Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synce…
Search for certain combinations of “TikTok” and adult content, and sooner or later you’ll land on a page promising exactly what you searched for: an …
Threat Summary Threat actors are actively exploiting two high-severity authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N…
California has launched the Delete Request and Opt‐out Platform (DROP), a state‐run portal that lets residents send deletion and opt‐out requests to …
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the rep…
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 mill…
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately …
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [.…
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remo…
CloudSEK researchers uncovered an exposed server linked to a Russian-speaking initial access broker, revealing months of operations targeting interne…
A cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to …
Now AI is making fake vulnerabilities and polluting the ecosystem. A batch of critical- and high-rated SQLite CVEs that appeared in the NVD with CISA…
In January 2026, the Silent Push research team mapped a cluster of adversary infrastructure staged for takeover of single sign-on accounts across mor…
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applic…
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises…
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anythin…
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile A…
LiteLLM is a popular AI gateway. It provides a unified interface to LLMs and simplifies governance. It also has access to the backend LLM provider ke…
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR…
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cybera…
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other crimina…
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 …
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of r…
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) soluti…
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
Mac users have historically trusted their operating system to keep them safe. That peace of mind mostly comes from Apple’s strict control over its ec…
A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems…
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states…
The bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen …
Introduction Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are fr…
The biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud…
The N‐central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‐able Patches Vulnerabi…
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices…
The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which…
The physical security firm says its alarm monitoring and system functionality have not been affected. The post Brinks Home Discloses Data Breach as H…
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web…
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
The UK government's corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of do…
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkS…
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilit…
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single fac…
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State…
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the…
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US W…
OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to…
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered befo…
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrik…
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed thr…
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily …