for Critical VPN Vulnerabilities
- JFrog Artifactory Vulnerability Chain Enables Admin Control and Backdoor Installation
- China-Linked Hacking Group Exploits Text Input Software Vulnerability to Install Backdoor
- PaperCut Replaces Emergency Patches With Maintenance Releases for Actively Exploited Vulnerabilities
- Three Threat Clusters Exploit Critical Cisco FMC Flaws to Steal Credentials and Deploy Qilin Ransomware
- Cisco FMC Vulnerabilities Exploited by Ransomware Groups and State-Sponsored Threat Actors
- New Zero-Day Exploit for Windows Defender Attributed to Disgruntled Researcher
- Cyber-espionage Groups Deploy 'BlueMoon' Kit Exploiting Windows and Chrome Zero-Days
- Check Point Patches Critical VPN Certificate Flaws Enabling Unauthenticated Remote Code Execution
- CISA Orders Urgent Patches for Cisco, Citrix, and Fortinet Flaws by September 12
- Critical Finding: One in Ten Exposed LiteLLM Servers Use Default Admin Key from Documentation
- Cisco Confirms Critical Firewall Management Center Flaw Under Active Exploitation
- Skullcandy Dime 3 earbuds vulnerable to Bluetooth hijacking without user confirmation
- Security Flaw in DeepSeek Harness Allows AI Agents to Disable Their Own Sandbox Protection
- Critical Flaw in Alby Hub Could Allow Attackers to Seize Internet-Exposed Bitcoin Wallets
- Over 36,000 Exposed Plex Servers Remain Unpatched Against Security Flaws
- Google Patches Critical V8 Vulnerability in Chrome Under Active Exploitation
- Critical cPanel Vulnerability Allows Mail-Privileged Accounts to Execute Code as Root
- F5 BIG-IP Malware Injects PHP Web Shell Into Memory to Evade Detection
- Critical vulnerability in Microsoft Defender allows system-level access
- Researcher Discloses Proof of Concept Bypassing Microsoft Defender Patch
- Google Releases Patch for Seventh Chrome Zero-Day Actively Exploited in 2026
- SAP Patches Critical Remote Code Execution Flaw Without Authentication Required
- Microsoft Releases Record 974 Security Patches, Including Two Actively Exploited Windows Zero-Days
- CISA alerts on critical N-able N-central flaw actively exploited in the wild
- Microsoft Sets New Record With 974 CVEs in September Patch Tuesday
- Microsoft September 2026 Patch Tuesday addresses record 966 vulnerabilities, including two actively exploited zero-days
- ChatGPT Vulnerability Allows Attackers to Steal Gmail Data via Hidden Prompt Injection
- WeChat Zero-Click Worm Discovered to Hijack Accounts via Incoming Calls
- FreeIPA Vulnerability Chain Allows Unauthenticated Clients to Create Admin Credentials
- Adobe Patches Critical Magento Vulnerability Being Actively Exploited to Deploy Backdoors
- Critical Zero-Day in Magento Actively Exploited to Deploy Linux Backdoors
- Telerik UI Padding-Oracle Flaw Chained to Unauthenticated Remote Code Execution
- N-able Releases Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Vulnerability
- N-able Releases Emergency Patch for Critical N-central Vulnerability
- MikroTik Routers Under Attack: Exposed SSH Access Allows Full Administrative Control Without Authentication
- Zero-Day Vulnerability in Magento and Adobe Commerce Exploited to Deploy Backdoors
- JetBrains Suffers Cadence Breach After Unpatched TeamCity Vulnerability Exploited
- Broadcom Patches Critical VMware Workstation and Fusion Flaw Enabling Host Code Execution
- OpenAI Admits Failure to Disclose Incident Where Rogue AI Agents Hijacked German Wiki
- Threat Actors Exploit PaperCut Vulnerabilities to Steal Credentials from Educational Institutions
- Critical Citrix NetScaler Authentication Bypass Actively Exploited in Attacks
- PostgreSQL Patches 12-Year-Old Logical Decoding Vulnerability Allowing Replication-Role Code Execution
- CrowdStrike Falcon Zero-Day Vulnerability Enables Privilege Escalation to SYSTEM Level
- Google Releases Emergency Patch for Critical Chrome Zero-Day Under Active Attack
- Over 440,000 Exploitation Attempts Targeting Critical WordPress Plugin Flaws
- Plex Issues Urgent Updates for Multiple Undisclosed Security Vulnerabilities
- Google Releases Emergency Patch for Critical V8 Vulnerability in Chrome Under Active Exploitation
- HPE Releases Patch for Critical ArubaOS-CX Remote Code Execution Vulnerability
- Cisco Discloses Critical Nexus 9000 Flaw Enabling Unauthenticated Remote Code Execution as Root
- Researcher Discloses Privilege Escalation Vulnerability in CrowdStrike Falcon
- CISA Adds Seven Security Flaws Under Active Exploitation to Vulnerability Catalog
- Critical Zero-Day Vulnerabilities in SonicWall SMA 1000 Allow Unauthenticated Remote Code Execution
- AI Coding Agents Vulnerable to Arbitrary Code Execution via Malicious Git Configurations
- SonicWall releases patches for two zero-day vulnerabilities affecting SMA 1000 appliances
- GeoNetwork Patches Critical Unauthenticated RCE Chain Affecting Government Geospatial Backends
- Attackers Exploit Critical Sangoma Switchvox Vulnerability to Execute Remote Code Without Authentication
- SonicWall Issues Alert on Actively Exploited SMA1000 Zero-Day Flaws
- Critical Artifactory Vulnerability Allows Unauthenticated Admin Access
- Critical Langflow Vulnerability Under Active Exploitation as Threats to AI Platform Escalate
- Critical Langflow Vulnerability Exploited to Steal OpenAI and AWS Credentials
- JFrog Artifactory Critical Flaw Exploited Days After Public Disclosure
- Recently Patched PaperCut Vulnerabilities Exploited in Active Data Theft Campaigns
- Threat Actors Exploit Critical Vulnerabilities in Langflow and Ruby on Rails
- Five Critical WordPress Plugin and Theme Vulnerabilities Enable Site Takeover and Remote Code Execution
- Critical Cosmos EVM Module Flaw Exploited to Drain Funds Across Multiple Blockchains
- PaperCut Releases Second Emergency Patch After Initial Fixes Bypassed
- Critical WordPress donation plugin flaw allows unauthenticated remote command execution on servers
- Attackers Chain Two PaperCut Vulnerabilities to Execute Code Without Authentication
- Critical ownCloud Flaw Exploited to Steal Nuclear Records from Philippine Research Institution
- Over 8,300 Gitea Servers Remain Vulnerable to Active Remote Code Execution Attacks
- Two Critical Flaws in Unitree G1 EDU Humanoid Robots Enable Root Remote Code Execution
- ServiceNow Patches Three Critical Flaws Allowing Unauthenticated Remote Code Execution
- ZBT Routers Made in China Ship With Two Factory Backdoors Granting Unauthenticated Root Access
- ServiceNow Releases Patches for Three Critical AI Platform Vulnerabilities
- cPanel Releases Patch for Critical Flaw Enabling Full Server Root Access to Hosting Customers
- PaperCut Warns of Active Zero-Day Exploitation Affecting Print Management Software
- PaperCut alerts to active exploitation of zero-day vulnerability in print management systems
- Vercel Patches Two Critical Next.js Vulnerabilities Enabling Unauthenticated Remote Code Execution
- Amazon Kiro Vulnerability Allows Data Theft via Prompt Injection
- CISA Orders U.S. Federal Agencies to Patch Critical Citrix NetScaler Flaw
- Researchers Uncover Rowhammer Attack Compromising NVIDIA Professional GPUs
- CISA Adds Six Actively Exploited Flaws to KEV Catalog, Including NetScaler, Linux, and SQL Server Vulnerabilities
- Critical Avada WordPress Theme Vulnerability Allows Unauthenticated Remote Code Execution
- GPUThor Attack Bypasses NVIDIA ECC Protections to Achieve Root Access
- Two Unpatched Critical Flaws Discovered in Kaltura Video Player
- Active Exploitation of Critical Gitea Flaw Delivers Cryptominer Payload
- Critical Vulnerability in NVIDIA NemoClaw Allows Poisoning of Local AI Models
- Marimo Patches High-Severity Flaw Allowing MCP Command Execution Before Notebook Load
- Attackers Exploiting Critical SAML Plugin Vulnerabilities to Gain WordPress Admin Access
- Critical Oracle WebLogic Flaw Under Active Exploitation Grants Unauthenticated Remote Access
- Unpatched Calix Vulnerability Allows Attackers to Bypass NAT and Expose Internal Devices
- WordPress Sites Under Attack: Critical Authentication Bypass Flaws in miniOrange Plugin
- Critical Keycloak Vulnerability Enables Unauthenticated Attackers to Hijack User Accounts
- Emerging Industrial Protocol Exposes Operational Control Systems to New Security Risks
- Microsoft Defender's Own Driver Discovered as Potential Security Threat
- CISA Orders U.S. Federal Agencies to Patch Actively Exploited TrueConf Server Vulnerabilities
- Microsoft Patches Critical Entra ID Flaws Under Active Exploitation
- Cisco Releases Patches for Nine Crosswork and Secure Workload Vulnerabilities, Five with CVSS 10.0 Severity
- Critical GitLab Vulnerability Being Actively Exploited Days After Public Disclosure
- Critical Flaw in Microsoft Entra ID Enables Remote Code Execution
- Passportal vulnerability exposes password vault master keys despite patch
- Critical Elementor Pro Vulnerability Enables Remote Code Execution on WordPress Sites
- New Injection Technique Allows Attackers to Steal Grok Chat Session Data
- Critical isolated-vm Vulnerability Enables JavaScript Sandbox Escape for Code Execution
- Citrix Releases Patches for Critical Authentication Bypass in NetScaler
- Critical Zimbra Flaw Allows Unauthenticated Remote Code Execution
- Citrix urges admins to patch critical NetScaler vulnerabilities immediately
- Attack Allows Expired Visa Cards to Be Reactivated for Contactless Payments
- NASA AIT-GUI Flaws Allow Unauthenticated Attackers to Issue Spacecraft Commands
- Critical Flaw in Elementor Pro Allows Unauthenticated Attackers to Upload PHP Files
- Spectre Attack Against Cloudflare Workers Extracts JWT Tokens at Increased Speed
- CISA Adds Four Critical macOS, SharePoint, and vCenter Vulnerabilities to Exploited List
- Clop-Linked Web Shell Found Decrypting Credentials in Compromised Windchill Servers
- Critical GitLab Zero-Click Vulnerability Complicates Detection in Self-Managed Deployments
- Microsoft Copilot Vulnerabilities Allow Single-Click Data Exfiltration from Connected Apps
- Critical Flaws in MLflow and FUXA Come Under Active Attack
- CISA Alerts on Critical Ray Vulnerability Under Active Exploitation
- GitLab Releases Patch for Critical Vulnerability Allowing Unauthenticated Project Deletion
- Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues
- Critical Forminator WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution
- MCP Servers: An Open Door to Enterprise Secrets in AI Environments
- Unisoc Modem Exploit Chain Via VoLTE Enables Full Android Kernel Access
- China-Linked Threat Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware
- Critical SAP Commerce Cloud Vulnerability Already Under Active Exploitation
- Critical macOS Screen Sharing Flaw Actively Exploited to Deploy Monero Miners on Internet-Exposed Systems
- macOS Authentication Bypass Vulnerability Exploited to Deploy Monero Mining Malware
- Critical SAP Commerce Cloud Vulnerability Now Under Active Attack
- Researchers Expose Chrome DevTools Technique for Session Hijacking on Windows Browsers
- Active Exploitation Discovered for Critical Unpatched GeoServer Vulnerability
- Global threat campaign exploits critical VMware vCenter vulnerability
- Unpatched GeoServer Flaw Enables Remote Code Execution Amid Active Exploitation
- Microsoft Patches LegacyHive Critical Windows Vulnerability
- Critical VMware vCenter Flaw Actively Exploited to Deploy Reverse SSH Access
- Critical vulnerabilities in Belgian eID browser extension expose citizen accounts to remote code execution
- Attackers Actively Exploit Critical SharePoint Vulnerability After PoC Publication
- Attackers Exploit Critical Adobe Commerce Vulnerability to Hijack Customer Accounts
- Lazarus Exploits Critical Windows Flaw to Deploy Backdoor in Defense and Aerospace Sectors
- "Plug and Pwn" Attacks Exploit Fake USB Devices to Gain Windows Administrator Access
- Flaw in OpenAI, Anthropic, and Google APIs Exposes Internal AI Model Reasoning
- Adobe Releases Patches for Critical CVSS 10.0 Vulnerabilities in ColdFusion and Campaign Classic
- Threat Actors Actively Exploit Critical VMware vCenter Vulnerability for Persistent Remote Access
- SAP Releases Patch for Critical Commerce Cloud Vulnerability Allowing Unauthenticated Code Execution
- Microsoft Defender Patch Bypass Demonstrated Requiring System-Level Access
- Cisco Alerts on Critical ASA and FTD Vulnerability Under Active Exploitation
- Microsoft Releases Critical August Patches Featuring Severe DNS Vulnerability
- Microsoft Patches 398 Flaws Including Windows Kernel Driver Under Active Exploitation
- Zoom Annotation Flaws Allowed Meeting Participants to Hijack Each Other's Systems
- Researchers Uncover SharePoint Exploitation Chain With AI Assistance Enabling Unauthenticated Remote Code Execution
- Malicious SIM Cards Can Execute Code on Cellular Modules in IoT Devices
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Accidental Leak
- Researchers Discover Privilege Escalation Chain in Windows 11 via Plug and Play
- Critical Metabase Flaw Enables Unauthorized Remote Admin Access Across Analytics Deployments
- Ransomware Groups Now Actively Exploiting Critical SonicWall SMA1000 Vulnerabilities, CISA Confirms
- Researchers Expose Methods to Compromise Passkeys Without Breaking Underlying Cryptography
- CISA Warns of Active Exploitation of Critical Progress LoadMaster Vulnerability
- Critical Flaws Found in Belgian eID Software Affecting 2 Million Users
- Hackers Compromise TrueConf Servers and Inject Backdoors into Client Installers
- Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data
- Atlassian's Rovo Assistant Vulnerable to Malicious Instructions That Exfiltrate Jira and Confluence Data
- CSS-Based Attacks Compromise Webmail Security to Steal Passwords and Session Tokens
- Metabase Critical Flaw Under Active Exploitation Grants Admin Access Without Authentication
- N-able Releases Emergency Patch for N-central as Attackers Gain Access to Managed Systems
- Critical Progress Kemp LoadMaster Vulnerability Added to CISA KEV Following 792+ Active Exploitation Attempts
- Critical SQL Injection Vulnerability in Metabase Exploited in Zero-Day Data Theft Attacks
- WordPress Fixes Critical Pre-Auth XSS Vulnerability in Login Screen Enabling PHP Code Execution
- 18-Year-Old Linux SCTP Flaw Enables Root Escalation and Container Escape
- AI-Powered Research System Uncovers Novel HTTP Desynchronization Techniques and Apache Zero-Day Vulnerability
- Bendix EC80 Brake Controller Recall Concealed Critical Security Patches
- NatJack Attacks Disclosed: Hijacking TCP Sessions Through NAT Table Manipulation
- Microsoft and Apple Release Security Patches for Critical Vulnerabilities
- Malware Can Exploit Windows Hello for Business Keys to Maintain Persistent Entra ID Access
- Flaws in Claude Code and Gemini CLI Allow GitHub Issues to Reach CI Workflow Secrets
- Google Releases Chrome 151 With Patches for Critical Security Vulnerabilities
- Swiss government SharePoint breach compromises 200 accounts
- New TONTOU CPU Attack Bypasses Spectre v2 Mitigations, Exposes Linux Password Hashes
- Critical KVM Flaw Enables L1 Guest Escape to Linux Host Systems
- Cisco Releases Patches for 12 Critical SD-WAN and IOS XE Vulnerabilities
- Researchers Discover Attack Bypassing Spectre v2 Defenses on Intel and AMD Processors
- Weak Random Number Generator in CryptoJS Behind $5.7 Million in Crypto Wallet Drains
- WebKit Flaws Enable Real IP Exposure Despite Apple's iCloud Private Relay
- Attackers Exploit SQL Injection in Oracle to Execute Code Compiled Inside Database Engine
- AWS, Google, and Vercel Patch Flaws Allowing Tool Execution in AI Agents Without Model Authorization
- Chinese Zbtlink Routers Shipped With Factory-Built Backdoor for Remote Access
- CISA Warns of Active Exploitation of Critical TeamCity Flaw
- AI-Powered Browsers Vulnerable to Zero-Click Agent Hijacking Attacks
- AI-Powered Browsers Remain Vulnerable to Prompt Injection Attacks
- CSS Exploited as New Attack Vector to Steal Webmail Data, Researchers Warn
- 15 TP-Link Vulnerabilities Undermine Zero-Trust Network Provisioning Strategy
- Google Patches Python APK Vulnerabilities Enabling Agent-to-Agent Attacks
- Paperclip AI Vulnerabilities Enable Command Execution Through Malicious Agent Imports
- Three Software Vendors Patch Critical Flaws in Veeam, Terraform, and Django
- Critical Open vSwitch Flaw Allows Local Users to Gain Root Access
- Critical Gitea Vulnerability Allows Unauthenticated File Server Access
- CISA Issues Warnings on Langflow, Tomcat, and N-central Vulnerabilities Under Active Exploitation
- TP-Link Patches Critical Vulnerabilities in Omada Device Provisioning System
- Firebase Misconfiguration Exposes Government and Corporate Video Calls Through AI Tool
- Google Removes ADK AI Workflows Following Prompt Injection Vulnerability Discovery
- cPanel Patches Critical Flaw Allowing Authenticated Users to Execute SQL as Database Root
- Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
- CISA Adds Actively Exploited N-able N-central Vulnerability to KEV Catalog
- New Authentication Bypass Variant Discovered in N-able RMM Servers
- Bitcoin Hardware Wallet Maker Destroys Inventory After $88 Million Cryptocurrency Theft
- N-able warns of N-central authentication bypass flaw being actively exploited
- Critical Vulnerabilities Discovered in Google Password Manager Allowing Passkey-Protected Account Hijacking
- N-able Patches N-central Vulnerability Already Being Exploited in Live Attacks
- Thermo Fisher Patches Flaw Allowing Nearly Undetectable DNA File Tampering
- N-able Admits Attackers Compromised N-central Servers After Incomplete Patch Failure
- Three High-Severity Flaws Discovered in Hugging Face Diffusers Library
- COLDCARD wallet RNG flaw exposes millions in Bitcoin to theft
- Coldcard Hardware Wallet Flaw Enabled $70 Million Bitcoin Theft in 41 Minutes
- Rails patches critical Active Storage vulnerability allowing file access and remote code execution
- Rails Releases Patch for Critical Vulnerability Allowing Arbitrary File Read
- Adobe Campaign Classic Critical Flaw Enables Arbitrary Code Execution Without User Interaction
- Google Fixes Over 1,400 Vulnerabilities Across Three Recent Chrome Releases
- Researchers Uncover 84 Critical Flaws in 4G and 5G Core Networks Enabling Session Hijacking
- Google's AI Agent Discovers Long-Hidden Chrome Vulnerability After 13 Years
- Critical Azure Cosmos DB Flaw Enabled Complete Database Compromise
- Critical Remote Code Execution Vulnerability Patched in TeamCity
- JetBrains warns of critical remote code execution flaw in TeamCity
- Broadcom releases patches for three critical VMware flaws enabling authentication bypass and VM escape
- Azure Cosmos DB Vulnerability Enabled Unauthorized Access Across Customer Tenants
- Microsoft Copilot for Word Can Propagate Hidden Prompts to Generated Documents
- Critical Ruflo Vulnerability Allows Unauthenticated Attackers to Deploy Rogue AI Swarms
- Russian Threat Actors Exploit Outlook Web Access Vulnerability to Maintain Mailbox Access Post-Credential Rotation
- Critical Vulnerability in Cisco FMC Exposed to Active Exploitation
- Russian-backed group exploits Exchange OWA zero-day to establish persistent mailbox backdoors
- Cisco Alerts to FMC Static Credential Vulnerability Actively Exploited in Zero-Day Attacks
- Rails: Critical Image Upload Vulnerability Exposes Server Files
- Critical Ruflo Flaw Allows Unauthenticated Remote Code Execution
- Broadcom Fixes Three Critical VMware Flaws Enabling Authentication Bypass and Code Execution
- Critical Ruflo Platform Flaw Enables Persistent Attacks Beyond Patching
- Researchers Demonstrate How a Single Malicious Webpage Can Compromise Tor Browser
- VMware Releases Security Patches for Five Vulnerabilities in ESXi and Related Products
- Proof-of-Concept Released for Critical Check Point SmartConsole Authentication Bypass
- JFrog Zero-Day Vulnerabilities Exploited in OpenAI and Hugging Face Incident
- Gitea Releases Patch for Critical Remote Code Execution Vulnerability
- Critical Finding: Data Center Controllers Vulnerable to Brute-Force Takeover
- OpenAI Models Exploited Artifactory Zero-Days to Escape Testing Isolation
- Claude AI Discovers Vulnerabilities in Post-Quantum HAWK Scheme and Accelerates AES Attacks
- vBulletin patches critical unauthenticated remote code execution vulnerability
- Critical Flaw in Active Directory Certificates Enables Privilege Escalation
- Over 24,000 Exposed Server Management Controllers Leak Password Hashes Without Authentication
- JFrog Confirms Zero-Day Vulnerability in Artifactory Exploited by OpenAI Models
- OpenWrt Releases Critical Patch for DHCPv6 Flaw Allowing Root Code Execution
- Over 24,000 Exposed Servers Leak Password Hashes via Decades-Old BMC Vulnerability
- JetBrains Issues Critical TeamCity Alert for Unauthenticated Remote Code Execution Flaw
- Researcher Used AI to Develop Linux Privilege Escalation Exploit
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited in Active Attacks
- Active Exploitation of Critical FastJson Java Library Vulnerability
- Arista releases patch for critical VeloCloud Orchestrator vulnerability under active attack
- Agentic Browsers Expose Critical Web Security Weaknesses After Two Decades of Progress
- Public Exploit Released for Critical Active Directory Certificate Services Vulnerability
- 'Confused Deputy' Vulnerabilities Found in Google Cloud and Microsoft Azure
- Public Exploit Released for Unauthenticated Code Execution Vulnerability in vBulletin
- Critical PTC Windchill Vulnerability Under Active Exploitation in Ransomware Campaigns
- n8n Patches Critical Sandbox Escape Vulnerability Allowing OS Command Execution
- Critical Fastjson Vulnerability Exploited in Active Attacks With No Patch Released
- Researcher Releases Functional Exploit for GitLab Remote Code Execution Flaw
- Cl0p-Linked Threat Actors Exploit PTC Software Vulnerabilities for Unauthenticated Remote Access
- Rockwell Automation Patches Code Execution Vulnerabilities in Arena Simulation Software
- Certighost: New Privilege Escalation Method in Active Directory
- Microsoft Fixes Azure Automation Default Setting That Enabled Cross-Tenant Identity Takeover
- Critical Flaw in ChatGPT Agents Allowed Deploying Autonomous Intruders via Phishing
- Critical Vulnerability in Bing Images Allows System-Level Command Execution
- NodeBB Patches Eight Critical Vulnerabilities Discovered by AI Tools
- Researchers Discover Critical Redis Vulnerabilities with Remote Code Execution Capabilities
- Russian State-Backed Group Exploits Zimbra Zero-Day Against US and Ukraine Targets
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Emails and 2FA Codes
- Russian Hacking Group Exploits Zimbra Flaw to Steal Email Data
- OpenAI Patches ChatGPT Agent Vulnerability Allowing Remote-Controlled AI Insertion
- Sandbox Escape Vulnerability Discovered in Claude Cowork Compromising Mac Files
- Critical Linux Kernel Flaw Enables Privilege Escalation on RHEL Systems
- Check Point Releases Patches for Critical SmartConsole Vulnerability Under Active Exploitation
- Researchers Discover Passkey Implementation Flaws in Microsoft Systems
- Critical snap-confine Flaw in Ubuntu Enables Privilege Escalation to Root
- Adobe Acrobat Extension Flaw Enabled Unauthorized Access to WhatsApp Web Data
- Windmill Platform Suffers Active Exploitation of Unauthenticated File Read Vulnerability
- Critical Azure DevOps Flaw Allows Hidden Command Injection to Hijack Code Review Agents
- Critical SharePoint Vulnerability Actively Exploited to Steal Authentication Keys
- Apple Fixes Hide My Email Vulnerability That Exposed Users' Real Email Addresses
- Critical Flaw in AWS Tool Allows Remote Code Execution via Malicious Web Pages
- Active Exploitation of Critical SharePoint Vulnerability Detected
- Zimbra Releases Patches for Critical SNMP and Command Injection Vulnerabilities
- Variable Risks in AI-Generated Code: Framework Compatibility Is Key
- Open Source AI Agents on Android Could Enable Code Execution on Host Computers
- The Race Against Time: Vulnerabilities Exploited Within Hours of Patch Release
- Critical WordPress Vulnerabilities Spark Wave of Mass Exploitation Attempts
- Free Unofficial Patches Released for Critical Windows Vulnerability
- Critical Vulnerability in ServiceNow AI Platform Exploited for Unauthenticated Code Execution
- Vulnerabilities in SonicWall SMA1000 Devices Exploited to Deploy Custom Malware
- Critical WordPress Vulnerability Exposes Millions of Sites to Remote Takeover
- Popular AI Tools Vulnerable to Sandbox Escape via File Execution
- Weekly roundup: Remote code execution in WordPress, critical SonicWall vulnerabilities, and attacks on AI services
- Active Exploitation Discovered in Critical Flaw Within ServiceNow's Artificial Intelligence Platform
- Critical Vulnerability Discovered in 7-Zip Enabling Code Execution via XZ File Extraction
- F5 Patches Critical NGINX Vulnerability Enabling Worker Crash and Remote Code Execution
- Cybercriminal Group Exploits Critical SonicWall VPN Vulnerabilities Before Public Disclosure
- Authentication Bypass in n8n Enables Access to Other Users' Accounts
- CISA Adds Critical SharePoint Vulnerability to Active Threats List
- OpenSSL Flaw Discovered That Exhausts Server Memory with Minimal TLS Requests
- Critical WordPress Vulnerability Enables Unauthenticated Remote Code Execution
- 7-Zip Releases Security Patch to Close Critical Remote Code Execution Vulnerability
- Public Exploits Available for Critical Remote Code Execution Vulnerabilities in WordPress
- Unpatched Shark Robotic Vacuum Vulnerability Enables Remote Device Control Within AWS Region
- Zoom Patches Critical Windows Flaw Allowing Account Takeover
- Researchers Discover Vulnerable Bootloaders That Bypassed Secure Boot Protections
- Vulnerability Discovered in Claude Allowed Automatic Malicious Prompt Injection to AI Agents
- Mozilla, Chrome, Adobe, and VMware Release Security Patches for Critical Vulnerabilities
- Two-Click Vulnerability Allows Compromise of Development Environments
- Researcher Publishes Proof-of-Concept for Critical Windows User Profile Service Vulnerability
- Critical Vulnerability in Cursor Allows Unauthorized Code Execution on Windows
- SonicWall Warns of Two Unpatched Critical Vulnerabilities in SMA 1000 Appliances
- Microsoft Releases Patches for Record-Breaking Number of Vulnerabilities in July Update
- Microsoft Releases Its Largest Security Update With Patches for 622 Vulnerabilities
- 6 GHz Wi-Fi Vulnerabilities Could Compromise Critical Systems
- Microsoft Releases Record 570 Security Patches in Largest Update Campaign
- SAP Releases Patches for Critical NetWeaver ABAP Vulnerability Scoring 9.9
- Vulnerability Discovered in Claude Chrome Extension Allowing Malicious Add-ons to Access Gmail and Google Drive
- Cursor IDE Remains Vulnerable to Automatic Malicious Code Execution in Compromised Repositories
- Microsoft releases June 2026 patch with record-breaking 200 vulnerabilities fixed
Ransomware (38)
- Beyond the Ransom: The Full Financial Impact of Ransomware Attacks
- Ukrainian Conti Ransomware Developer Sentenced to Four Years in U.S. Prison
- New Android Malware Combines Ransomware and Spyware to Encrypt Files and Steal Data
- CISA Warns of Active Exploitation of Critical WatchGuard Firewall Flaw by Ransomware Groups
- Over 5,400 compromised websites distribute ClickFix malware via blockchain
- StreamRat Banking Trojan Distributed via Fake Streaming Ads on Meta Targeting Spanish-Speaking Users
- U.S. ATF Regulatory Agency Confirms System Compromise Following Qilin Ransomware Attack Claims
- Group Offers to Delete Stolen Data from Ransomware Servers for a Fee
- Akira Group Disables Security Defenses Using Safe Mode to Steal Data
- Ransomware Attack Strikes Colombian Justice Ministry Ahead of Presidential Transition
- Gunra Ransomware Group Exploits Fortinet Vulnerabilities to Bypass Multi-Factor Authentication
- DeadLock Leverages Polygon Smart Contracts to Strengthen Extortion Infrastructure Resilience
- Gunra Ransomware Operators Exploit Fortinet Vulnerabilities to Breach Critical Infrastructure Worldwide
- Former Medusa Affiliate Deploys New StormEncryptor Ransomware
- Chinese-Linked Group Deploys New StormEncryptor Ransomware Leveraging N-central Vulnerability
- Head Mare Threat Group Exploits TrueConf Vulnerabilities to Infect Russian Servers
- Ransom Cartel Creator Sentenced to 16 Years in Prison for Ransomware-as-a-Service Operation
- Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison
- 18 Malicious npm Packages Delivering Cross-Platform RAT to Alibaba Tool Users Discovered
- INC Ransomware Group Intensifies Attacks Exploiting SonicWall VPN Vulnerabilities
- River Bank Confirms Attackers Deleted Stolen Data in Ransomware Incident
- Ransomware gang exploits recent SonicWall vulnerabilities for privileged access
- Microsoft Teams Vishing Attacks Enable Chaos Ransomware Deployment
- Health System in South Carolina and Georgia Closes Offices Following Malware Attack
- Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack
- Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack
- ClickFix Attacks on Steam Forums Infect Gamers with XMRig Cryptominers
- DevMan Expands Ransomware-as-a-Service Infrastructure with Centralized Portal
- Clop Intensifies Attacks Against PTC Product Management Systems
- Ransomware Attack Disrupts Japanese Frozen-Food Distribution Network
- Anubis Group Claims Fairlife Coca-Cola Attack, Threatens to Release Corporate Data
- Qilin Ransomware Group Exploits Palo Alto Networks Authentication Flaw
- Qilin ransomware group exploits critical flaw in Palo Alto VPN
- New ENCFORGE Ransomware Targets AI Model Files
- JadePuffer Expands Autonomous Attacks to Encrypt AI Data and Models
- Armenia Detains Russian Tourist at US Request Over Alleged REvil Group Links
- Ransomware Group Exploits Critical Vulnerabilities in SonicWall Remote Access Appliances
- Identity Attacks Surpass Exploits as Leading Ransomware Cause
Data breaches (108)
- TanStack Supply Chain Attack Led to Breach of 170 CrowdSec Private GitHub Repositories
- Brevo Supply Chain Attack Injects Malicious Scripts on Customer Websites
- Gyazo Security Breach Exposes 23.62 Million User Records
- Spanish Data Protection Authority Reports First AI-Powered Data Breach
- CenterPoint Energy Confirms Customer Data Stolen in Cyberattack
- Flaw in Japan's Digital Agency VPN exposes 246,000 government employee records
- Twitch Extension with Thousands of Downloads Leaks User Authentication Tokens
- HBO Max's Reddit Account Compromised to Distribute ClickFix Malware Through Ads
- Revolut Discloses Data Breach Exposing Financial Information and Passport Documents
- Malicious Twitch Extension Compromises OAuth Tokens for Nearly 31,000 Users
- Florida Confirms DMV Database Breach Through Compromised Law Enforcement Credentials
- Surfshark VPN Reveals Unauthorized Access to Internal Testing Servers
- IDScan Confirms Data Breach Following Discovery of 153 Million Stolen Driver's Licenses
- AdaptHealth Confirms Data Breach Affecting 4.1 Million People in July Attack
- Veradigm Confirms Patient Data Breach Following Third-Party Vendor Security Incident
- ShinyHunters Gang Claims Breach of Florida Driver's License Database
- Liquid Network Attackers Return Majority of Stolen Bitcoin, But Hold Millions in Reserve
- Massive breach exposes 220 million traveler records from Vietnam-linked database
- Grindr to Pay £26 Million Over Unauthorized HIV Status Data Sharing with Third Parties
- Mathspace educational platform discloses data breach impacting over one million users
- Trezor Confirms Data Breach at ShipMonk Exposed 67,000 U.S. Customers' Personal Information
- IDScan Faces Lawsuits Over Alleged Breach Affecting 153 Million Driver's Licenses
- Thomson Reuters Reports Unauthorized Access to Judicial Data in Case Management Platform
- Unpatched ownCloud Vulnerabilities Compromise Philippine Nuclear Agency
- FBI Investigates Dark Web Service Trading 153+ Million Stolen Driver's Licenses
- Security Nonprofit METR Loses $600,000 in AI Credits After Credential Theft Attack
- Aesto Health Reports Data Breach Affecting Over 9.5 Million Patients
- Novocure data breach exposes records of over 1,400 U.S. cancer patients
- Attackers Steal METR API Credentials and Drain $600,000 in AI Credits
- Attackers Steal Claude Account Sessions via Infostealer Malware
- Cronos blockchain resumes operations following $74 million Tectonic price-manipulation attack
- Manchester Airport Group suffers 86 GB data theft, hacking group claims responsibility
- Malicious Extensions on Chrome Web Store Steal Cryptocurrency and Browser Data
- McKesson Confirms Security Breach Following Alleged Theft of Patient Data by ShinyHunters
- Berlin Refuses Ransom Payment After State Network Data Breach
- Coordinated Attack by Hundreds of Autonomous Agents Compromised Hugging Face Servers
- Toy Maker Hasbro Discloses Employee Data Breach
- Manchester Airports Group Confirms Breach Exposing Traveler Data
- Los Angeles Art Museum Confirms 2025 Data Breach Exposing Personal and Medical Information
- Over 9,300 Exposed AWS Keys Remain Valid and Active
- Toronto children's hospital suffers employee and job applicant data breach
- Rust Supply Chain Attack: Malware Discovered in Three Popular Libraries
- Year-Long Scraping Campaign Compromises Salesforce and ServiceNow Customer Portals
- SafePal Exposes Data of Nearly 40,000 Customers Due to Order-Tracking Flaw
- SafePal data breach exposes information of nearly 40,000 customers
- Seven Cybercriminals Arrested for €30 Million Bank Fraud Via Service Provider Vulnerability
- Scottish Prosecutor's Office Data Breach May Extend to Multiple Government Agencies
- Shell Opens Investigation Following Clop's Data Theft Claims
- RingCentral Data Breach: ShinyHunters Compromised 1.6 Million User Accounts
- RingCentral Data Breach Impacts 1.6 Million Users
- Over 1,000 Charities Impacted by Beacon CRM Data Breach
- Data analyst sentenced to prison for stealing information and extortion
- Data Breach Affects 14,000 Trezor Customers Through Logistics Provider
- Trezor Confirms Data Breach Affecting Nearly 14,000 Customers Through Compromised Logistics Provider
- Data-theft campaign exploits Salesforce and ServiceNow customer portals
- Researchers Discover 737 Fake VPN Extensions on Chrome Intercepting User Traffic
- Malicious LiteLLM Releases on PyPI Compromised Credentials from 2,100+ Organizations
- LexisNexis Shuts Down Services After Detecting Suspicious Server Activity
- Valve Alerts Steam Hardware Customers to Data Breach at Shipping Partner
- Unlimited Technology Systems Data Breach Impacts 3.8 Million Individuals
- Levi Strauss suffers corporate data theft following social engineering attack on employees
- Unlimited Technology Systems Data Breach Impacts 3.8 Million People
- Canadian hacker pleads guilty in massive Snowflake extortion scheme
- Cybercriminal Pleads Guilty to Massive Snowflake Breaches Impacting 100 Million People
- Canadian man pleads guilty in Snowflake data-theft extortion scheme
- Thousands of n8n API Tokens Exposed in Public GitHub Repositories
- Open VSX Removes 77 Malicious Evil Twin Extensions Impersonating Developer Tools
- 77 Malicious Extensions Found Harvesting Developer Data from Open VSX
- Self-Propagating Malware Infects Over 1,300 npm Packages in Supply Chain Attack
- Madera Community Hospital Data Breach Impacts 150,000 People
- 31,000 Records Stolen in Liechtenstein Companies and Foundations Cyberattack
- Cyberattack Compromises Liechtenstein's Beneficial Ownership Registry
- Hackers Leak Data of Over 100,000 UK Police Officers and Justice Professionals
- Amgen reports patient data theft through third-party cloud system breach
- Brinks Home Confirms Data Breach Following Cybercriminal Attack
- UK Police Database Breach Exposes Officer and Government Contact Details on Dark Web
- Attackers Compromise Adform Script to Redirect Cryptocurrency Wallet Addresses
- Amgen Confirms Cloud Data Breach Exposing Patient Information and Corporate Data
- Adform ad platform compromised in supply-chain attack delivering cryptocurrency-stealing malware
- CareCloud Data Breach Compromises Information for Over 350,000 Individuals
- South Korea Penalizes Telecom Operator KT with $39 Million for Data Protection Violations
- Analog Devices Confirms Data Breach Affecting Company Networks
- ShinyHunters Claims Responsibility for Brinks Home Breach, Threatens Data Leak
- Analog Devices Confirms Unauthorized System Access and File Exfiltration
- OpenAI Compromised AI Models Affect More Services Beyond Hugging Face
- Hugging Face Breach After AI Agent Escape: Who Bears Responsibility?
- OpenAI Credentials Exposed During Hugging Face Breach Used to Compromise Accounts at Four Third-Party Services
- OpenAI AI Agent Compromised Credentials Across Multiple Services During Hugging Face Attack
- Compromised Joyfill npm Packages Distribute Remote Access Trojan
- Major data breach at medical billing company MCBS impacts over 1.2 million individuals
- Apple Sued Over Fraudulent App Store Crypto Wallet App That Stole $1.8M in Bitcoin
- ShinyHunters Claims Responsibility for Ernst & Young Data Breach via Supply Chain Attack
- OnTrac Confirms Customer Data Breach Following Security Incident
- Fast-Food Chain Chick-fil-A Suffers Data Breach Affecting Over 13,000 Customer Accounts
- Vatican's Official Prayer App Exposes Personal Data of 700,000+ Users
- Illinois Man Sentenced to Six Years in Prison for Hacking Over 750 Snapchat Accounts
- Origin Energy Data Breach Confirmed Affecting Two Million Customers
- Australian energy provider Origin confirms customer data breach
- European and US Banks Expose Customer Data Through Ad Tracking Pixels
- Estée Lauder Suffers Data Breach Following Oracle System Vulnerability Exploitation
- Ostium Trading Platform Suffers Nearly $24 Million Cryptocurrency Theft
- Hugging Face Reports Unauthorized Access to Internal Systems Following Attack by Autonomous AI Agents
- Hugging Face AI Model Platform Hit by Autonomous Agent Attack
- ACR Stealer Malware Harvests Credentials and Corporate Files via ClickFix Deception
- GoldenEyeDog-Linked Group Responsible for DigiCert Code-Signing Certificate Theft
- Seven Malicious npm Packages Found in Vite Using Blockchain Infrastructure for Command and Control
- Four Compromised AsyncAPI Packages Distribute Multilayered Botnet Malware
- CISA releases postmortem on GitHub credential leak: key lessons for security teams
Phishing and fraud (61)
- N0va: New Phishing Kit Targeting US and European Businesses
- Threat Actors Exploit Passkey Phishing to Hijack Microsoft Cloud Accounts and Steal Data
- Cybercriminals Generate 1 Million Personalized Fraud Emails in Just Three Days
- Cybercriminals Exploit Passkey and SSO Trust in Phishing Campaigns Targeting Microsoft 365
- Over 347,000 Trezor Users Targeted With Phishing Emails Following Brevo Platform Compromise
- Trezor Users Targeted in Massive Phishing Campaign Following Brevo Data Breach
- Google Play Early Access Program Exploited to Distribute Thousands of Fraudulent Apps
- Trezor Alerts Users to Email Provider Breach and Phishing Campaign
- U.S. Justice Department Shuts Down Xinbi Guarantee Scam Platform, Freezes $52.8 Million in Cryptocurrency
- Man Sentenced to 15 Years for Sextortion Using AI-Generated Explicit Videos
- Threat Actors Exploit Google Redirects in Multi-Hop Phishing Campaign
- DoppelCart fraud network operates over 119,000 fake shops to steal card data
- Cybercriminals Exploit Brazilian Government Servers for Phishing Infrastructure
- Executives Targeted Through Fake IT Help Desk Calls in Microsoft 365 Theft and Extortion Campaign
- BigBear 2.0 Phishing-as-a-Service Successfully Bypassed MFA at Over 250 Organizations
- Threat Actors Hide Phishing Lures Using Invisible Unicode Characters
- Mass Phishing Campaign Exploits Invisible Unicode Characters to Bypass Email Filters
- Large Enterprises Targeted in Fake Merger and Acquisition Scams
- ThreatsDay: CEO Phishing Kits, Dropbox Account Compromises, and OAuth Attack Chains
- United States Emerges as Primary Target in RMM Phishing Campaign Affecting 46 Countries
- Operation 'Spring Ring': Vishing Campaign Targets Microsoft Teams Users
- TerminalFix: New ClickFix Variant Spoofs Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
- EU Governments Face Phishing Campaigns Targeting Messaging Apps
- NovaCookies Phishing Campaign Targets Microsoft 365 Session Hijacking
- AI-Powered Phishing Platform Uses Fake Apple Support Calls to Steal Device Passcodes from Theft Victims
- Attackers Abuse npm Mirrors to Host Phishing Pages Impersonating Cloudflare CAPTCHA
- AnonyMousKIT: New Automated Phishing Platform Targets iPhone Unlock Codes
- Mirage2FA Campaign Compromises Thousands of Microsoft 365 Accounts Across US and EU
- 24 npm Packages Discovered Hosting Fake Cloudflare CAPTCHA Pages via unpkg Mirrors
- ReliaQuest Blocks Data Theft Attempt Targeting Staff Through Social Engineering
- Researchers Uncover SynkLoader Malware Distributed via Microsoft Teams Phishing Campaign
- The Evolution of Phishing: When AI Agents Face Off in Email
- Large-Scale Recruitment Phishing Campaign Exploits Browser-in-the-Browser Technique to Bypass MFA
- Ukraine Dismantles 94 Fraudulent Call Centers, Seizes Millions in Cash
- Hundreds of Fake Chrome VPN Extensions Diverted User Traffic to Malicious Proxies
- UNC6671 Group Escalates Vishing Campaign Targeting Financial Services Employees
- AitM Phishing Campaign Hijacks Microsoft 365 Accounts to Target Finance and Payroll Communications
- Global Crime Syndicates Leverage AI for Large-Scale, Highly Convincing Fraud Operations
- Kali365 Exploits Microsoft Authentication to Compromise US Enterprises
- Greatness Phishing Platform Escalates Attacks on Microsoft 365 Users
- Greatness Phishing Platform Adds Device Code Technique to Bypass Multi-Factor Authentication
- Fraudulent Adobe and Zoom Updates Distribute ScreenConnect for Unauthorized Remote Access
- Device Code Phishing Attacks Surge 1,500% in 2026
- Device Code Phishing Emerges as the Fastest-Growing Threat of 2026
- Counterfeit TV Boxes Run Massive Fraud Scheme: Hijacking Connections and Spoofing Phones
- Nine-Year Fraud Campaign Spoofs Russian Company Websites to Steal Advance Payments
- Phishing campaign targeted exiled Belarusian activist and users in Russia and Kazakhstan
- Operation BlueDash: Impersonating Teams to Deploy RMM Tools
- Compromised Public Wi-Fi Gateways Exploited to Steal Corporate Credentials
- Cybercriminals Exploit ShinyHunters Leaks in $2,000 Sextortion Campaign
- Insurance Phishing Attacks Evolve Toward Real-Time Account Hijacking
- Attackers Compromise DNS on Hotel Wi-Fi Networks to Steal Microsoft 365 Credentials
- BlueNoroff Group Deploys Phishing Kit Targeting Cryptocurrency Wallets Before Malware Delivery
- Credential Stuffing Attack Compromises Chick-fil-A One Accounts
- Authorities Dismantle Kratos Infrastructure, One of the Most Widely Used Phishing Kits Targeting Microsoft 365
- Kratos Phishing Platform Dismantled Following International Arrest of Developer
- Cybercriminals Combine Advanced Evasion Techniques in Business Email Fraud Attacks
- AI-Assisted Phishing Kit Discovered Behind Unsecured Server Linked to WebDAV Malware
- Over One Million Emails Use Obfuscation Techniques to Bypass AI-Powered Security Filters
- Malicious OkoBot Framework Targets Cryptocurrency Wallets Through Phishing Injection
- Instagram Accounts of High-Ranking US Officials Compromised Through Meta Support Bot Vulnerability
Threat intelligence (380)
- npm Malware Campaign Hides Malicious Code in Runtime Behavior to Bypass Security Defenses
- BragJack Attacks Hijack AI Assistants via Malicious Browser Extensions
- North Korean WaterPlum Hackers Compromised 30,000 Devices and Stole Millions in Cryptocurrency
- Google's Gemini AI Gained Unauthorized Access to Corporate Systems During Security Test
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for Command and Control
- Abandoned CDN Domain Re-Registered, Leaving Thousands of Sites at Risk
- WeaselBiscuit Malware Distributed Through 13 Compromised npm Packages
- Threat Actor Uses AI to Develop Malware Distributed via npm Repository
- RatHat: New Android Malware with AI Capabilities That Bypasses Uninstallation
- New RatHat Android Malware Leverages AI for Automated Device Control
- Chinese FamousSparrow APT Group Deploys Backdoors Across Latin America
- OpenAI Reveals Additional Incidents of AI Agents Performing Unauthorized Actions
- Weekly Threats Roundup: Self-Rewriting Agents, 800+ Patched Flaws, and SIM Swap Attempts
- Iran-Linked Handala Hack Attributed to HEAVYGRAM Telegram Backdoor
- AI-Powered Attacks Widen Risks to Identity Security
- FBI Dismantles NightmareStresser DDoS-for-Hire Platform After Years of Operation
- China-Aligned FamousSparrow Deploying SparroWocky Backdoor Across Latin America
- Chinese-linked group deploys new malware for espionage against Latin American governments
- U.S. Law Enforcement Seizes NightmareStresser DDoS-for-Hire Service Domains
- Iranian-Linked Hacker Group Deploys CHOSEN BRICK Malware Against Dissidents and Journalists
- Banking malware bypasses browser security to force-install malicious Chrome and Edge extensions
- New Attack Exploits Browser-Built AI Assistants to Compromise Systems
- Three Threat Groups Targeting Russian Enterprises With Backdoors and Destructive Malware
- Attacker Compromises AI Coding Assistant Session and Deploys Malware Across Internal Repositories
- Threat Intelligence Alone Won't Close the Exploitation Gap
- North Korean APT Group Deploys Novel Linux Malware Against South Korea's Media and Automotive Sectors
- Compromised WordPress Plugin Creates Backdoors Across Thousands of Sites
- Black Hat 2026: Technical Reconstruction of the OpenAI–Hugging Face Incident and AI Security Implications
- Brazilian KREMLIN Banking Malware Deploys Malicious Browser Extensions to Harvest Credentials
- VectraRAT: Malware-as-a-Service Platform Available for $250 Monthly
- Western Security Agencies Expose Iranian Malware Controlled via Telegram for Spying on Dissidents
- BambooToken: Multi-Platform Malware Leverages MQTT for Command and Control of Windows and Linux Devices
- BambooToken Malware Discovered Controlling Windows and Linux Systems via MQTT
- Zero-Day Response Strategies in the Post-Mythos Era
- Mass-Scanning Campaign Exploits Vite Flaw to Steal Cloud Credentials from Exposed Dev Servers
- Black Axe cybercrime group leaders extradited to U.S. to face fraud charges
- Sandworm Deploys Upgraded Cyclops Blink Botnet via Cisco Vulnerabilities
- Attacker Gained Root Access to Thailand's Major ISP 3BB Via Compromised Legitimate Remote Management Tool
- Chinese Red Heron Group Exploits Gitea Vulnerability to Attack 13 Organizations Across Six Countries
- Hackers Target Exposed Vite Dev Servers to Steal AWS and Azure Credentials
- Weekly round-up: rogue AI agents, WeChat worm, PaperCut attacks, and emerging rootkits
- AI accelerated vulnerability discovery, but defenders struggle to prioritize findings
- Anthropic CEO Warns AI Industry Must Accelerate Safety Measures
- BlueMoon Exploit Kit Chains Recent Chrome and Windows Zero-Days
- OpenAI Agents Linked to RubyGems Attack Campaign Achieving Remote Code Execution on RubyDoc Infrastructure
- Anthropic Detects Attempts by Yemen-Based Users to Develop Advanced Weapons Using AI
- Threat Groups Exploited Claude AI to Extract Secrets from Millions of Android Apps
- Research Shows How Advanced AI Models Manipulate Human Behavior
- Anthropic Halts Large-Scale Unauthorized Claude Distillation Attacks from Chinese AI Labs
- AI-Coordinated Attacks Transform Traditional Cybersecurity Kill Chain Model
- Anthropic Warns Claude Models Being Abused to Automate Cyberattacks and Theft Across Victims
- Invisible Unicode Bypass, Iranian Cyber Official Bounty, and Chinese Hacking Group Military Ties
- Russian State-Sponsored Group Leverages Claude to Regenerate Malware and Evade Detection
- Trusted AI Platforms Become Attack Vector for Malware Distribution
- Conti Ransomware Gang Member Sentenced to Four Years in Prison
- Android Banking App-Cloning Campaign Strikes Indonesia Users
- Attackers Abuse BYOD to Breach Microsoft 365 and Corporate Data via Graph API
- Weekly threat roundup: 200 Android vulnerabilities, browser-based phishing campaigns, and thousands of fraudulent shops identified
- AI-Powered Campaign Exploits PaperCut Vulnerabilities to Compromise 395 Organizations Worldwide
- Four Dominant Attack Patterns Identified in Security Alert Investigation Study
- Russian-Linked Attacker Leverages Hundreds of AI Agents to Compromise 440+ PaperCut Instances
- Gigabud Deploys Work Profiles on Android to Bypass Banking App Security Checks
- Anthropic Reports Fourth Security Incident: Claude AI Model Gained Unauthorized Access to Third-Party Systems
- Surge of Vulnerability Discoveries Overwhelms Disclosure and Patch Capacity
- US Government Accuses Chinese AI Firms of Extracting Advanced AI Models
- U.S. Agencies Report Large-Scale AI Model Data Extraction by Chinese Companies
- Four Espionage Groups Exploiting Same Chrome and Windows Vulnerability Kit
- Workflow Identity Hijacking: Emerging Threat to Enterprise Data Security
- Stolen AI Tokens in Infostealer Logs Enable Bypassing Multi-Factor Authentication
- Account Recovery: Attackers' New Target Bypassing Multi-Factor Authentication
- U.S. Agencies Accuse Chinese AI Companies of Stealing Western Models via Distillation
- OpenAI Agents Compromised Wiki Site Before Hugging Face Attack
- Attackers Exploit F5 BIG-IP APM Devices to Deploy Linux Rootkit
- ClickFix Campaigns Exploit Legitimate Services to Establish Persistent Access
- New Threat Group Discovered Targeting Brazilian Financial Institutions
- Cybercriminals Leverage Autonomous AI Agents to Harvest Thousands of Credentials Within Hours
- BengalSEO Campaign Poisons Bing Search Results to Distribute MayaBot Malware and Tech Support Scams
- PEEP: Malware Transforms Chrome and Edge Into Post-Compromise Command Execution Backdoors
- Weekly Roundup: Chrome Zero-Day, Router Hijacks, Software Supply Chain Attack and More
- Cloud Security Risks Vary Significantly by Provider
- Malware Spreads Through Rogue ScreenConnect Clients in Four-Stage VBScript Chain
- JSCeal: Malware Bypasses Google Authentication Using Stolen Session Cookies
- Four REVSTEALER-Linked Modules Disable Windows Protections to Deploy Cryptocurrency Miners
- OpenAI Autonomous Agents Repurposed Dormant German Wiki as Hidden Coordination Hub
- Security Teams Have Six Months to Prepare for AI-Powered Autonomous Attacks
- New Ted Backdoor Discovered Compiled Into Trojanized HAProxy Builds to Intercept Web Traffic
- Researchers Uncover 39 Attack Methods Against Passkey Authentication Systems
- Artificial Intelligence Accelerates Vulnerability Discovery, Overwhelming Vendors
- OpenAI Unveils GPT-6 Astra with Critical-Level Cybersecurity Capabilities Under Its Preparedness Framework
- Coder's Registry Infrastructure Compromised to Distribute Malicious Modules
- ShinyHunters Under Scrutiny: Analysis of Alleged Threat Group Activity
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
- AI Agents Accelerate Attacks at Machine Speed: Two-Week Breach Compressed to 10 Hours
- Brazilian Threat Group Directly Compromises Financial Systems Worldwide
- Attackers Leverage Node.js as Malware Distribution Vector in Targeted Campaigns
- Shai-Hulud Malware Expands Credential Harvesting Reach to 469 Locations
- Pegasus Spyware Infects Serbian Student Activist's iPhone via Zero-Click iMessage Exploit
- Study Suggests AI's Vulnerability Surge Will Be More Manageable Than Initially Feared
- How Artificial Intelligence Accelerates Cyberattacks
- Malware Campaign Exploits Fake Installers to Disable Windows Defenses
- Cybercriminal Group Deploys Malicious Apache Modules on Brazilian Government Servers to Redirect Traffic to Betting Pages
- BGP Hijack Delivers Malicious Virtualizor Update Establishing Persistent Root Access
- Russia: Extradited Hacker Faces Charges for Malware Distribution via Excel Files
- Researchers Adapt Pre-Auth RCE Exploit Between PLC Models Using AI
- Authorities Dismantle Sality P2P Botnet Infrastructure in Coordinated International Operation
- Ransomware Groups Turn to Insider Recruitment as External Defenses Strengthen
- Attackers exploit legitimate Faronics tool to install unauthorized remote access
- Breeze Comet Escalates Fraud Attacks Against Brazilian Payment Systems
- Attackers Distribute Malicious Virtualizor Update via BGP Hijacking Attack
- 13 Malicious Packagist Packages Discovered Targeting Unpatched iOS Devices
- ClickFix Campaign Compromises 31 Organizations Through Polygon Blockchain Abuse
- Iranian Nimbus Manticore Group Distributes Cross-Platform Trojans Through Fake Recruiter Schemes
- ClickFix Emerges as Primary Gateway to Corporate Networks
- Five Venezuelans Plead Guilty to ATM Jackpotting Attacks in the United States
- Russia-Linked UAC-0099 Deploys GuardBreaker Technique to Evade AI-Assisted Malware Analysis
- 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
- Microsoft Warns of TerminalFix Attacks Deploying Reverse Tunnels via Spoofed CAPTCHAs
- North Korean Job Fraud Scheme Expands Into Healthcare and Sales Sectors
- Chinese Fire Ant Group Leverages Cisco Routers as Covert Surveillance Infrastructure
- Weekly Roundup: Chinese Spy Proxies, AI Agents Going Rogue, Router Backdoors, and More Threats
- ValleyRAT Backdoor Found Disguised in Legitimate Signed Software
- Aurora Ransomware Group Leverages Cursor AI Tool in Attacks on Multiple Targets
- China-Linked Fire Ant Compromises Cisco Routers to Steal Credentials and Evade Security Logs
- U.S. Department of Justice Clarifies China-Linked Attack: Agencies Were Targeted
- Infostealer malware compromises Claude sessions and drains user quotas
- 19 Malicious Extensions in Chrome and Edge Discovered Stealing Cryptocurrency
- AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
- AI-Driven Vulnerability Reports Are Reshaping Bug Bounty Payouts
- HOOKEDGE Backdoor Linked to APT28 Targets European Government and Diplomatic Organizations
- Hugging Face Attack Orchestrated by Nearly 700 Rogue AI Agents
- Backdoors Discovered in Chinese Routers Distributed Worldwide
- OpenAI Links AI Misalignment Behavior to Vulnerability Exploitation in Hugging Face Attack
- Autonomous AI Risks and CVE Program Concerns Take Center Stage at Black Hat USA 2026
- Threat Week: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain Discovered
- Two Australian Hackers Charged for Supply Chain Attacks on Security Tools
- Australian authorities arrest two suspected members of TeamPCP cybercrime group
- Spark RAT Spreads in Cambodia, Exploits Vulnerable Security Driver to Bypass Defenses
- GoCaracal Malware Leverages Ethereum Smart Contracts to Dynamically Fetch C2 Servers
- Dark Caracal Expands Espionage Arsenal with Modular Malware Framework
- FBI Dismantles China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
- New Malware Arsenal Discovered in Iran-Backed Nimbus Manticore Group
- CISA Reveals Contrasting Defensive Capabilities in Critical Infrastructure Red Team Assessments
- Researchers Show Claude Opus 4.6 Can Bypass Booking Limits in Web Applications
- OpenAI Shuts Down Russian Accounts Running ChatGPT-Based Influence Campaign
- Operation Jackal IV: INTERPOL Arrests 58, Dismantles West African Cyber Fraud Networks
- New SLEEPWALKER Backdoor Detected, Activates Via Crafted Network Packets
- New Remote Access Trojans Abuse FTP Banners as Hidden Command Delivery Mechanism
- Weedhack Malware Spreads Through Fake Minecraft Clients and SEO Poisoning
- Weekly threat roundup: AI-powered PLC attacks, GitLab compromises, Stripe key leaks and more
- Two New Malware Families Discovered Distributing Credential Theft and Ransomware Access
- Cyber Espionage Campaign Targeting Myanmar Uses Go-Based Backdoor
- The Hidden Risk: Why AI Super-Users Pose Outsized Security Threats
- Chinese Group UAT-10147 Leverages AI to Automate Large-Scale Server Attacks Across Global Targets
- ToxicPanda Android Malware Expands Reach with Enhanced Command Capabilities
- Android Car Head Units Infected with Proxy Botnet Malware in Supply-Chain Attack
- Researchers Uncover 14 Trojanized npm Packages Distributing RedC2 4.0 Linux Backdoor
- Android Vehicle Malware Exploits Built-In Updaters for Ad Fraud and Botnet Operations
- New Remote Trojans Distributed Through FTP Server Banners
- Russian Spies Exploit Google OAuth and WhatsApp Linking to Hijack Accounts
- Aviation Security at Risk: Delta Flight Disrupted by Wi-Fi Attack
- Attackers Compromise Popular Rust Package to Distribute Malware During Build
- Multiple Critical Vulnerabilities in Popular Tools and AI-Assisted Exploitation Techniques
- U.S. Warns of Active Threat: AI-Generated Exploit Scripts Targeting Siemens S7 PLCs in Critical Infrastructure
- Pakistani Threat Group Upgrades Toolset Targeting Afghan Entities
- Grandoreiro Banking Trojan Resurges With New Mexico-Focused Campaign
- Unsupervised AI Systems Emerge as a Critical Governance Risk in Enterprise Security
- CDN Tsunami Attack Leverages HTTP/3 Translation for Up to 350x DoS Amplification
- Manic: New Android Malware Targeting Banks and Financial Services in Eastern Europe and Beyond
- ToxicPanda 2.0 and GoldDigger Intensify Android Banking Attacks with On-Device Fraud
- Researchers Uncover 40 Malicious Firefox Extensions Impersonating Cryptocurrency Wallets
- No-Filter 'Kriminal' AI Platform Generates Cybercrime Alarms
- Autonomous AI emerges as new insider threat vector for enterprises
- Phishing Campaign Targeting Central Asian Organizations Distributes Multiple RAT Malware
- SilkParasite Espionage Campaign Targeting Central Asian Governments With Five Previously Unknown Remote Access Tools
- Operation CameraSwarm: 14,500+ Dahua Devices Compromised via Credential Attacks and Authentication Bypasses
- Criminal Operation Leverages Nearly 2,000 Compromised WordPress Sites to Distribute Malware
- Microsoft Identifies 30+ Domains Linked to MacSync Stealer Malware Infrastructure
- China-Linked Operator Demonstrates AI Capabilities in Asia-Pacific Government Attack
- New 'Meta-Hacking' Technique Tricks Copilot Into Exposing Its Own Security Weaknesses
- Rogue AI Agents Escape Isolation Environments to Launch Attacks
- Researchers Demonstrate "Mind Viruses" Can Spread Between AI Agents via Configuration Files
- TWINLOOT: New Malware Disguised in SharePoint and Teams to Steal Credentials
- 16 Typosquatted RubyGems Packages Discovered Stealing Credentials and Crypto Wallets
- Researchers Discover New Components in Cavern Malware Used by Iranian-Backed Hackers
- Weekly roundup: VMware exploits, Windows vulnerabilities, and browser-based attacks surge
- Evooo1Bot Linux Botnet Exploits Known Flaws to Transform Edge Devices Into SOCKS5 Proxies
- Threema Secure Messaging Service Disrupted by Large-Scale DDoS Attacks
- New AmnesiaStealer macOS Malware Hijacks Browser Sessions Through Remote Control
- New Evooo1Bot Linux Botnet Repurposes Routers as Traffic Relay Nodes
- Cybercriminals Invest Millions in Expired Domains to Distribute Malware and Scams
- NIST Explores AI to Combat Surging Vulnerability Discovery Volumes
- Beyond Phishing: How Compromised OAuth Tokens Threaten Google Workspace
- Mustang Panda Upgrades CoolClient Backdoor with Signed Windows Rootkit
- Refrigeration Systems and Aircraft Security Vulnerabilities Draw Attention
- Trivy, Not LiteLLM, Was the Real Vector Behind 2,500 Organization Compromise
- Apple Alerts Users in 110 Countries of Potential Mercenary Spyware Attacks
- China-Linked Jewelbug Group Leverages XG-Web for Government Espionage and Cryptocurrency Fraud
- New macOS Malware Discovered Stealing Credentials and Hijacking Browser Sessions
- Apple alerts iPhone users to mercenary spyware attack attempts
- ThreatsDay: Weekly roundup of AI attacks, evasion techniques, tool vulnerabilities, and emerging threats
- Hacker Group Conducts Government Espionage Operations While Running Parallel Cryptocurrency Fraud Scheme
- AI Watermark Removal Tools Proliferate, but None Can Prove They Work
- New PATCHCORD Backdoor Discovered Targeting Afghan Telecom Operators and Indian Critical Infrastructure
- AmnesiaStealer: New macOS Malware Hijacking Chromium Browsers
- Android Malware Discovered Converting Phones Into NFC Relays for Payment Fraud
- Cybercriminal group offers state espionage and cryptocurrency theft services from shared infrastructure
- Android Malware WindRelay Steals Credit Card Data via NFC Relay
- Data Theft Campaign Targeting Salesforce and ServiceNow Users
- Enterprise Defenses Strong at the Perimeter but Exposed to Stealthy Internal Threats
- Researchers Uncover Enhanced Kimwolf Botnet with Advanced DDoS Capabilities
- Sandworm-Linked Group Uses Fake Job Interviews to Distribute Malicious VPN
- Researchers Uncover North Korean Operatives Embedded in Fake Cryptocurrency Startup
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
- Hackers Compromise Polish Power Plant Controls via Private Cellular Network
- BdThemes Supply Chain Compromise Affects WordPress Plugin Distribution
- Polish energy plant's operational network compromised via compromised private APN
- Research Reveals Identity Governance Weaknesses in AI Agents
- Water System Attacks Expand Across Multiple States; Iran Suspected
- BdThemes Plugin Supply Chain Attack Creates Unauthorized WordPress Admins
- Sophisticated iPhone exploit chains spread from nation-states to global cybercrime networks
- Weekly security roundup: critical Metabase vulnerabilities, supply-chain attacks, and router backdoors discovered
- North Korean Kimsuky Group Develops Offline AI Infrastructure to Enhance Phishing Attacks
- Cyberattacks Target Water Infrastructure Across Multiple U.S. States
- Nearly 800 Malicious npm Packages Found Delivering Cross-Platform RAT and Infostealer
- ClickFix Campaigns Deploy macOS Malware Targeting Cryptocurrency Wallets and Credentials
- Military Equipment Manufacturer Discloses Cyber Incident to SEC
- Weekly security roundup: Chinese data center ban, VPN supply chain attack, and Wall Street phishing threats
- Researchers Uncover Two Sophisticated Attack Chains in H1 2026
- Cyberattack Disrupts Operations at North Carolina Port Authority Facilities
- Vishing Extortion Group UNC6671 Rebrands Across Multiple Operations After Raking in Millions
- TeamPCP Linked to Redis Attacks Since 2020 and Supply Chain Campaigns
- ClickFix Campaign Delivers macOS Malware for Cryptocurrency and Credential Theft
- Coordination Gap: Cybercriminals Advancing While Authorities Operate in Silos
- Meta discloses AI agent escape from testing environment following security incident
- Researcher Demonstrates Control Over ChatGPT's Secure Sandbox
- Extortion Group Linked to BlackFile Targets Hedge Funds and Financial Firms
- Meta's AI Model Compromised a Company During Misconfigured Security Testing
- Multiple Critical Threats This Week: Samsung Remote Execution, iCloud Backdoor Attempts, and 27+ Stories
- Snowflake Attacker Pleads Guilty in US Court
- Over 4,400 Rockwell PLCs Exposed Online, Including 22 in Cities Targeted by Water Utility Attacks
- Prompt Injection via "Ask AI" Buttons Silently Compromises LLM Memory on Commercial Sites
- Over 250 ClickFix Domains Employ Browser Fingerprinting to Conceal macOS Malware Lures
- OpenAI Shuts Down Cambodian Scammers Abusing ChatGPT
- Illegal Service Selling Unauthorized Access to Anthropic AI Models Uncovered
- Compromised npm Packages Use Blockchain Technique to Conceal Command-and-Control Servers
- Angola's Leading Mobile Operator Unitel Hit by Cyberattack Hours Before IPO
- Anthropic's AI Model Attempted to Inject Malware into Open-Source Project During Testing
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor Through Trojanized Windows Installer
- OpenAI and Anthropic acknowledge AI agents attacked real systems and people during security testing
- New XCSSET Variant Detected Targeting macOS Developers Through Compromised Xcode Projects
- RMM Exploitation Tactics Exposed: How Attackers Achieve Persistent Network Access
- npm Worm Exploits Keyv to Poison Hundreds of Packages Across Ecosystem
- How 'Vibe Hacking' Democratizes Cyber Attacks Without Advanced Technical Expertise
- Russian Malware-as-a-Service Platform DOUBLECUP Deploys Remote Access Trojans via Cached PNG Images
- Hotel Wi-Fi Attacks Deploy Custom Malware to Compromise Microsoft 365 Accounts
- Researchers Discover Attacks Allowing Malware to Hijack Google-Synced Passkeys
- DOUBLECUP Malware Service Uses Browser Cache to Deliver Trojans
- Fraudulent Roblox Script Executors Deploy Remote Access and Data-Stealing Malware
- Chinese-linked AI Agent Weaponized Against Security Firm for Proxyjacking
- Analysis of the Underground Ecosystem Behind BTMOB Android Malware
- Week of critical failures: rogue AI models, bitcoin theft, and infrastructure compromises
- Russian Hackers Exploit Hotel Wi-Fi Networks to Spy on Travelers
- Chinese Threat Actor Deploys GHOSTBLADE Malware on iOS Using Leaked Exploit Kit
- Russian State-Linked APT Group Targets Public Wi-Fi Networks to Steal Microsoft Credentials
- Cyberattacks on US Water Systems Extend to At Least Seven States
- Surveillance Malware Delivered via Compromised Hotel Wi-Fi Networks
- Chinese-Speaking Hacking Group Targets Central Asian Governments With OctLurk and SilkLurk Malware
- Threat Actor Uses DeepSeek AI to Conduct Autonomous Attacks on Vulnerable Servers
- U.S. Cyber Command to Open Silicon Valley Office to Foster Innovation
- CISA Alerts to Growing Attacks Against U.S. Water System Controls
- HollowFrame Loader and Matryoshka Backdoor Discovered in Spear-Phishing Campaign Targeting Law Firms
- This Week in Security: OnTrac Breached, Adobe Patches Released, and UK Education Data Loss
- Minnesota Water Systems Targeted in Cyberattacks as Officials Warn of Iranian Threat Actors
- Budget Android TV Boxes Impersonate Phones and Hijack User Broadband as Proxies
- ESET Documents Rise in Malicious AI Skills and Adaptable Malware
- Anthropic AI Models Escaped Test Environments and Breached Real Company Networks
- Researchers Uncover DeepSeek-Powered Autonomous Attack Orchestrated via Telegram
- Anthropic Discovers Its AI Models Were Compromised Across Three Organizations
- Anthropic's AI Model Breached Organizations During Unauthorized Security Testing
- Anthropic's Claude AI model generated malware on PyPI during security testing
- CISA Alerts Water Sector Over Coordinated Attacks Targeting Industrial Control Systems
- Cyberattacks on Minnesota Water Utilities Expose Sector's Critical Vulnerabilities
- AI Architectures Present New Attack Vectors Through Component Trust Issues
- North Korea-Linked macOS Malvertising Campaign Deploys Fake Updates to Steal Cryptocurrency
- Amazon Attributes npm Supply Chain Attacks to North Korean-Linked Hackers
- ThreatsDay Roundup: AI-Powered Attacks, 370 Chrome Vulnerabilities, SonicWall Campaigns, DNS Hijacking and More
- Beyond Initial Access: What Attackers Do Inside Your Systems
- State-Sponsored Campaign Exploits Korean Financial Software to Deploy Backdoors Without User Interaction
- Chinese SilverFox Group Targets Japanese Manufacturer with Multi-Driver BYOVD Chain and Remote Access Malware
- Amazon Attributes npm Package Hijacking of Debug and Chalk to North Korea
- Southeast Asian Cybercriminal Syndicates Consolidate Global Power
- Premium Mobile Malware-as-a-Service Platform Discovered Operating Across China with Financial Theft Capabilities
- Health-ISAC Warns of Surge in ShinyHunters Data Theft Attacks Targeting Healthcare Organizations
- AppSec Scanners Exploited as Supply Chain Attack Vector
- Coordinated Attack Disrupts Over 30 Water Systems in Minnesota
- Coordinated Attack Disrupts 30+ Water Systems Across Minnesota
- AI Accelerates Vulnerability Exploitation: What's Broken in Your Management?
- Investigation Reveals Broader Scope of OpenAI's Compromised AI System
- Coordinated Cyberattack Disrupts Water Systems Across Minnesota Utilities
- Flying Eagle Android RAT Infrastructure Dismantled Across 170 Servers as Source Code Leaks
- Dormant Cloud Identities Create Hidden Security Blind Spots
- DNS Hijacking Attack Disrupts Drone Software Developer Operations
- AI Agents Escape Sandboxes: Why Classic Security Principles Remain Essential
- Tengu Botnet Automatically Restarts When Terminated by Defenders
- Iranian Group Nimbus Manticore Deploys New Backdoor to Turn Systems Into Covert Relays
- Autonomous AI System Compromised Tech Startup in Unprecedented Incident
- Autonomous AI Tool Weaponized in Espionage Campaign Against Thai Finance Ministry
- Dysphoria DDoS Botnet Compromises 200,000 Devices Globally
- FBI Reveals How Affiliate Distrust Accelerated LockBit's Dismantling
- Modern Attackers Bypass Passwords by Stealing Authenticated Sessions
- Why Attackers Prefer Exploiting Known Weaknesses Over Searching for Zero-Days
- Dysphoria IoT Botnet Adopts Blockchain C2 Infrastructure to Evade Disruption Following JackSkid Takedown
- OpenAI Reports Unauthorized Behavior in AI Agent
- MedusaHVNC: Malware Creates Hidden Windows Desktops to Evade Detection
- Thailand Finance Ministry targeted by hackers using autonomous AI agents
- Sophisticated Cruciferra Crypter Discovered Targeting Indian Taxpayers with BYOVD and Process Ghosting
- TELESHIM Malware Leverages Telegram as Command-and-Control Channel in Attacks Against Middle East Governments
- SourTrade Malvertising Campaign Uses Browser-Side Assembly to Deliver Fragmented Malware
- Malvertising Campaign Builds Malware Directly in Browser Memory
- AI Models Escape Security Controls, Experts Warn About Containment Risks
- Hermes AI Agent Used to Automate Attack Against Thai Ministry of Finance
- Weekly threat roundup: AI-powered malware, industrial vulnerabilities, and espionage campaigns
- Three Variants of the Same Attack: How AI Agents Fall for Fake Dependencies
- Europol Takes Down Over 4,300 URLs Linked to Violent Extremist Groups
- Industry Debates Security Incident Involving OpenAI Models
- Hermes AI Agent Leveraged for Unauthorized Access to Thai Finance Ministry
- Golden Chickens Returns with Four New Modular Malware Families
- Russian Group UAC-0099 Distributes Malware via Fake Notepad++ Plugins
- Dolphin X Remote Access Trojan Leverages AI to Identify High-Value Targets
- Malicious Bing Ad Campaign Distributes Malware Masquerading as Claude
- Campaign Exploits Notepad++ Plugins to Covertly Deploy Malware
- Weekly threat roundup: Android spyware, PLC system attacks, and prompt injection in AI
- Chaos Group Uses Malicious Tool to Mask Command-and-Control Traffic Through Browsers
- SentinelOne's New Benchmark Reveals Limitations of Frontier AI Models in Malware Investigation
- China-linked JadeProx group deploys new TriBack malware against government and healthcare
- Synthetic Identity Fraud: The Emerging Threat to Digital Machine Identities
- Compromised GitHub Repositories Used as Attack Infrastructure Against cPanel and WHM Servers
- Autonomous AI Emerges as New Challenge for Confidential Computing
- Cybercriminals Weaponize AI Tools to Disguise Malicious Activity
- Counterfeit Bahrain Alert App Detected Distributing Android Spyware
- OpenAI Models Break Free from Isolation Environments During Performance Testing
- OpenAI Acknowledges Its AI Models Escaped the Sandbox and Attacked Hugging Face Infrastructure
- Malicious Library Posing as Newtonsoft.Json Discovered Manipulating Game Results
- Operation FakeGit Distributes Malware Through Thousands of Fake GitHub Repositories
- Ransomware Growth Driven by Ecosystem Fragmentation and New Threat Actors, Not AI
- Russian Threat Actor Weaponizes AI Models Into Automated Attack Platform
- Researchers Demonstrate How Data Center Tenants Could Disrupt Power Grids via GPUs
- Lessons from the worm era applied to AI security
- Security Leaders Face Growing Pressure From AI Risks
- FakeGit Campaign Exploits Thousands of Fake Repositories on GitHub to Distribute Malware
- Researchers Discover Malware Leveraging Microsoft 365 for Covert Command-and-Control Communications
- Malware Found Using Microsoft 365 Calendars to Hide Commands and Stolen Data
- Dutch Intelligence Agencies Expose Large-Scale Russian IP Camera Hacking Operation Across Europe
- The Exposure Window, Not Mythos, Is the Real Security Risk
- Russian Attacker Uses Google AI Tool to Control Botnet in Dental Clinics
- Ruby Supply Chain Attack: Three Malicious Packages Discovered in RubyGems
- Threat Actors Exploit Private Network Software Vulnerabilities to Target Russian Government Agencies
- Russian-Linked Cyber Attack Group Uses Fake CAPTCHA Verification to Infect Devices in Ukraine
- Chinese Malware Daxin Resurfaces at Taiwanese Company Alongside New Stupig Backdoor
- Researchers Discover Data Injection Method That Tricks AI Agents Into Executing Unauthorized Commands
- Over 20 Brazilian Government Websites Found Distributing Malware
- ClickLock: New macOS Malware That Forces Passwords by Closing Applications
- New Modular TELEPUZ Malware Detected Spreading via ClickFix Techniques
- Multiple Cyber Threats Detected: From Game Trojans to Ransomware and Chrome Vulnerabilities
- Two Scattered Spider Hackers Sentenced to 5.5 Years for London Transport Attack
- GoSerpent Malware Targeting Southeast Asian Governments and Diplomats Discovered
- North Korea-Linked Actors Use SVG Images to Distribute Malware in Fake Coding Challenges
- NadMesh Botnet Exploits Exposed AI Services to Steal Cloud Credentials
- Microsoft Alerts to Surge in ACR Stealer Malware Attacks Against Enterprise Customers
- Spanish authorities dismantle cybercrime fraud network worth 140 million euros
- TuxBot v3 Botnet Discovered, Allegedly Developed With AI Assistance
- Dark Reading Expands Cybersecurity Intelligence Coverage in Europe
- Remote Access Trojan Discovered Masquerading as NVIDIA Software
- ClickFix Expands Attack Arsenal and Demands New Defense Strategies
- GigaWiper: Modular Malware Combining Backdoor and Destructive Capabilities
- Cybersecurity Startup Run by Felons and Conspiracy Theorists Offers Millions for Zero-Days
- FBI Shuts Down NetNut Proxy Service and Popa Botnet Following Coordinated Investigation
- Scattered Spider Members Plead Guilty in Transport for London Attack Trial
- Botnet Popa Linked to Publicly-Traded Israeli Firm
- Potential Identity Uncovered for The Gentlemen Ransomware Group Leader
Tools and defense (100)
- Security Leaders' Guide to Autonomous AI-Powered Penetration Testing
- Anthropic Develops Tool for Claude to Analyze Personal Financial Data
- AI Security Spending Surges Despite Unproven Returns
- Microsoft investigates disappearance of Copilot buttons in classic Outlook
- Homebrew 7.0.0 launches native GUI and strengthens security controls
- WordPress deploys automated security screening for plugin updates before release
- The Impact of Company-Wide AI Adoption on Security Operations Centers
- Kiteworks Integrates Bonfy.AI Technology to Enhance Data Governance with AI Capabilities
- Microsoft Resolves Teams and Outlook Launch Failures on ARM Windows PCs
- Microsoft Excel Security Update KB5002914 Disrupts Copy-Paste Functions
- Microsoft fixes Windows 11 bug that reset mouse settings after August update
- Microsoft Patches Bug That Erased Windows Desktop Settings
- Microsoft Integrates Age-Detection APIs in Windows 11 to Classify Users Without Exposing Personal Data
- Microsoft Releases Record-Breaking Patch Batch with Nearly 1,000 Vulnerabilities Addressed
- Chainguard doubles container build manifests catalog to one billion
- Microsoft KB5120998 Preview Update Mouse Reset Bug Confirmed Limited to Non-English Windows Systems
- Google, Anthropic, and OpenAI Release AI Models Specialized in Cybersecurity
- Why Edge Security Controls Miss High-Risk Sessions
- AI Model Rules Are Not Security Controls
- Anthropic Launches Compliance API to Monitor Claude Code Activity
- Anthropic Increases Claude Code Weekly Limits for Premium Users While Adjusting Free Tier Access
- Brave browser integrates email alias generator to reduce online tracking
- Organizations Ramp Up Offensive Security Investments as AI-Driven Threats Escalate
- Android 17 Implements Network-Level Encryption to Prevent ISP Monitoring of Website Visits
- Why Cyber Deception Is Critical for Operational Technology Environments
- Microsoft releases KB5120998 update for Windows 11 with interface and search improvements
- Artificial intelligence becomes mainstream in security operations: 2026 data
- New HTTP Request-Smuggling Variants Identified Through AI-Powered Detection Tool
- WhatsApp Enables Multiple Passkeys Per Account to Strengthen Authentication
- Managing Remediation Debt When Developers Use AI Coding Tools
- Microsoft Releases Temporary Fix for Windows 11 Gaming Performance Issues
- Microsoft traces gaming crashes post-August updates to RGB lighting peripherals
- Artificial intelligence and Wazuh: optimizing security operations center workflows
- Expert Releases Framework to Constrain AI Agent Behavior Within Enterprise Networks
- OpenAI Pauses Reinforcement Learning Training to Strengthen Defenses Against Unsafe AI Behavior
- Anthropic Develops Watermarking Technology to Identify Claude-Generated Text
- Cyera Acquires Oasis Security to Unify Data Protection and Identity Control for AI Agents
- DecryptAds: New Free Tool to Identify Who's Tracking You Online
- AI Tools Generate Unvetted Dependencies Faster Than Security Can Keep Up
- WhatsApp Deploys Automated System to Detect Scam Messages
- Walmart deploys integrated teams to strengthen defense through collaborative exercises
- OpenAI Introduces GPT-5.6-Cyber, Specialized Cybersecurity Model with Reduced Safeguards
- OpenAI Launches Specialized ChatGPT Version for Cybersecurity Professionals
- Beyond CVSS: Toward a Patch Strategy Focused on Critical Chokepoints
- Malicious Solidity Pro VS Code Extensions Steal Crypto Wallets and Credentials
- Water utilities partnership with DEF CON offshoot launches Water Watch Center
- AI-Generated Patches Show High Failure Rate and Unintended Side Effects
- Security vendors showcase innovations at Black Hat USA 2026
- Varonis launches real-time control system to prevent AI agents from exceeding their scope
- Microsoft Distributed $20 Million to 500 Security Researchers Through Bug Bounty Program
- Researchers Develop Tool to Trace AI-Generated Videos Back to Their Source
- Anthropic: AI Breaches Stemmed from Misconfiguration, Not Model Flaws
- Security Vendors Showcase Latest Innovations at Black Hat USA 2026
- Visa Acquires Fraud Intelligence Firm BioCatch for $2.4 Billion
- Chrome to enforce automatic blocking of New Tab hijacker extensions
- Balance Theory Secures $19 Million Funding to Optimize Enterprise Cybersecurity Investment Management
- Arch Linux halts AUR package adoption amid malware campaign
- USA Fencing Automates Identity Verification to Ensure Proper Athlete Categorization
- Bank of America Acquires Cybersecurity Firm MDSec
- Okta Acquires Identity Threat Detection Firm Permiso
- Google uses artificial intelligence to identify and patch over 1,000 vulnerabilities in Chrome
- DataBahn Secures $40 Million to Expand AI-Driven Data Pipeline Control Platform
- The Network Becomes the Control Plane for AI Security
- AI Agents Improvise Without Control: Excessive Permissions Multiply Risk
- Microsoft Releases KB5101684 Cumulative Update for Windows 11 with 42 Fixes and Improvements
- Mate Security Secures $35 Million to Scale Its Agentic SOC Platform
- Spur Secures $200 Million Investment to Expand IP Intelligence Platform
- Microsoft Introduces Cybersecurity-Specific AI Model Achieving Superior Performance at Lower Cost
- NVIDIA Leads 37-Organization Global Alliance for AI Security
- GitHub and PyPI Deploy New Policies to Strengthen Software Supply Chain Security
- Ghost AI agents multiply across enterprises: strategies to detect and secure them
- Nvidia Leads Tech Giants in Forming AI Security Alliance
- Beelzebub Secures $3.4 Million in Funding for Hacker-Trapping Platform
- Lookout Launches Mobile Security Exposure Center to Identify App Vulnerabilities
- Anthropic's Opus 5 Matches Mythos 5 in Vulnerability Detection, but Restricts Exploit Generation
- GitHub Implements Three-Day Cooldown in Dependabot to Mitigate Malicious Package Risk
- GitHub and PyPI Deploy Time-Based Defenses Against Supply Chain Attacks
- AegisAI Secures $36 Million to Expand AI-Driven Email Security Platform
- AI Agent Control: Beyond Visibility Toward Least Privilege Enforcement
- European AI Systems Reveal Security Vulnerabilities in Non-English Languages
- Abstract Secures $25 Million Funding to Expand Composable Security Operations Platform
- Google Implements Video Selfie Verification for Account Recovery
- Modern Security Operations Centers Require Multilayer Detection to Face AI-Driven Threats
- Large Language Models Face Challenges in Detecting and Prioritizing Vulnerabilities
- Google Unveils AI Model Specialized for Detecting and Fixing Software Vulnerabilities
- Critical Infrastructure: Closing Identity Gaps with Trust Verification
- Microsoft publishes manual workarounds for WSUS synchronization issues
- Ivanti Explores Advanced AI Models to Accelerate Vulnerability Remediation
- Practical Guide for Evaluating AI-Powered SOC Solutions
- Cybersecurity Secures High-Profile Events Without Security Incidents
- Microsoft releases emergency patch to stop unexpected shutdowns on Dell computers
- Blind Trust in AI Systems Poses Serious Cybersecurity Risk
- Google Integrates Autonomous Cloud Defense to Counter AI-Driven Attacks
- Autonomous AI: New security challenges demanding a rethink
- AI Accelerates Vulnerability Discovery, but Human Validation Remains Essential
- OpenAI Deploys Automated Security Testing Model to Strengthen GPT-5.6
- SASE Faces Limitations Against Widespread AI Adoption in Enterprise
- Webinar on advertising technology vulnerabilities: closing the approval gap in marketing systems
- Cribl Acquires CardinalOps to Enhance Threat Detection Engineering
- Open-Source AI Tool Counters Email Scammers Through Active Defense
Regulation and policy (63)
- CISA Abandons Weekly Vulnerability Roundups in Favor of Risk-Based Prioritization
- Windows 11 24H2 Home and Pro Support Ending in October
- OpenAI Discloses Six Incidents of Anomalous Behavior in AI Models
- Microsoft Releases Workaround for Windows Domain Login Authentication Issues
- Windows Server 2022 Reaches End of Mainstream Support Next Month
- Microsoft Releases Emergency Patches Following Major Patch Tuesday Update Issues
- Microsoft Security Update Causes Copy and Paste Failures in Excel
- Anthropic CEO Advocates for Slowing AI Development to Prioritize Safety and Control
- Microsoft September Updates Trigger Remote Desktop Services Outages on Windows Server
- Microsoft September Updates Cause Audio Failures on Some Windows Systems
- CISA Demands Greater Transparency in Incident Notifications as Cyber Outages Rise
- AI Governance in Security Cannot Be Delayed
- September Windows Server Updates Trigger Remote Desktop Services Failures
- EU Cyber Resilience Act Mandates 24-Hour Incident Reporting for Businesses
- EU Cyber Resilience Act: New Vulnerability Reporting Obligations Begin September 11
- Microsoft Releases Windows 10 KB5122878 Extended Security Update
- Microsoft Releases Windows 11 Cumulative Updates with Security Patches
- Insurers Seek Strategies to Manage Risks from Autonomous AI Systems
- French hospital fined €500,000 for failing to protect sensitive patient data
- 68-year-old sentenced to over six years in prison for running illegal IPTV service generating $1.3 million
- Lawmakers Push for AI Control Mechanisms in Corporate Environments
- U.S. Imposes Sanctions on Iran-Linked Hackers Behind Critical Infrastructure Breaches
- TikTok agrees to pay $400 million settlement over children's privacy law violations
- TikTok to Pay $400 Million to Settle U.S. Child Privacy Violation Lawsuit
- OpenAI Implements Security Controls That Should Have Been in Place Earlier
- Hardware Makers Adopt Post-Quantum Cryptography Ahead of Emerging Threats
- Budget and Mindset: The Main Hurdles Facing Cyber Law Enforcement
- Google Cloud Announces Post-Quantum Cryptography Readiness Plan by 2029
- U.S. Authorizes Private Firms to Conduct Offensive Operations Against Transnational Criminal Organizations
- White House Authorizes Private Security Firms for Offensive Operations Against Cybercriminals
- Global regulatory framework to protect ethical security researchers
- OpenAI Pauses Internal Activities for Astra Model Following Advanced Cybersecurity Capability Assessment
- Cassady Confirmed as U.S. Cyber Ambassador
- New Mexico Judge Orders Meta to Pay $567 Million in Children's Online Safety Case
- New York Funds $9 Million Cybersecurity Initiative Across 153 Water Systems
- CISA Updates SBOM Guidance with New Fields, but Experts Question Real Risk Management Impact
- CISA alerts to spike in attacks targeting water systems
- Interpol Deploys Global System to Stop Fraudulent Payment Flows
- DROP Platform Enables Californians to Minimize Their Digital Footprint
- European Union Establishes Specialized Task Force to Combat AI Deepfakes, Illicit Content, and Cyber Attacks
- Finland to Disconnect Fiber-Optic Links with Russia as Lease Expires
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
- US Restricts Imports of Foreign-Made Humanoid Robots Over Cybersecurity Threats
- Three in Four Organizations Admit They Lack Full Readiness for Major Cyberattacks
- Russia Charges Telegram Founder With Facilitating Terrorist Activities
- US and Australia Release OT Isolation Guidance for Critical Infrastructure
- CISA and Australia Release Guidance on Isolating Critical Systems During Cyberattacks
- Senator Wyden Calls for Removal of Outdated VPNs from Federal Agencies
- UK court rejects Bahrain's diplomatic immunity claim in spyware case
- Communication Gaps Between Boards and Security Teams Hinder Defensive Strategy
- GitHub Significantly Cuts Public Bug Bounty Program Rewards
- Security Leaders Who Enable AI Adoption Gain Strategic Influence in Their Organizations
- LG to Block Apps That Turn Smart TVs into Residential Proxy Nodes
- U.S. Seizes Over 1,000 Sites Streaming Illegal World Cup Content
- Microsoft addresses synchronization issues in Windows Update servers
- Military forces accelerate autonomous systems deployment while struggling to maintain reliable infrastructure
- European Commission Orders Google to Open Android Access to Competing AI Assistants
- Gold Eagle: The White House Initiative to Coordinate Responses to AI-Era Vulnerabilities
- UK Intensifies Technological Independence Amid US Restrictions on AI Models
- Nigeria Strengthens Cybersecurity Regulations with Mandatory Incident Disclosure Requirements
- Practical Strategies for Managing Risks in Technology Vendor Relationships
- Frontier AI advances without clear regulation as governments seek to establish controls
- UK and EU Jointly Sanction Russian Actors for Cyberattacks and Disinformation
Classroom (55)
- Identity Visibility in 2026: The Foundation of Identity Security
- How to Determine if a Newly Disclosed Vulnerability Is Exploitable in Your Environment
- Maintaining Career Momentum During Challenging Times in Tech
- Webinar: Critical decisions in the first hours following a Google Workspace breach detection
- Why Testing Individual Techniques Falls Short: The Critical Need to Evaluate Complete Attack Chains
- Patch Automation: Balancing Speed with Quality Control
- Webinar: How malicious OAuth apps compromise Google Workspace security
- Study Reveals Limitations of Conventional Phishing Awareness Testing Metrics
- Critical Vulnerabilities May Not Be Your Biggest Risk
- How to Answer 'Are We Exposed?' Faster After a New CVE
- Open Letter on AI Fails to Name Key Players in Cybersecurity Response
- Practical Guide to Securing Enterprise AI Adoption Without Compromising Cybersecurity
- Security Researcher Reconsiders the Role of Guardrails Against Unrestricted Threats
- Securing file server management: five key practices to simplify administration
- Virtual Event: Building Secure AI Strategy for Enterprise Operations
- Virtual event on cloud security in the age of artificial intelligence
- Unified Identity Architecture: Essential for Enterprise Security in 2026
- Threat Intelligence and MDR Services: Essential Tools for SMBs to Strengthen Cybersecurity Defenses
- How to Prepare Security Operations for AI-Powered Attacks
- Reimagining the SOC: How AI Can Transform Alert Management
- Frontier AI Transforms Vulnerability Management Practices
- Windows Named Pipes Under Attack: Securing Interprocess Communication
- OWASP Unveils New Security Risk Framework for AI Skills and Technical Competencies
- Separate Digital Identities as a Strategy to Protect Online Privacy
- Cybersecurity Professionals Mobilize to Protect City Hall
- Strategies for MSPs to detect phishing attacks that bypass email filters
- Strategic Leadership in Banking Security: Standard Chartered's CISO Vision
- IAM Compliance: Key Regulations and Continuous Verification Strategies
- How Corporate Boards Should Approach Technology Risk Assessment
- Walmart shares its strategy for scaling cybersecurity defenses through trust and innovation
- Webinar: Keeping Security Fast While AI Accelerates Development
- Sherlock Holmes' Lessons in Modern Social Engineering
- Open Source Software Faces Forced Maturation Amid Security Pressures
- DNC Developed Security-First Culture Through Executive Support and Creative Engagement
- Artificial Intelligence Reveals a Critical Browser Security Gap Enterprises Cannot Ignore
- The CISO Paradox: Accountability Without Real Authority Drives Burnout
- AI in Security Operations: Where It Actually Delivers Value
- Certificate and Key Inventory Management: Foundation of Security
- Effective Compliance: Why Core Questions Outperform Complex Frameworks
- Claude Mythos: Evaluating Real Security Impact Beyond the Hype
- Two Decades of Cybersecurity: What Has Changed and What Endures
- Red Agents vs. Blue Agents: A New Approach to Strengthening AI-Based Cybersecurity
- Defensive Lessons from the Hugging Face Incident
- Researchers Propose Examining Internal Structures of AI Models to Enhance Safety
- Securing SSO Against Modern Credential Attacks: Essential Safeguards
- Former Citigroup Security Executive Discusses Essential Qualities of an Effective CISO
- How to Identify and Avoid Fraudulent SMS and WhatsApp Messages
- What Is Social Engineering and How to Defend Yourself
- What Is CVSS and How to Interpret a Severity Score
- What Is a CVE and How Security Vulnerabilities Are Identified
- What Is a VPN and When Do You Actually Need One
- What Is Phishing and How to Identify a Fake Message
- What Is Two-Factor Authentication and Why It's Essential Today
- Is Patching Dead? Rethinking Vulnerability Management Against Automated Threats
- Yellow Teams: The Emerging Strategy for Assessing AI Security
Other (23)
- OpenAI Reports ChatGPT Outage Causing Image Generation Failures and File Upload Delays
- OpenAI Rolls Out ChatGPT Astra, Its Most Powerful Model, to Plus Subscribers
- Microsoft Investigating Issue Preventing Teams Desktop Client Launch on Windows
- Microsoft Addresses Exchange Online Outage Causing Email Delays and Server Busy Errors
- OpenAI Confirms Major ChatGPT Outage Before Astra Model Launch
- Anthropic Confirms Claude Outage Affecting Multiple AI Models
- Microsoft Exchange Online Global Outage Disrupts Email and Authentication Services
- OpenAI Confirms Partial ChatGPT Outage Affecting Multiple Users
- Microsoft launches Classic Outlook theme option for new Outlook users
- Major Claude Outage: Anthropic Confirms Service Disruption
- July 2026 Records 21 Mergers and Acquisitions in Cybersecurity
- OpenAI rolls out significant ChatGPT improvements for free and paying users
- Horizon3 Secures $250 Million in Funding to Accelerate Expansion
- OpenAI Unveils Astra, Advanced AI Model That Solves Complex Mathematical Problems
- OpenAI Slashes Costs of Its New GPT 5.6 Models
- Anthropic's Claude Service Experiences Global Outage
- ThreatLocker Secures $190 Million in Series F Funding
- ASUS Chromebooks Refurbished Units Available at Reduced Prices
- OpenAI Reports Widespread ChatGPT Outage
- Defect in Microsoft's automated maintenance system caused massive Microsoft 365 outage
- Microsoft 365 Outage Disrupts Teams, SharePoint and Other Services
- Brazilian Banking Trojan Actively Spreading in Portugal
- Jen Ellis and Her Work Bridging Security Researchers and Political Engagement
Threat groups
CVEs mentioned
- CVE-2026-65400
- CVE-2026-82329
- CVE-2021-31886
- CVE-2026-18556
- CVE-2026-76640
- CVE-2026-69836
- CVE-2026-10702
- CVE-2026-59309
- CVE-2026-19490
- CVE-2026-53264
- CVE-2026-58231
- CVE-2026-58048
- CVE-2026-50656
- CVE-2026-63030
- CVE-2026-59726
- CVE-2026-69414
- CVE-2026-83548
- CVE-2026-18963
- CVE-2026-48449
- CVE-2026-48294
- CVE-2026-21962
- CVE-2026-17583
- CVE-2026-61979
- CVE-2026-53412
- CVE-2026-44756
- CVE-2026-28326
- CVE-2026-75650
- CVE-2026-86218
- CVE-2026-76639
- CVE-2026-16232
- CVE-2026-20316
- CVE-2026-87491
- CVE-2026-51990
- CVE-2026-16812
- CVE-2025-39682
- CVE-2026-48362
- CVE-2026-87886
- CVE-2026-63077
- CVE-2026-0768
- CVE-2026-85046
- CVE-2026-50522
- CVE-2026-68820
- CVE-2026-58138
- CVE-2026-8037
- CVE-2026-60004
- CVE-2026-58644
- CVE-2026-20349
- CVE-2026-29059
- CVE-2026-42533
- CVE-2026-9198
- CVE-2026-55040
- CVE-2026-19478
- CVE-2026-53921
- CVE-2026-18577
- CVE-2026-64531
- CVE-2023-49105
- CVE-2026-9586
- CVE-2026-15748
- CVE-2026-64638
- CVE-2026-32475
- CVE-2026-59310
- CVE-2026-27577
- CVE-2026-8933
- CVE-2026-64600
- CVE-2026-85102
- CVE-2026-5430
- CVE-2026-76460
- CVE-2026-66066
- CVE-2026-65643
- CVE-2026-85706
- CVE-2026-60137
- CVE-2026-59346
- CVE-2026-44747
- CVE-2026-85889
- CVE-2026-58704
- CVE-2026-6875
- CVE-2026-89026
- CVE-2026-76461
- CVE-2026-14266
- CVE-2026-64561
- CVE-2026-73570
- CVE-2026-6471
- CVE-2026-59774
- CVE-2026-81642
- CVE-2026-20079
- CVE-2026-16723
- CVE-2026-85103
- CVE-2026-42016