CyberWireDaily.
LIVE · Thu Sep 17
Subscribe
AllBreachesMalwareRansomwareVulnerabilitiesRegulationEspionageToolsCloudMobileGeneralGuides
Archive
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
7h ago
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
7h ago
Threat Intelligence Alone Won't Close the Exploitation Gap
7h ago
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
7h ago
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
7h ago
Data Broker Radaris Loses Domains in Privacy Fight
7h ago
AI Security Spending Jumps as Fear Outpaces Proof of Value
7h ago
Fighting Your Dragons Through Tough Tech Times
7h ago
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Yesterday
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Yesterday
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Yesterday
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Yesterday
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Yesterday
BragJack Attack Can Turn a Browser's Agentic AI Against It
Yesterday
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Yesterday
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Yesterday
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Yesterday
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Yesterday
Cyber Op Targets South Korean Media & Automotive Sectors
Yesterday
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
Yesterday
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
Yesterday
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
2 days ago
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
2 days ago
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
2 days ago
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
2 days ago
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
2 days ago
VectraRAT Can Hack Windows Enterprises for $250 per Month
2 days ago
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
2 days ago
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
2 days ago
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
2 days ago
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
2 days ago
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
2 days ago
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
3 days ago
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
3 days ago
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
3 days ago
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
3 days ago
AI Changed the Exposure Problem. Validation Needs to Change With It.
3 days ago
Anthropic CEO: Time to Shift From Improving to Controlling AI
3 days ago
SpiderSilk Hunts External Threats With AI-Based Scanner
3 days ago
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
4 days ago
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
5 days ago
When the Whole Company Adopts AI: What It Does to Your SOC
5 days ago
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
5 days ago
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
5 days ago
AI Governance Can't Wait
5 days ago
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
5 days ago
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
5 days ago
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
5 days ago
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
5 days ago
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
5 days ago
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
5 days ago
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
5 days ago
Why AI Is So Good at Scamming Humans
5 days ago
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
6 days ago
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
6 days ago
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
6 days ago
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
6 days ago
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
6 days ago
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
6 days ago
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
6 days ago
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
6 days ago
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
6 days ago
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
6 days ago
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
6 days ago
Indonesia Hit by Android Banking App-Cloning Campaign
6 days ago
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
6 days ago
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Sep 10, 2026
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Sep 10, 2026
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Sep 10, 2026
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Sep 10, 2026
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Sep 10, 2026
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
Sep 10, 2026
EU Cyber Resilience Act to Enforce New Reporting Requirements
Sep 10, 2026
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
Sep 10, 2026
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Sep 10, 2026
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Sep 10, 2026
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
Sep 10, 2026
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Sep 10, 2026
Mythos Vulnerability Firehose Hits a Human Bottleneck
Sep 10, 2026
US Government Accuses Chinese AI Firms of Distilling Frontier Models
Sep 10, 2026
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
Sep 10, 2026
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Sep 9, 2026
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
Sep 9, 2026
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
Sep 9, 2026
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Sep 9, 2026
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
Sep 9, 2026
Identity-Based AI Attack Threatens Security of Enterprise Data
Sep 9, 2026
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Sep 9, 2026
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Sep 9, 2026
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
Sep 9, 2026
What It Took to Reach 1 Billion Build Manifests
Sep 9, 2026
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
Sep 9, 2026
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Sep 9, 2026
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Sep 9, 2026
Microsoft Plugs Nearly 1,000 Security Holes
Sep 9, 2026
Patch Tuesday Sets Another Record With 974 CVEs
Sep 9, 2026
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Sep 9, 2026
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
Sep 8, 2026
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Sep 8, 2026
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Sep 8, 2026
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Sep 8, 2026
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Sep 8, 2026
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Sep 8, 2026
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
Sep 8, 2026
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Sep 8, 2026
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Sep 7, 2026
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Sep 7, 2026
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
Sep 7, 2026
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Sep 7, 2026
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
Sep 7, 2026
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Sep 6, 2026
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Sep 6, 2026
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Sep 6, 2026
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Sep 5, 2026
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Sep 5, 2026
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Sep 5, 2026
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
Sep 5, 2026
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Sep 5, 2026
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Sep 5, 2026
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
Sep 5, 2026
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Sep 5, 2026
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Sep 5, 2026
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
Sep 5, 2026
Companies Have 6 Months to Prepare for Automated Attacks
Sep 5, 2026
Insurers Search for Answers to Rein in Rogue AI
Sep 5, 2026
What the AI Warning Letter Completely Missed
Sep 5, 2026
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Sep 4, 2026
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
Sep 4, 2026
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
Sep 4, 2026
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Sep 4, 2026
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Sep 4, 2026
Companies Have Six Months to Prepare for Automated Attacks
Sep 4, 2026
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
Sep 4, 2026
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
Sep 4, 2026
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
Sep 4, 2026
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
Sep 4, 2026
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
Sep 4, 2026
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Sep 4, 2026
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Sep 4, 2026
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
Sep 4, 2026
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Sep 3, 2026
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Sep 3, 2026
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Sep 3, 2026
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
Sep 3, 2026
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Sep 3, 2026
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
Sep 3, 2026
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Sep 3, 2026
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Sep 3, 2026
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Sep 3, 2026
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Sep 3, 2026
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Sep 3, 2026
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
Sep 3, 2026
AI’s Vulnerability Surge May Be More Manageable Than First Feared
Sep 3, 2026
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
Sep 3, 2026
AI Gives Cybercriminals a Dangerous Time Advantage
Sep 3, 2026
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Sep 2, 2026
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Sep 2, 2026
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Sep 2, 2026
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Sep 2, 2026
How to Secure Enterprise AI: From Adoption to Incident Readiness
Sep 2, 2026
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
Sep 2, 2026
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
Sep 2, 2026
AI Model Evaluator METR Hit by Credential Theft, Probing
Sep 2, 2026
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Sep 2, 2026
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Sep 2, 2026
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Sep 2, 2026
FBI Probes Service Selling 153M+ Drivers Licenses
Sep 2, 2026
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Sep 2, 2026
Attackers Pounce on Critical Artifactory Flaw Following Disclosure
Sep 2, 2026
Stronger Security Drives Ransomware Groups to Recruit From Within
Sep 2, 2026
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
Sep 2, 2026
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Sep 1, 2026
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Sep 1, 2026
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
Sep 1, 2026
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
Sep 1, 2026
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Sep 1, 2026
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
Sep 1, 2026
The Guardrails Debate: Security Researcher Changes His Mind
Sep 1, 2026
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Sep 1, 2026
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
Sep 1, 2026
Anthropic Users Hit by Infostealer Attacks, Session Thefts
Sep 1, 2026
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
Sep 1, 2026
AI Model Rules Are Not Security Controls
Sep 1, 2026
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Aug 31, 2026
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Aug 31, 2026
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Aug 31, 2026
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Aug 31, 2026
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Aug 31, 2026
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Aug 30, 2026
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Aug 30, 2026
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Aug 30, 2026
Hugging Face Breach Raises Big Questions About AI Security Controls
Aug 30, 2026
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
Aug 30, 2026
Ransomware Attacks are on the Rise
Aug 30, 2026
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Aug 30, 2026
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Aug 29, 2026
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Aug 29, 2026
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
Aug 29, 2026
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Aug 29, 2026
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Aug 29, 2026
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Aug 29, 2026
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
Aug 29, 2026
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
Aug 29, 2026
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Aug 29, 2026
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Aug 29, 2026
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Aug 29, 2026
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Aug 29, 2026
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Aug 29, 2026
Hundreds of OpenAI Agents Invaded Hugging Face Servers
Aug 29, 2026
Offensive Security Investments Surge as AI Threats Increase
Aug 29, 2026
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Aug 29, 2026
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Aug 28, 2026
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Aug 28, 2026
Key Reasons Why Identity Fabric Matters in 2026
Aug 28, 2026
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
Aug 28, 2026
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Aug 28, 2026
You Need Cyber Deception for OT
Aug 28, 2026
Defining an AI Kill Switch Is Hard, but Necessary
Aug 28, 2026
The Vulnpocalypse Is Repricing the Bug Bounty Economy
Aug 28, 2026
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
Aug 28, 2026
What the Data Says About AI in Security Operations in 2026
Aug 28, 2026
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Aug 28, 2026
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Aug 28, 2026
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Aug 28, 2026
Chinese Routers Sold Worldwide Contain Backdoors
Aug 28, 2026
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
Aug 28, 2026
CISOs Break Their Silence in 'Declassified' Docuseries
Aug 28, 2026
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Aug 27, 2026
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Aug 27, 2026
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Aug 27, 2026
Learn How to Build Security Operations Ready for AI-Powered Attacks
Aug 27, 2026
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Aug 27, 2026
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Aug 27, 2026
Russian Hackers Phish EU Officials Over Messaging Apps
Aug 27, 2026
'HTTP Terminator' Hunts for Novel Desync Attacks
Aug 27, 2026
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
Aug 27, 2026
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Aug 27, 2026
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
Aug 27, 2026
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
Aug 27, 2026
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
Aug 27, 2026
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Aug 27, 2026
Red Flags That Expose Fake North Korean IT Workers
Aug 27, 2026
Android Malware Hijacks Update System for Car Head Units
Aug 27, 2026
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Aug 26, 2026
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
Aug 26, 2026
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
Aug 26, 2026
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
Aug 26, 2026
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
Aug 26, 2026
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Aug 26, 2026
Interpol's Jackal IV Disrupts West African Crime Infrastructure
Aug 26, 2026
Nigeria Looks to Sovereign Cloud for Cyber, National Security
Aug 26, 2026
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
Aug 26, 2026
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Aug 26, 2026
Frontier AI: Vulnerability Management's Systemic Revolution
Aug 26, 2026
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Aug 26, 2026
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Aug 26, 2026
Hidden Prompts Trick AI Into False Email Summaries
Aug 26, 2026
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Aug 26, 2026
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
Aug 26, 2026
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Aug 25, 2026
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Aug 25, 2026
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Aug 25, 2026
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Aug 25, 2026
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Aug 25, 2026
Is Cyber Facing an Affordability Crisis?
Aug 25, 2026
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
Aug 25, 2026
'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture
Aug 25, 2026
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Aug 25, 2026
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Aug 25, 2026
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Aug 25, 2026
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
Aug 25, 2026
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Aug 25, 2026
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
Aug 25, 2026
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
Aug 25, 2026
China-Linked Hacker Shows AI Capabilities in APAC Attack
Aug 25, 2026
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Aug 24, 2026
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Aug 24, 2026
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
Aug 24, 2026
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Aug 24, 2026
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Aug 24, 2026
Tricky 'SynkLoader' Multitool May Herald Ransomware
Aug 24, 2026
ToxicPanda Banking Trojan Matures Into Enterprise Threat
Aug 24, 2026
The Vulnerability Gap: Why Discovery Is Outrunning Repair
Aug 24, 2026
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Aug 24, 2026
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Aug 24, 2026
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
Aug 24, 2026
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Aug 24, 2026
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Aug 24, 2026
'Grandoreiro' Malware Resurfaces With Mexico Campaign
Aug 24, 2026
Agentic AI Presents New Insider Threat Model for Orgs
Aug 24, 2026
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
Aug 24, 2026
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Aug 23, 2026
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Aug 23, 2026
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Aug 23, 2026
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Aug 23, 2026
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Aug 23, 2026
How an Emerging Industrial Protocol Family Could Put OT at Risk
Aug 23, 2026
Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near
Aug 23, 2026
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
Aug 23, 2026
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Aug 23, 2026
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Aug 23, 2026
Why "Shady AI" is Security's Next Big Governance Problem
Aug 23, 2026
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Aug 23, 2026
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
Aug 23, 2026
What We Missed: Delta Flight Disrupted With Wi-Fi Hack
Aug 23, 2026
N-able Bug Exposes Password Vault Master Keys
Aug 23, 2026
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Aug 23, 2026
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
Aug 22, 2026
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Aug 22, 2026
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Aug 22, 2026
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Aug 22, 2026
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Aug 22, 2026
Calling on Cyber Pros to Help Defend City Hall
Aug 22, 2026
OpenAI Adds Controls That Should've Been There Already
Aug 22, 2026
New CUSTODY Framework Constrains AI Agents Inside the Network
Aug 22, 2026
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Aug 22, 2026
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Aug 22, 2026
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Aug 22, 2026
Wazuh and AI For Enhanced SOC Workflows
Aug 22, 2026
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Aug 22, 2026
Microsoft Patches a Record 570 Security Flaws
Aug 22, 2026
Lessons Learned from CISA’s Recent GitHub Leak
Aug 22, 2026
OWASP Flags Top AI Skill Risks in New Security Blueprint
Aug 22, 2026
Opinion: Why We Keep Buying Vulnerable Gadgets (And Why Companies Love It)
Aug 21, 2026
Opinion: Stop Patching Like It's 2015. The Real Vulnerability Crisis Is Our Broken Supply Chain.
Aug 21, 2026
Opinion: The Regulatory Compliance Industry Just Became Its Own Security Risk
Aug 21, 2026
Opinion: Stop Worrying About "Blending In" and Start Asking What Malware Invisibility Actually Costs
Aug 21, 2026
Opinion: Cloud Migration's Heresy—Sometimes Slow Is the Only Speed That Makes Sense
Aug 21, 2026
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Aug 21, 2026
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Aug 21, 2026
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
Aug 21, 2026
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
Aug 21, 2026
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Aug 21, 2026
Opinion: Stop Chasing the Malware Variant, Start Watching Who's Renting the Infrastructure
Aug 20, 2026
Opinion: The 'Ransomware is Unstoppable' Narrative Serves the Attackers
Aug 20, 2026
Opinion: Stop Counting Breach Records. Start Counting Breach Velocity.
Aug 20, 2026
Opinion: We're Selling 'AI Agent Control' Like It's a Feature, Not a Band-Aid for a Broken System
Aug 20, 2026
Opinion: We've Accepted Breaches as Inevitable. That Comfort Is Dangerous.
Aug 20, 2026
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Aug 20, 2026
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
Aug 20, 2026
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
Aug 20, 2026
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Aug 20, 2026
Phishing 3.0: The Fight Moves to Agent Versus Agent
Aug 20, 2026
Read This Before You Buy That TV Streaming Stick
Aug 20, 2026
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
Aug 20, 2026
Opinion: The Cloud Migration Gold Rush Is Moving Too Fast for Its Own Good
Aug 19, 2026
Opinion: We're Celebrating Security Tools That Let Companies Avoid Accountability
Aug 19, 2026
Opinion: The Real Threat Isn't the Next Zero-Day, It's How We Keep Making the Same Mistakes
Aug 19, 2026
Opinion: We're Paying Vendors to Hide Their Vulnerability Problems, Not Fix Them
Aug 19, 2026
Opinion: The Cloud's Credential Problem Is About to Get Much Worse
Aug 19, 2026
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Aug 19, 2026
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Aug 19, 2026
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
Aug 19, 2026
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Aug 19, 2026
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Aug 19, 2026
Opinion: The 'Zero-Trust Cloud' Movement Is Being Sold as Inevitable. It Deserves More Skepticism Than It's Getting.
Aug 18, 2026
Opinion: We're Still Treating Cloud Security Like a Perimeter Problem. That's the Real Vulnerability.
Aug 18, 2026
Opinion: The 'Cloud-Native Security' Fantasy Is Being Sold as Inevitable. We Should Reject It.
Aug 18, 2026
Opinion: The Mobile Security Theater Must End - Simplicity Wins Over Layers
Aug 18, 2026
Opinion: The AI Security Arms Race Is Moving Too Fast to Win
Aug 18, 2026
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Aug 18, 2026
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Aug 18, 2026
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Aug 18, 2026
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Aug 18, 2026
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Aug 18, 2026
Video Call Exploit Chains Two Flaws in Unisoc Modems
Aug 18, 2026
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
Aug 18, 2026
Opinion: The Cloud Migration Gold Rush Is Moving Too Fast. Maybe That's the Problem.
Aug 17, 2026
Opinion: The 'Digital Minimalism' Movement Is Being Sold as Liberation. It's Often Just Privilege.
Aug 17, 2026
Opinion: The Cloud Migration Panic Is Pushing Companies Toward Disaster
Aug 17, 2026
Opinion: The Water Utility Breach Isn't a Vulnerability Problem. It's an Accountability Problem.
Aug 17, 2026
Opinion: Why the Rush to 'Immediate Breach Disclosure' May Be Making Ransomware Worse
Aug 17, 2026
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Aug 17, 2026
Interpol Leverages Global System to Curtail Fraud Payments
Aug 17, 2026
DROP Platform Lets Californians Reduce Digital Footprint
Aug 17, 2026
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
Aug 17, 2026
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
Aug 17, 2026
Opinion: Stop Building Ransomware Theater. Start Actually Defending Networks.
Aug 16, 2026
Opinion: The SBOM Mandate Needs a Pause, Not a Push
Aug 16, 2026
Opinion: The Purple Team Tool Craze Signals a Reckoning We're Not Ready For
Aug 16, 2026
Opinion: We're Paying CISOs to Fail, Then Blaming Them for Being Exhausted
Aug 16, 2026
Opinion: The Mobile Supply Chain Reckoning We Keep Postponing
Aug 16, 2026
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
Aug 16, 2026
Is There Really a Fix for CISO Fatigue?
Aug 16, 2026
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
Aug 16, 2026
The Morning After We Pull a Root of Trust, Nobody Owns It
Aug 16, 2026
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
Aug 16, 2026
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Aug 16, 2026
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Aug 16, 2026
New Tool Traces AI Videos Back to Their Source
Aug 16, 2026
Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues
Aug 16, 2026
Who’s Tracking You? Use This New Service to Find Out
Aug 15, 2026
CSS: The Hidden Threat Lurking in Your Inbox
Aug 15, 2026
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Aug 15, 2026
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
Aug 15, 2026
Angola's Largest Telco Breached Hours Before IPO
Aug 15, 2026
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Aug 15, 2026
Mission-Driven Security: Inside a Global Bank's Defense
Aug 15, 2026
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
Aug 15, 2026
AI Sends Global Crime Syndicates Into Fraud Nirvana
Aug 15, 2026
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Aug 15, 2026
No Perfect Fix for AI Browser Prompt Injection Flaws
Aug 15, 2026
Fake Reservation Links Prey on Weary Travelers
Aug 15, 2026
iPhone Users Urged to Update to Patch 2 Zero-Days
Aug 15, 2026
Google Patches Chrome’s Fifth Zero-Day of the Year
Aug 15, 2026
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
Aug 14, 2026
What Boards Need to Know About Tech Risk
Aug 14, 2026
Cyera's Oasis Security Buy Is All About AI Agent Control
Aug 14, 2026
Researcher Claims Control of ChatGPT Secure Sandbox
Aug 14, 2026
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Aug 14, 2026
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Aug 14, 2026
Twitter Whistleblower Complaint: The TL;DR Version
Aug 14, 2026
Firewall Bug Under Active Attack Triggers CISA Warning
Aug 14, 2026
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Aug 14, 2026
Global Threat Campaign Hits Critical VMware vCenter Flaw
Aug 14, 2026
Walmart Leaders Transform Security Operations Without Going Bananas
Aug 14, 2026
Outdated Cybercrime Laws Put Security Researchers at Risk
Aug 14, 2026
Sherlock Holmes Was the 'OG' Social Engineer
Aug 14, 2026
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
Aug 14, 2026
Student Loan Breach Exposes 2.5M Records
Aug 14, 2026
Watering Hole Attacks Push ScanBox Keylogger
Aug 14, 2026
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Aug 13, 2026
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Aug 13, 2026
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Aug 13, 2026
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
Aug 13, 2026
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Aug 13, 2026
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Aug 13, 2026
Belgium's eID Authentication Opens Citizen Accounts to RCE
Aug 13, 2026
Walmart Takes a 'Trusted Agent' Approach to Purple Teaming
Aug 13, 2026
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Aug 13, 2026
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
Aug 13, 2026
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
Aug 13, 2026
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
Aug 13, 2026
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Aug 13, 2026
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
Aug 13, 2026
Walmart's "Trusted Agent" Approach to Purple Teaming
Aug 13, 2026
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Aug 13, 2026
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
Aug 12, 2026
Enterprise Defenses Recovered at the Edge and Collapsed Inside
Aug 12, 2026
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Aug 12, 2026
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Aug 12, 2026
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Aug 12, 2026
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Aug 12, 2026
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Aug 12, 2026
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Aug 12, 2026
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Aug 12, 2026
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Aug 12, 2026
Microsoft Plugs Nearly 400 Security Holes
Aug 12, 2026
Microsoft's Patch Tuesday Deluge Continues With August Updates
Aug 12, 2026
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Aug 12, 2026
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
Aug 11, 2026
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Aug 11, 2026
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Aug 11, 2026
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Aug 11, 2026
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Aug 11, 2026
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
Aug 11, 2026
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Aug 11, 2026
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Aug 11, 2026
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
Aug 11, 2026
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
Aug 11, 2026
Multistate Water System Attacks Widen, Iran Suspected
Aug 11, 2026
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
Aug 11, 2026
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Aug 10, 2026
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Aug 10, 2026
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Aug 10, 2026
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
Aug 10, 2026
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Aug 10, 2026
Coruna, DarkSword iOS Exploits Proliferate Globally
Aug 10, 2026
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Aug 10, 2026
LG to Ban Residential Proxies from Smart TV Apps
Aug 10, 2026
Who Runs the Ransomware Group ‘The Gentlemen?’
Aug 10, 2026
AI-Generated Patches Fail Half the Time
Aug 10, 2026
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
Aug 10, 2026
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Aug 9, 2026
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Aug 9, 2026
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
Aug 9, 2026
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Aug 9, 2026
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Aug 9, 2026
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Aug 9, 2026
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Aug 9, 2026
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Aug 9, 2026
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
Aug 9, 2026
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Aug 9, 2026
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Aug 8, 2026
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Aug 8, 2026
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Aug 8, 2026
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Aug 8, 2026
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Aug 8, 2026
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Aug 8, 2026
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Aug 8, 2026
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Aug 8, 2026
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Aug 8, 2026
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Aug 8, 2026
FBI Seizes NetNut Proxy Platform, Popa Botnet
Aug 8, 2026
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
Aug 8, 2026
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Aug 7, 2026
Growing Up The Hard Way
Aug 7, 2026
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
Aug 7, 2026
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Aug 7, 2026
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Aug 7, 2026
Canadian Man Pleads Guilty in Snowflake Extortions
Aug 7, 2026
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Aug 7, 2026
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Aug 7, 2026
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
Aug 7, 2026
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Aug 7, 2026
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Aug 7, 2026
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
Aug 6, 2026
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Aug 6, 2026
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Aug 6, 2026
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Aug 6, 2026
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Aug 6, 2026
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
Aug 6, 2026
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
Aug 6, 2026
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Aug 6, 2026
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
Aug 6, 2026
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
Aug 6, 2026
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Aug 5, 2026
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Aug 5, 2026
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Aug 5, 2026
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Aug 5, 2026
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Aug 5, 2026
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Aug 5, 2026
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Aug 5, 2026
© 2026 CyberWireDaily — Security Breaches, Threats & Cyber News — About — Guides — Contact — Editorial Policy — Corrections — Terms — Privacy — Privacy
Daily briefing

Get CyberWireDaily in your inbox.

Stay ahead of the latest stories with a quick daily digest. No noise, just the important updates.

Close this and we won’t show it again today.