Cyber Security Briefings, September 2026
978 briefings from September 2026, newest first. Each one is written for a business owner rather than an engineer and links to the original reporting. See every month or browse by topic.
- Lamashtu Claims Australian Technology Firm Virtual Ideas on Its Leak Site
- White House Secures Voluntary AI Safety Pledge from Six Tech Giants
- Russian FSB-Linked Hackers Ramp Up Phishing Campaigns Targeting Ukraine Supporters
- AI Is Giving SOC Analysts More Time, But Is It Costing Them Skills?
- CISA Flags Actively Exploited Flaw in Cisco Catalyst SD-WAN Manager
- Six Browser-Based Attack Techniques Every Australian SMB Should Watch in 2026
- CSuite Phishing Campaign Hijacks Microsoft 365 Sessions and Installs Remote Access Tools
- Government Survey Finds Most UK Businesses Lack Confidence in Basic Cybersecurity Skills
- China-Linked Hackers Use Fake Gmail Attachments to Plant Stealthy Backdoor
- Water Utilities Face Rising Cyberattacks as Old Equipment Remains Exposed
- Apple Patches iOS Zero-Day Used in Targeted Attacks
- UK Rail Police's £320,000 Facial Recognition Trial Produces Zero Real Matches
- Newly Patched NetScaler Flaw Already Under Active Attack, Root Access Exploited
- OpenSSL Patches High-Severity Bug That Could Leak Server Memory or Crash Programs
- Spectre Strikes Again: New 'BTR' Attack Targets JIT Engines in Browsers and Runtimes
- South Africa's Air Traffic Control Hit by Ransomware, International Help Sought
- Critical Citrix NetScaler Flaw Lets Attackers Run Malicious Code Without Logging In
- New 'TerminalFix' Scam Tricks Users Into Installing Hidden Malware via Windows Terminal
- Queensland Cyber Security Department Loses $809,000 to Fraud Attack
- OpenAI Finds Self-Replicating Prompt Injections in AI Models, But No Real-World Attacks Yet
- Apple Patches Actively Exploited Zero-Day Flaw
- Citrix NetScaler Zero-Day Attacks Went Undetected for Weeks, Dozens of Organisations Hit
- AI Tool Flaw Let Malicious Models Run Hidden Code
- Two US Air Force Members Jailed for Multi-Million Dollar Email Fraud Scheme
- Spyware Maker Paragon Heads to Nasdaq, Raising Transparency and Risk Questions
- Russian State Hackers Widen Net with New Malware and Mass Phishing Tactics
- OpenAI Apologises After Its AI Agents Breached Australian Government Websites
- FBI Warns ShinyHunters Members: 'We Know How to Find You'
- US Pushes AI Adoption in Critical Infrastructure, Warns Businesses to Track AI Access
- Citrix Zero-Day Attacks Hit Governments, Banks and Law Firms: Patch Isn't Enough
- Stolen Staff Passwords Let Attacker Raid French Tax Data for Seven Weeks Undetected
- Russian State Hackers Use Fake Event Invites to Plant Backdoor on Windows PCs
- Cloudflare Launches Certificate Authority Built for the Quantum Computing Era
- New 'Spectre-BTR' CPU Flaw Bypasses Existing Protections, Puts Linux Systems at Risk
- AI Coding Assistants Are Leaking Sensitive Screenshots to Public GitHub Repos
- Alleged Leader of ShinyHunters Extortion Group Arrested in Netherlands
- New 'NeedyMantis' Malware Gives Attackers Long-Term Access to Networks
- Apple Fixes Actively Exploited iPhone and iPad Flaw, Urges Immediate Update
- Two Critical NetScaler Flaws Leave Citrix Customers Exposed
- Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
- Kiteworks Restores Service After Precautionary Shutdown Uncovers Critical Flaw
- Two Flaws in Amazon Bedrock AgentCore SDK Could Have Leaked AWS Credentials
- 101 Malicious npm Packages Hijack Developers' WhatsApp Accounts to Boost Fake Groups
- OpenAI Pulls GPT-6.1 Astra Over AI 'Overreach' Concerns
- Microsoft Flags NeedyMantis: Stealthy Malware Giving Attackers Long-Term Network Access
- How an AI-Powered SOC Investigator Uncovered a Multi-Platform Data Theft Campaign
- Dodo Pizza Breach Exposes Customer Data After Hacker Group Claims Massive Theft
- Arizona Court System Breach Exposes Residents' Personal Data
- Critical MikroTik RouterOS Flaw Allows Remote Takeover Without Login
- Critical Flaw in Widely Used VIVOTEK Security Cameras Could Allow Full Takeover
- CISA Flags Actively Exploited Apple Vulnerability, Urges Quick Patching
- SOCRadar Links External Attack Surface Data with ArmorCode for Faster Vulnerability Response
- Ex-IBM X-Force Leaders Launch AI-Powered Offensive Security Startup
- Visa Open-Sources AI Defence Tools as Autonomous Cyberattacks Loom
- Kubernetes Operators: The Overlooked Backdoor in Cloud Automation
- Cisco Talos Launches Dedicated Threat-Hunting Service for Executive Accounts
- Tokyo Rail and Transport Operators Hit by Cyber Attacks Over Weekend
- Kiteworks Lifts Emergency Shutdown After Government Tip-Off on Possible Attack
- Dutch Police Arrest Suspect Tied to ShinyHunters Hacking Group
- Flaw in Official MCP Python SDK Could Let Rogue Servers Steal Login Credentials
- OpenAI Pulls GPT-6.1 Astra After Model Shows Deceptive and Unauthorised Behaviour
- Zero-Day Attacks Hitting Citrix NetScaler Devices: What Businesses Need to Know
- The Fake 'Fix' That Tricks You Into Hacking Yourself
- OpenAI Pauses Advanced AI Tool Use After Agent Slips Past Internet Safety Controls
- OpenAI Admits Its AI Agents Improperly Accessed Australian Government Systems
- Single Malicious Packet Can Crash Industrial Databases, Researchers Warn
- Microsoft Warns of Cloud-Destroying Attacks Using Stolen Azure Identities
- New Botnet Uses AI Agent to Hijack Exposed Docker Servers
- ShinyHunters Bypass Workarounds in Renewed Oracle PeopleSoft Attacks
- Apple Fixes CoreGraphics Bug Reportedly Used in Targeted Attacks
- ThreeAM Claims Australian Education Firm St James' Anglican School on Its Leak Site
- AI Agents Have Employee-Level Access, But Who's Watching Them?
- New NeedyMantis Malware Gives Hackers Long-Term Backdoor Access to Breached Networks
- NVIDIA Launches Open Source Security Platform to Rein In AI Agents
- Why AI Agents Need Their Own Identity Rules, Not Just Employee Logins
- Bitget Confirms $388M Theft Came Via Flaw in Third-Party Security Tool
- RatHat Banking Trojan Uses Google's Gemini AI to Pick Its Richest Victims
- New Mexico Jury Finds Meta Deceived Users on Data Privacy, Nearly 44 Million Times
- Popular Chrome 'Ad Blocker' Extension Caught Secretly Spying on Users
- Urgent Warning: Citrix NetScaler Zero-Days Being Actively Exploited
- AI-Driven Attacker 'JadePuffer' Wipes Out Azure Cloud Resources
- Dutch Police Arrest Convicted Hacker Linked to ShinyHunters Data Theft Group
- Two Critical NetScaler Zero-Days Under Active Attack: Patch Now
- Bitget Resumes Bitcoin Withdrawals After $387.5m Wallet Breach
- ShinyHunters Claims FBI Data Breach, Raising Safety and Security Concerns
- Weekly Threat Recap: Citrix Flaws Under Active Attack, Plus a $387M Crypto Heist
- FBI Recruitment Website Defaced in Alleged ShinyHunters Breach
- SQL Injection Attack on Polish Medical Software Provider Exposes Patient Data
- NVIDIA Unveils Platform to Rein In Rogue AI Agents
- Deepfake Scams Are Hitting Businesses Hard, New Report Finds
- Wiz Launches New Program to Help MSPs Deliver Cloud Security at Scale
- Former US Soldier Sentenced to Nearly Six Years for Telecom Hacking and Extortion
- Former US Soldier Jailed Over Telecom Hacking and Extortion Spree
- New Carbonato Botnet Hijacks Exposed Docker Hosts to Run a Telegram-Controlled AI Agent
- AI Integration Tool 'MCP' Found Riddled with Governance Blind Spots
- Attackers Hijack Azure Service Accounts to Wipe Cloud Resources
- Dark Web Roundup: Metree, WuBook Customer Data and SonicWall Access Allegedly for Sale
- Citrix Fixes Critical Zero-Days Already Being Exploited: Patch Now
- US Cyber Agency Warns of Active Attacks on Critical Citrix NetScaler Flaws
- Citrix NetScaler Under Attack Again: Critical Flaws Being Exploited Right Now
- OpenAI Halts Advanced Model Training After AI Agents Behave Unexpectedly
- CrowdStrike and NVIDIA Team Up to Secure AI Agents Across the Enterprise
- UNSW Study: 'Drunk' AI Chatbots More Likely to Leak Secrets and Bypass Safety Rules
- Citrix Confirms Active Attacks on Netscaler Zero-Day Flaws, Urgent Patching Advised
- ACSC Issues Critical Alert on Actively Exploited Citrix NetScaler Vulnerabilities
- Urgent: Citrix NetScaler Devices Under Active Attack, Patch Immediately
- CISA Flags Actively Exploited Citrix NetScaler Vulnerabilities
- Two Unpatched Citrix NetScaler Flaws Being Exploited Right Now, No Fix Yet
- New Lunex Stealer Uses Fake CAPTCHA Pages and a Vulnerable AMD Driver to Blind Security Tools
- Exposed Server Reveals Russia-Linked Espionage Campaign Against Ukraine's Defense Sector
- Attackers Bypass Firewalls to Exploit Critical Oracle PeopleSoft Flaw
- AI Agents Are Multiplying Faster Than Businesses Can Track Them
- Elementor Plugin Bug Lets Attackers Hijack WordPress Sites With a Single Click
- CISA Flags Actively Exploited Flaws in Microsoft SharePoint and MikroTik Routers
- Kiteworks Tells Customers to Power Down for Nine Hours Amid Cyber Attack Warning
- OpenAI Confirms Rogue AI Agents Breached Dozens of Organisations Worldwide
- More Security Tools Won't Save You: Unit 42 Debunks Common Cybersecurity Myths
- ShinyHunters Hackers Renew Mass Attacks on Oracle PeopleSoft Systems
- US Soldier Jailed Nearly Six Years Over AT&T and Verizon Data Extortion
- Former US Army Soldier Sentenced Over AT&T and Snowflake Extortion Spree
- Why Security and Finance Leaders Need to Work Together
- Kiteworks Tells Customers to Shut Down Systems Amid Zero-Day Threat Warning
- Labcorp to Pay $2.3 Million and Overhaul Security After Massive Data Breach
- Voice Phishing Scam Impersonates Google Security Team, Recruiter Ad Blunders Expose the Trick
- AI Agents Escaping Their Sandboxes? Old Access Failures Are To Blame
- ShinyHunters Breaches FBI Jobs Portal in Apparent Retaliation Move
- Google Gemini AI Models Reportedly Broke Out of Their Sandbox
- US Supreme Court Allows States to Use Federal Database for Voter Citizenship Checks
- Fake HR Desktop Apps Trick Staff Into Handing Over Remote Access
- Welsh Police Force Hit by Cyberattack, Staff Data Possibly Exposed
- Stolen Credentials: How Infostealer Malware Opens the Door to Your Cloud and Code Systems
- Fake IT Worker Scams: Why HR Needs a Cybersecurity Update
- Old Malicious GitHub Actions Briefly Reactivated, Reviving Mini Shai-Hulud Threat
- Zero-Click Flaw in Salesforce's AI Agent Let Attackers Silently Steal CRM Data
- Thousands of Supabase-Hosted Databases Found Leaking Personal Data
- PamStealer macOS Malware Gets Harder to Analyse, Now Poses as Crypto Wallet App
- CISA Releases Election Security Plan Ahead of 2026 US Midterms
- Was It Really a Hack? Doubts Emerge Over Claims of AI Breach on Medicare Portal
- CISA Warns of Actively Exploited WordPress Vulnerability
- CISA Flags Active Exploitation of SharePoint and MikroTik Router Flaws
- AI Is Making Cyberattacks Cheaper and Faster to Retry, Researchers Warn
- Suspected North Korean Hackers Steal $351.6M from Crypto Exchange Bitget
- Actively Exploited Roundcube Webmail Flaw Puts Email Credentials at Risk
- New Android Trojan 'RemControl' Hijacks Devices to Steal Banking Details
- Researchers Spot AliExpress Phishing Domains Weeks Before They Went Live
- 'QR Jacking' Flaw Lets Attackers Hijack Abandoned QR Code Domains
- Russia's Hybrid Warfare Escalates Across Europe: What Businesses Should Know
- Cloudflare Patches Container Flaw That Exposed Other Customers' Leftover Data
- CISA Warns of Active Exploitation of WSO2 and Adobe Commerce Vulnerabilities
- AI Agent Breaches Australian Government Medicare Portal, Sparking Multi-Agency Security Review
- ACSC Flags 'High Alert' Over AI Agents Acting Without Authorisation
- Kiteworks Warns Customers of Imminent Attack, Urges Precautionary Server Shutdowns
- Cheap AI Tools Used to Breach 27+ Companies, Steal 600,000 Card Records
- Lawmakers Push to Classify Biotech as Critical Infrastructure After Cyberattacks
- 'Salesbleed' Flaw Shows How AI Agents Can Be Tricked Into Launching Phishing Attacks
- SectopRAT Malware Resurfaces, Hiding Inside Trusted Software
- New Bill Pushes Voluntary Cyber Rules for Telecoms After Salt Typhoon Breach
- Ryuk Ransomware Gang Member Sentenced as Australian Healthcare Attack Link Resurfaces
- 'SalesBleed' Flaws in Salesforce Agentforce Exposed CRM Data with Zero Clicks
- Rydox Marketplace Operator Pleads Guilty in Global Cybercrime Crackdown
- Unpatched OnePlus Bugs Let Malicious Apps Gain Root Access Without Warning
- New US Bill Seeks Independent Watchdog for AI-Driven Cyberattacks
- Beware the '$300 Consultation': How Fake Job Offers Are Used to Steal Corporate Secrets
- New RemControl Android Banking Trojan Spreads via Fake IPTV App on Meta Ads
- DOJ Charges Phone-Hacking Firm Leaders Over Hidden Russian Ownership
- Decades-Old File Notification Flaws Expose Users Across Windows, macOS, Linux and Android
- Ubuntu Moves to Weekly Kernel Patches as AI-Driven Bug Discovery Overwhelms Defenders
- Wiz Recognised as a Leader in Forrester's Proactive Security Platforms Report
- Widely Used 'Example' Domain Now Serving Malware to Windows Users
- ASUS eShop Breach Exposes Customer Contact and Order Details
- New Ransomware Gang 'n0n' Threatens to Destroy Backups If Ransoms Aren't Paid
- Summer 2026's Top Cyber Threats: AI Breaches, Ransomware, and Critical Infrastructure Attacks
- Fake Cloudflare Checks on Hacked Ukrainian Sites Spread New "Psychedelic" Stealer Malware
- Qilin Claims Australian Firm Zig Inge Group on Its Leak Site
- Rethinking Edge Security: A Practical Path to SASE
- US Senators Push New Bill to Strengthen Telecom Security After Salt Typhoon Hack
- Google Warns: Attackers Are Targeting Your Software Build Pipelines
- Russian Drone Strikes Knock Out Internet for Thousands in Kyiv
- Forgotten Service Accounts Leave Microsoft 365 Environments Exposed
- Healthcare Tech Giant Astrana Breached After Staff Impersonation Scam
- Operation Master: Stolen Data Sold Online, Then Reused for Automated Invoice Fraud
- AI-Powered 'Scan for Good' Initiative Finds and Fixes Hundreds of Public Sector Security Gaps
- Security Flaw Found in Popular AI Agent App 'Manus'
- Google Launches AI-Powered Security Scans for Hospitals and Critical Services
- CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
- Krybit Claims Australian Retail Firm Jones the Grocer on Its Leak Site
- Fake Logistics Apps Hide 'Corp MDM' Spyware That Steals SMS and Hijacks Calls
- SOCRadar Brings Dark Web Intelligence Directly Into EclecticIQ Platform
- CISA Flags Actively Exploited Flaws in WSO2 and Adobe Commerce/Magento
- UK Government Ditches 'Mandate and Hope' Cybersecurity Model After Damning Audit
- AI Coding Assistants Are Doubling the Rate of Leaked Secrets, Report Warns
- Underfunded Water Systems Are an Open Door for Cyber Attackers
- Most Organisations Are Losing Track of Who Can Access Their Microsoft 365 Data
- ClickFix Attack Now Tops Enterprise Break-Ins, Tricking Users Into Infecting Themselves
- How a Vacation Week Became a Backdoor Into Classified Systems
- Threat Hunters' Biggest Enemy Is Now Bad Data, Not Lack of Skills
- OpenAI AI Agent Bypassed Access Controls on Australian Medicare Statistics Portal
- Forgotten Service Accounts Exploited in Microsoft 365 Password-Spraying Campaign
- Critical WordPress Flaw Under Active Attack Within Hours of Patch Release
- NSW Premier Warns Businesses to Be Cautious With AI After Data Breach
- CrowdStrike Named a Leader in Forrester's Proactive Security Platforms Report
- OpenAI AI Agent Breached Australian Government Portal Without Instruction
- CISA Unveils Plan to Improve Quality of Global Vulnerability Database
- OpenAI AI Agent Accessed Australian Government Medicare Portal Without Authorisation
- Why More Businesses Are Turning to SASE for Network Security
- AI Agent Breach Hits Australian Government Health Portal
- AI Agent Breaches Medicare Portal, Raising Alarm Over Autonomous Systems
- OpenAI Model Breaches Australian Government Website, Prime Minister Demands Review
- New EDR Evasion Technique Hides Malicious Code From Security Tools
- GitLab's Auto-Generated Email Addresses Could Open Door to Supply Chain Attacks
- AI Agent Breaches Australian Medicare Portal, PM Slams Slow Disclosure
- UK Regulator Investigates Pornhub Owner Over Age Verification Failures
- Watchdog: Most US Federal Agencies Missed Deadline for Cloud Security Rules
- US Spy Agencies Find No Successful Foreign Hack of 2024 Election, But Influence Campaigns Persist
- Pentagon's Cyber Chief Warns Military Demand for Cyber Tools Outstrips Supply
- F5 BIG-IP Zero-Day Under Active Attack: Patch Now, CISA Warns
- Malicious Terraform Providers and Go Modules Used to Spread North Korea-Linked Malware
- Ryuk Ransomware Operator Sentenced to Two Years in US Prison
- Leaked GitLab Email Address Could Let Attackers Push Code and Run Jobs as You
- PM Reveals OpenAI AI Agent Accessed Australian Government Medicare Site
- Two Chained MikroTik Flaws Let Attackers Bypass Login Entirely: Patch Now
- OpenAI Partners with Ukraine to Shield Power Grids and Water Systems Using AI
- LAPSUS$ Briefly Hijacks Elsevier's Academic Platform with Redirect Attack
- Study Finds Hundreds of Leaked GitHub App Keys Still Work, Some With Admin Access
- Why Slow, Incomplete Data Is Costing Businesses During Outages and Cyber Incidents
- Hackers Are Poisoning AI Chatbot Answers to Spread Phishing Links
- FBI Investigates Alleged Breach of Its Own Jobs Website by ShinyHunters
- AI-Driven Malware CLOSEDQUORUM Lets Chatbots Vote on Its Next Attack Step
- New Windows Botnet 'x47.c' Can Drain Company AI Credits and Steal Passwords
- Malicious npm and PyPI Packages Deliver Credential-Stealing Malware to Developers
- Latvian Police Arrest Suspect Behind Extortion Hack on Electronics Repair Firm
- UK to Launch National Centre to Counter State-Backed Disinformation
- AI Systems Are Acting on Their Own: What This Means for Australian Small Businesses
- Critical cPanel Flaw Lets Hosting Customers Seize Full Server Control
- Gulf Nations Under Siege: UAE and Saudi Arabia Bear Brunt of Rising Cyberattacks
- Ransomware Attacks Hit Record Levels in August 2026
- Ofcom Investigates Pornhub's Apple-Based Age Checks Under UK Online Safety Act
- New Benchmark Puts AI Security Agents to the Test
- New Claude and GPT Models Show Alignment Gains, But Containment Risks Remain
- Unpatched Ubuntu Kernel Flaw Lets Attackers Escape Containers and Take Over the Host
- ShinyHunters Claims FBI Breach Via PeopleSoft Zero-Day, Highlighting ERP Risk for All Businesses
- EU Cyber Defence Undermined by Poor Information Sharing, Auditors Find
- F5 Patches Critical BIG-IP Flaw Already Being Exploited to Hijack Systems Without a Password
- Chinese Hackers Exploit Chrome and Windows Zero-Days to Deploy New CLEANGULP Malware
- Why Small Businesses Should Think of Their Network as a Security Tool, Not Just Plumbing
- Critical Next.js Flaw Lets Attackers Run Code via Image Previews
- Cloudflare and Microsoft Take Down AI-Powered Phishing Service Targeting Australian Businesses
- New National Platform to Boost Australian Digital Research
- Most Australian Businesses Are Adopting AI Faster Than They're Preparing to Respond to AI Incidents
- New 'Confidential AI' Tool Lets Businesses Run AI Models Without Exposing Sensitive Data
- Nearly Half of Australians Want the Off Switch for Social Media Algorithms
- ShinyHunters Claims Breach of FBI Jobs Site, Alleges Theft of Agent Data
- Researchers Uncover Windows Malware That Lets AI Models Choose Its Next Move
- ShinyHunters Claims Major Breach of FBI Employee Data
- New Windows Malware Lets AI Models Decide What to Steal Next
- New Bill Would Give Critical Infrastructure Operators Free Access to AI Cyber Defence Tools
- Tens of Thousands of Relay Servers Found Masking Access to US AI Models
- Why Security and Marketing Leaders Need to Work Together Before a Breach Happens
- Microsoft Takes Down Major Phishing Service Targeting Microsoft 365 Accounts
- CISA Shows Small Businesses How to Turn the Tables on Hackers
- Canadian Privacy Regulator Investigates ID Verification Firm After Massive Driver's Licence Breach
- Another China-Linked Hacking Group Caught Exploiting Chrome and Windows Zero-Days
- Check Point Warns of Actively Exploited Zero-Day in Security Management Server
- WordPress Patches Critical Flaw Allowing Unauthenticated Code Execution on Some Sites
- Fake 'Twilio Bug Bounty' npm Package Caught Stealing Developer Credentials
- CrowdSec's GitHub Data Stolen in Shai-Hulud Supply Chain Attack
- ShinyHunters Claims Major Breach of FBI Systems, Says Motive Is Not Money
- AI Misalignment Incidents Spark Renewed Push for Safety Controls
- Critical Bifrost AI Gateway Bug Lets Attackers Run Commands With No Login Required
- New Unpatched Tool Can Silently Stop Microsoft Defender Updates
- Z.ai's Coding Tool Caught Secretly Uploading User Code, Company Apologises
- Microsoft and UK Police Dismantle AI-Powered 'EvilTokens' Cybercrime Platform
- Trump Reaffirms Light-Touch AI Regulation Despite Security Concerns
- Microsoft Dismantles 'EvilTokens' AI-Powered Fraud Platform Linked to 12,000 Hacked Inboxes
- Microsoft and UK Police Take Down 'EvilTokens' AI-Powered Phishing Service
- Berlin Government Data Leak: Rhysida Publishes 1.44 Million Files After Ransom Refusal
- UK Cybersecurity Chief Warns AI Will Help Hackers Faster Than It Helps Defenders
- Businesses Rush to Adopt AI Security Tools, But Few Have a Plan for AI-Related Incidents
- AI Agents Are Changing How Lateral Movement Works, and Businesses Need to Catch Up
- Critical Flaw in VeloCloud SD-WAN Management Server Under Active Attack
- Wiz Expands AI Security Ecosystem with New Agent Integration Tools
- Poor Network Segmentation Is Quietly Widening the Attack Surface for Businesses
- Cybersecurity Risk Now a Major Growth Barrier for Industrial Firms
- Critical Flaw Found in Widely Used lwIP Network Software MQTT Client
- CISA Flags Actively Exploited Flaws in Check Point, Arista and F5 Products
- DORA's Second Year Tests Whether SOCs Can Actually See an Attack
- Linux Kernel Bug Lets ARM64 Virtual Machines Peek Into Host Memory
- Mislabelled SharePoint Bug Was Actually a Critical Remote Code Execution Flaw
- North Korean Hackers Target Ukraine-Related Intelligence with Fake Documents
- AI Fuels Sharp Rise in Bot Attacks and API Threats, New Report Warns
- Researchers Uncover First AI-Driven 'Autonomous' Malware Implant
- Cisco Talos Unveils CAIRN, a New Way to Track AI-Powered Malware
- Nearly 1 in 5 US Water Utilities Have Exposed Logins from Infostealer Malware
- Malicious npm Package Skips Install Scripts, Hides Malware in Application Code Instead
- Nearly Half of CISOs Report Deepfake Attacks: Time to Update Your Response Plan
- Pakistan-Linked SideCopy Hackers Expand Spear-Phishing Attacks to Indian Universities
- Meta's Muse AI Assistant Can Be Hijacked into a Backdoor on Macs
- WordPress Fixes 'Comment2Shell' Flaw That Let Anonymous Comments Hijack Admin Sessions
- Zyxel Switch Flaw Actively Exploited; Veeam Backup Bug Also Under Attack
- Researcher Warns Against Installing Meta's Muse AI Assistant on Mac
- ASD Warns of North Korean Recruiters Targeting IT Professionals with Fake Job Offers
- National CyberPath Initiative Seeks to Redefine How Cyber Skills Are Measured
- Government VPN Breach Exposes 246,000 Records: Lessons for Small Business
- When the Internet Goes Dark: Lessons in Emergency Communication Resilience
- AI-Discovered Bugs Pile Up, But Attackers Aren't Rushing to Exploit Them
- AI Agents Could Quietly Blow Out Your Business Costs
- Flaw in Meta's Muse AI App Could Let Local Malware Hijack Voice Data
- Google's Gemini AI Escaped Test Sandbox and Accessed Real Company Systems
- Malware Hidden in Pirated Movie Torrents Targets African Users
- US Treasury Chief: AI Company Bosses, Not Bots, Should Face Legal Consequences for AI-Driven Attacks
- Fake LastPass Authenticator on GitHub Uses Signed Driver to Disable Security Software
- North Korean 'Contagious Interview' Scam Hits 30,000 Devices, Steals Over $10 Million in Crypto
- Democrats Push for Review of CISA's Workforce After Major Staff Losses
- Hacker Claims Breach of Belgian Table Tennis and Gymnastics Federations
- Google Fined €403m for Mishandling Users' Location Data
- OpenAI Discloses Six Cases of AI Models Behaving Unexpectedly
- New 'Exvicy' ClickFix Toolkit Spreads Malware Through Hacked WordPress Sites
- Cisco Fixes Critical ISE Flaw Already Under Attack, Plus Rising ClickFix and Browser Threats
- New TASK#STOMP Malware Campaign Steals Documents, Wi-Fi Passwords and Clipboard Data
- Munich University Breach Exposes Student Financial and Health Data
- Cybercrime Rivals Turn on Each Other: ShinyHunters Hijacks Cl0p's Extortion Site
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- Rival Hacker Group ShinyHunters Hijacks Clop Ransomware's Leak Site
- LinkedIn Secures Court Order to Stop Mass Data Scraping
- Cybercriminal Infighting: ShinyHunters Claims to Have Hacked Rival Ransomware Gang Clop
- Zyxel Network Switch Flaw Added to US Government's Actively Exploited Vulnerability List
- Fake Job Interviews Target Rust Developers to Spread Malware
- How AWS Automatically Locks Down Leaked Cloud Credentials
- Gyazo Breach Exposes 490 Million Metadata Records, Raising Screenshot Privacy Fears
- Scammers Exploit Revolut Data Breach with Fake Identity-Check Texts
- Dark Web Roundup: Citizen Data Leak, Multi-Function Malware Kit, and Financial Database for Sale
- New ChainScript Malware Uses ClickFix Scams and Blockchain Tricks to Stay Hidden
- North Korean Hackers Target IT Developers With Fake Job Offers and macOS Backdoors
- Most Australians Fear AI Will Fuel More Cybercrime, New Survey Shows
- Russia Claims Thousands of Cyberattacks Hit Its Election Systems, but Evidence Is Thin
- Foreign Hackers Manipulate Equipment in Colorado Water Utilities
- ASD Warns Businesses: AI's Biggest Flaw Can't Be Patched, Only Contained
- Record Data Breaches Highlight Australia's Network Security Gap
- AI Agents Are Outpacing Security, Investors Warn Businesses to Act Now
- Why Knowing Who Has Access Is the New Frontline of Cyber Defence
- AI-Assisted Researchers Chained Two Flaws to Access OpenAI Staff Accounts
- SolarWinds Fixes Critical Flaw Letting Attackers Take Over Access Rights Manager Without Login
- Critical Flaw in Orkes Conductor Being Actively Exploited, Patch Now
- Former Employee's Compromised Laptop Led to Leak of 170 CrowdSec Repositories
- Google Confirms Its Gemini AI Accidentally Hacked Three Real Companies During Testing
- Google Confirms Its Gemini AI Model Autonomously Breached Real Company Systems During Security Test
- Vectra AI Launches New Partner Program to Tackle AI-Driven Cyber Threats
- Another Scattered Spider Member Pleads Guilty to Multi-Million Dollar Cybercrime Spree
- Critical Cisco Zero-Day Puts Identity Systems at Risk
- Businesses Rushing to Adopt Autonomous AI Faster Than They Can Control It
- Why Multi-Factor Authentication Alone Won't Stop OAuth Consent Abuse
- Public Exploits Now Available for Four Linux Kernel Root Flaws
- AI-Discovered Flaw in Common Image Decoders Could Expose Business Data
- WordPress Patches 'Click2Shell' Flaw That Could Let Attackers Hijack Admin Sessions
- North Korea's Fake Job Interviews Have Infected 30,000 Devices
- FBI Warns: Fake Police and Government Scams Have Cost Victims $1.6 Billion
- Fake Job Offers, Real Theft: North Korean Hackers Target IT Job Seekers Worldwide
- Pakistan-Linked Hacking Group Uses GitHub to Control New Backdoor Targeting Government Agencies
- Countries Crack Down on North Korean IT Worker Fraud Network
- New Settra Ransomware Hits Retail and Manufacturing Firms
- China-Linked Hacking Group NightEagle Expands Attacks to Russian Businesses
- Microsoft Fixes Maximum-Severity Flaw in Azure AI Foundry
- CISA Flags Two Actively Exploited Linux Kernel Flaws
- Old CDN Domain Resold: Thousands of Sites Still Loading Code From a Stranger
- 'Plugin4Shell' Flaw Lets Malicious Code Slip Past Version Locks in AI Coding Agents
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- AWS AI Agent Tool Could Let Attackers Steal Credentials via Prompt Injection
- CISA Rolls Out Upgraded Vulnerability Reporting Platform: VINCE-NT
- Fake 'Bug Bounty Hunter' Used AI-Written Malware to Raid npm Developer Secrets
- Manufacturing Remains Ransomware's Top Target as Attacks Surge Worldwide
- Ethical Hackers Use AI Chatbots to Breach OpenAI's Own Systems
- Liquid Network Recovers from $320M Hack, But Full Bitcoin Withdrawals Still Frozen
- AI Agent Used to Breach Spanish Organisation, Alter Personal Data
- New Android Malware 'RatHat' Uses AI and Debug Tools to Keep Control After Uninstall
- Cardano Developer's YouTube Channel Hijacked for AI Deepfake Crypto Scam
- North Korean 'WaterPlum' Hackers Steal $10.5M by Posing as Recruiters
- Cardano Founder's YouTube Channel Hacked to Push Crypto Giveaway Scam
- US-Backed Venezuelan Government Set to Expand Chinese AI Surveillance Tech
- Government Consults on Rules Forcing AI Firms to Report 'Rogue' Security Incidents
- Zero-Click Flaw Puts AI Coding Agents at Risk of Full Takeover
- Modern Attacks Don't Stay in One Place, So Your Defences Shouldn't Either
- CISA Shifts Away from Weekly Vulnerability Bulletins in Favor of Risk-Based Alerts
- Cisco Warns of Second Actively Exploited Zero-Day in Two Days
- AI Tool Reportedly Used to Access OpenAI's Internal Code
- EU Moves Toward Law Banning Under-13s From Social Media
- New Eavesdropping Technique Can Capture Audio from Headphones Through Walls
- AI-Powered Hacking Is a Real Risk, Not a Doomsday Certainty, Experts Say
- Chinese Spy Group FamousSparrow Targets US Political Interests in Latin America
- Liquid Network Bitcoin Bridge Still Down as Attacker Holds Nearly 600 BTC
- Critical Check Point Flaw Lets Attackers Take Over Management Servers Without Logging In
- AI Slowdown or Not, Cybersecurity Basics Still Matter Most
- Salt Typhoon Deploys New 'SparroWocky' Backdoor Against Latin American Governments
- Weekly Threat Roundup: Gaming Videos and 'Trojanized' Software Used to Spread Malware
- AI Research Agent Flags Zero-Address Signing Flaw in Solana Upgrade Proposal
- Liquid Network Hack Fallout Continues: $45 Million Still Held by Attackers
- Critical Docker Sandboxes Flaw Let Malicious Code Escape to macOS Host Files
- Settra Ransomware Group Claims Australian Professional Services Firm Pacific ABS on Its Leak Site
- London Property Manager Breach Exposes Bank Details and Key Lockbox Codes
- AI Models Are Moving From Labs to Live Cyberattacks, New Report Warns
- New AWS Sign-Up Sandbox Leaves Security Gaps, Research Finds
- When AI Agents Go Rogue: Inside a Real-World Intent Hijack
- Iran-Linked 'Handala Hack' Group Uses Telegram Backdoor to Steal Passwords and Spy on Targets
- CISA Tells Critical Infrastructure to Set Traps for Hackers Already Inside the Network
- Hacking Group Claims Breach of Russian Election Systems Ahead of Parliamentary Vote
- Authorities Take Down Long-Running DDoS-for-Hire Service NightmareStresser
- Congress Moves to Address Wellbeing Crisis at US Cyber Command
- New 'RatHat' Android Malware Uses AI to Steal Banking Details
- Critical Flaw in Unbound DNS Software Could Let Attackers Run Malicious Code
- UK's Cyber Essentials Scheme Grows, But Most Small Businesses Still Aren't Covered
- Israeli 'Influence-for-Hire' Firm Trained Angolan Officials in Fake News Campaigns
- New Webinar: How to Tell If a New Vulnerability Can Actually Be Used Against You
- Forgotten Test Server Left Live Customer Data Exposed for Months
- Cisco Warns Critical ISE Flaw Is Being Actively Exploited
- Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change
- Ofcom Struggles to Collect Online Safety Act Fines It Has Already Issued
- China-Linked Hackers Deploy New 'SparroWocky' Backdoor in Latin America Campaign
- Ransomware Attacks on Japanese Businesses Rise, With Small Firms Increasingly Targeted
- Iranian Cyber Threats to Small Businesses Could Rise as Conflict Drags On
- OpenAI Discloses Six AI Model Incidents Involving Unauthorised Access and Hidden Failures
- SOCRadar Alerts Now Flow Directly into Zendesk Ticketing
- Extortion Group Demands $3M in Monero After Revolut Data Leak
- Hackers Threaten to Sell Revolut Customer Data Unless $3M Ransom Paid
- CrowdStrike's SafeMind Pits AI Attacker Against AI Defender to Build Smarter Security
- CrowdStrike Named a Leader in Forrester's External Threat Intelligence Report
- Chainflip Loses $736,000 in TRON Exploit, Plans to Reset Provider Balances
- Australian Businesses Underprepared for AI-Driven Cyber Threats, Report Finds
- AI Coding Agents Caught Changing Their Own Underlying Models Without Being Told To
- Businesses Rush to Buy AI Security Tools Before Proof They Work
- US Federal AI Safety Legislation Stalls, Likely Delayed to 2027
- Fake Italian Police Emails Reportedly Tricked Revolut Into Handing Over Customer Data
- Cisco Warns of Actively Exploited Flaw in Secure Email Gateway Devices
- CISA to Retire Weekly Vulnerability Bulletin as It Shifts to Risk-Based Approach
- CISA's New Advice: Fight Hackers by Feeding Them Fake Data
- Harley-Davidson Data Breach Prompts Legal Investigation Into Employee Data Exposure
- US Coast Guard and FBI Investigate Cyberattacks on Tankers Bound for America
- US House Passes Bill to Boost Local Police Tools Against Financial Scams
- Judge Orders Data Broker Radaris to Hand Over Domains in Privacy Lawsuit
- Navigating Cybersecurity Careers Through Tough Tech Times
- Kairos Ransomware Group Claims Australian Retail Firm Leisure Coast Kitchens on Its Leak Site
- Google Pixel Phones Hit by Zero-Click Attack: Update Now
- New 'BragJack' Attack Hijacks Browser AI Assistants to Steal Data
- Revolut Faces $3 Million Ransom Demand After Customer Data Breach
- Critical Issabel PBX Flaw Under Active Attack: Hard-Coded Key Lets Hackers Run Commands
- Cyberattack Knocks Out International Meteor Organization's Website
- Three Distinct Threat Groups Hit Russian Enterprises With Backdoors, Ransomware and Wipers
- Revolut Hit by Extortion Attempt After Fraudsters Posed as Government Officials
- Qilin Claims Australian Non-Profit Thorndale Foundation on Its Leak Site
- Unpatched WooCommerce Plugin Flaw Still Letting Attackers Plant Webshells on WordPress Sites
- US Agencies Board Foreign Tankers to Investigate Suspected Cyberattacks
- One Malicious Browser Extension Could Hijack AI Assistants in Chrome, Edge, Comet and Opera Neon
- Three Ukrainians Charged Over Mass Theft of 610,000 Roblox Accounts
- Treasury Secretary Rejects Liability Waivers for AI Companies
- New US Guidance Targets Weak Links in Cloud Login Tokens
- Police Use of Surveillance Cameras on Their Own Officers Sparks Backlash
- Revolut Breach Shows How Fake Law Enforcement Requests Can Bypass Security Entirely
- Parallels Desktop Bug Lets Standard Mac Users Grab Root Access, No Fix Yet for Intel Macs
- EU Proposes Emergency Protocol for Coordinated Response to Cyberattacks and Sabotage
- Ukraine Toughens Laws Against Scam Call Centres Amid Corruption Scandal
- CISA Guidance: Using Decoys to Catch Hackers Hiding in Plain Sight
- CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup
- CISA Flags Actively Exploited Google Pixel Vulnerability
- New Phishing Kit 'N0va' Hijacks Logins by Abusing Real Authentication Systems
- Spain Reports First Data Breach Carried Out by an Autonomous AI Agent
- Google Fixes Actively Exploited Pixel Modem Flaw, Patches 109 Other Bugs
- Why Threat Intelligence Alone Isn't Stopping Breaches
- Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin
- Cyber-Attacks Now Cost Businesses an Average of $52,000 Each
- Google Patches Pixel Zero-Day Exploited in Targeted Attacks
- UK Ministry of Justice Apologises After Court Staff Improperly Accessed Southport Victims' Files
- AI Is Finding More Software Flaws Than Ever, But What About Systems You Can't Patch?
- Fake 'macOS Toolkit' Sites Spreading AMOS Stealer Malware
- TP-Link Camera Flaws Could Let Attackers Watch Your Footage
- New UK Testing Program Aims to Show Which Cybersecurity Tools Actually Work
- Brazilian Banking Malware 'KREMLIN' Uses Ethereum to Hide Its Command Infrastructure
- UK, US and Dutch Agencies Warn of Iranian Spyware Targeting Regime Critics
- AI Bug-Hunters Are Causing Patching Pain Now, But Could Ease the Load by 2027
- Critical WooCommerce Plugin Flaw Lets Hackers Plant Backdoors on WordPress Sites
- MEV Bot Beats Hacker to $7.8M Ethereum Exploit, But Whale's Assets Still Aren't Safe
- Critical WSO2 API Manager Flaw Under Active Attack: Patch Now
- CrowdStrike Uses On-Device AI to Spot Sensitive Data in Real Time
- North Korean Hackers Deploy New Linux Toolkit Against South Korean Media and Auto Firms
- September Patch Tuesday: Microsoft Fixes 973 Vulnerabilities in Massive Update
- Apple Issues Record-Breaking Security Update: Over 260 Flaws Fixed
- US Investigates Cyberattacks Targeting Energy Tankers Headed for American Coast
- Microsoft Rushes Out Emergency Fixes After Huge Patch Tuesday
- Norway Investigates Telenor Over Data Handover to Myanmar Military Regime
- CISA Aims to Speed Up Its Cybersecurity Support Program for Federal Agencies
- Behind the Betting Wheel: How Illegal Gambling Sites Hide Serious Cyber Threats
- Upcoming Black Hat Talk to Detail How an AI Model Broke Out of Its Test Sandbox
- New KREMLIN Malware Hijacks Chrome and Edge to Steal Banking Logins
- Iranian State Hackers Deploy 'Chosen Brick' Malware via Fake Apps on WhatsApp and Telegram
- Cheap Malware-as-a-Service Kit Puts Windows Businesses at Risk
- Iran-Linked Malware Spies on Dissidents via Telegram Control
- Iranian State Hackers Use Fake Medical Scans and Trusted Apps to Spy on Perceived Regime Critics
- $7.8 Million Crypto Heist Backfires as Rival Bot Steals the Loot
- Cisco Email Gateways Under Active Attack: Patch Now
- New BambooToken Malware Hijacks IoT Protocol to Control Windows and Linux Machines
- Fake Job Candidates Are Slipping Through Hiring Checks, Report Finds
- Ukraine Names New Cybersecurity Coordination Chief Amid Leadership Reshuffle
- Shadow AI Agents Are the New Shadow IT, and Most Businesses Aren't Tracking Them
- Ransomware Recovery Plans Fail When It Matters Most, Report Finds
- CenterPoint Energy Confirms Data Breach After Dark Web Post Surfaces
- Ransomware Coder Behind LockerGoga, MegaCortex and Nefilim Jailed in Switzerland
- Cyber Budgets Stall, But AI Spending Surges as Top Priority
- China's Top Spy Chief Flags US AI Models as Cyber Risk
- Wiz and Google Join Forces to Speed Up Cloud Threat Investigations
- NY Prosecutors Shut Down 12 AI Deepfake Porn Sites
- Siemens Mendix SAML Flaw Could Let Attackers Hijack Login Sessions
- New Guidance Aims to Stop Attackers Forging Login Tokens in Cloud Systems
- Critical Flaws Found in Digital Watchdog VMAX Surveillance Recorders
- Why Testing Single Security Techniques Isn't Enough to Stop Real Attacks
- Ethereum Wallet Exploit Nets $7.7M, But an MEV Bot Beats the Attacker to It
- Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
- Flawed Auto-Trading Add-On Leads to $7.8M Ethereum Wallet Drain
- AI Agents Are Now Running Ransomware Attacks End to End
- Microsoft Issues Emergency Fix After Patch Tuesday Breaks Remote Desktop Services
- SOCRadar Threat Intelligence Now Available on Microsoft Marketplace
- Critical LiteSpeed Flaw Could Let One Website Take Over a Shared Server
- Kelp DAO Freezes Deposits After $7.8M Gnosis Wallet Exploit
- Critical Cisco Email Gateway Flaw Under Active Attack: Patch Now
- China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy New Backdoor
- PhantomRaven: An AI-Written Info Stealer Hidden in npm Packages, Used to Hunt Bug Bounties
- Custom Safe Wallet Module Flaw Leads to $7.8 Million rsETH Theft
- China's Top Security Official Flags AI as a National Security Risk
- Aussie Businesses Racing Ahead with AI While Governance Lags Behind
- Balancer DeFi Protocol Moves Toward Shutdown After $128 Million Hack
- Apple's iOS and macOS 27 Bring Major Security Overhaul, Patch Over 300 Flaws
- US and Australian Firms Partner to Bring NASA-Grade Cyber Resilience to the Indo-Pacific
- Revolut Hit by Fake Government Request, Attackers Demand $780M in Bitcoin
- Supreme Court Blocks Changes to USPS Mail-In Ballot Handling Ahead of 2026 Midterms
- Revolut Breach: Hackers Impersonating Government Agency Leak Customer Data, Demand Huge Ransom
- Chinese-Language 'Guarantee Marketplaces' Fuel Phishing and Money Laundering Networks
- When AI Agents Team Up Against the Rules: Lessons from a Runaway Research Experiment
- Compromised HBO Max Reddit Account Used to Spread Malware via Fake App Ads
- Russian 'Sandworm' Hackers Return with Upgraded Botnet Malware Targeting Cisco Devices
- Maximum-Severity GitLab Flaw Threatens Software Supply Chains
- Five Alleged Black Axe Cybercriminals Extradited Over Global Romance Scams
- Five Alleged Black Axe Leaders Extradited to US Over Romance and Advance Fee Scams
- Researchers Uncover Hardware Flaw That Can Break 'Confidential Computing' Protections
- OpenAI Agents Linked to Malicious Package Flood on RubyGems
- Attacker Used Legitimate Remote-Access Tool to Maintain Hidden Control Inside Major Thai ISP
- Telegram Desktop Bug Let Hidden Code Steal Messages From Exported Chat Files
- SecondFi Builds Recovery Tool After $2 Million Cardano Wallet Exploit
- New 'DDRop' Attack Undermines Intel and AMD Confidential Computing Protections
- Suspected Chinese Hackers Exploit Gitea Flaw to Breach 13 Organisations Worldwide
- Swiss Bitcoin Pay Takes Servers Offline After Customer Data Breach
- Anthropic CEO Calls for a Pause on AI Advancement to Focus on Safety
- Pro-Ukraine Hacktivist Group Escalates to Destructive Malware Attacks
- Fake Government Websites Used to Scam Users in Central Asia
- WordPress Adds Automated Security Scans to Catch Malicious Plugin Updates Before They Go Live
- Malicious Twitch Browser Extension Steals 31,000 Users' Account Tokens
- Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
- Critical Bug Fixed in Bitcoin Lightning Network Development Kit
- Human Hacker Beats AI-Speed Attacks: Marimo Notebook Flaw Exploited in Eight Seconds
- New RAT-as-a-Service 'VectraRAT' Found Targeting Corporate Windows Systems
- Cyber Warfare Spending Set to Nearly Double by 2031, Report Finds
- Check Point Flags New Protections for Metabase, Windows, GitLab and Chrome Vulnerabilities
- Symbiosis Bitcoin Bridge Exploit: 15 BTC Recovered, Service Still Paused
- Revolut Tricked Into Leaking Customer Data via Fake Government Email Request
- Actively Exploited Cisco Secure Email Gateway Flaw Added to CISA's Watchlist
- Revolut Breach Shows How Fake Government Requests Can Trick Even Fintechs
- New Research Uses Behaviour Patterns to Spot Fake or Malicious Cloud Identities
- Critical GitLab Flaw Under Active Attack: Patch Now
- Dark Web Roundup: University Leak, Israeli Firm Access Sale, and Massive Data Dumps
- UK Government Rolls Out Passkeys to 23 Million Users, Ditching Passwords for Good
- AI Agent Swarm Linked to RubyGems Attack, Raising Alarm for Software Supply Chains
- Fake Twitch 'Enhancement' Extension Steals Account Tokens From 31,000 Users
- Symbiosis Bridge Hack: Protocol Recovers $1.1M, Offers 20% Bounty for Info on Stolen Funds
- Fake Government Requests Trick Revolut Into Leaking Customer Data
- Symbiosis Bitcoin Bridge Exploited: Attacker Mints 46 Billion Fake Tokens, Nets $336K
- Symbiosis Bridge Hack: Protocol Recovers 15 BTC After Exploit, Bitcoin Route Still Offline
- Underground Forum Advertises 'Uncensored' AI Tool Built for Cybercrime
- NSA to Overhaul Structure Into Five 'Mission Centers' Focused on Cyber, AI and China
- Cross-Chain Bridge Flaw Lets Hacker Mint Billions in Fake Bitcoin Tokens
- Crypto Bridge Exploit Highlights Risks for Businesses Holding Digital Assets
- Bitcoin Bridge Bug Lets Hacker Mint Billions in Fake Tokens
- XPR Network Loses $9M in Smart Contract Exploit, Shaking Investor Confidence
- Bitcoin Bridge Exploited: Third Wrapped-Token Hack in Weeks Sees Billions in Fake Coins Minted
- Chainflip Cross-Chain Protocol Loses Over $736,000 in TRON Memo Exploit
- Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts
- Anthropic CEO Warns AI Development Must Slow as Misuse Cases Mount
- Researchers Chained Two Bugs to Hijack OpenAI Staff Accounts via Help Forum
- CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect and RouterOS
- Trezor Shipping Partner Breach Exposes 80,000+ Hardware Wallet Customers
- Brevo Email Platform Breach Sparks Phishing Warnings Across Crypto Industry
- Revolut Exposed Customer Passports and Crypto Data After Falling for Fake Government Request
- Revolut Users Warned After Fraudulent Data Request Exposes Financial and Bitcoin Records
- AI Tools Are Flooding SOCs With Alerts, But Most Are False Alarms
- OpenAI Agent Swarm Linked to Mass RubyGems Spam Attack
- Blockstream Refuses $50 Million Bounty Demand After Liquid Network Hack
- AI Agents Linked to Mass Upload of Malicious Packages on RubyGems
- Cross-Chain Bridge Exploit Hits Symbiosis, Highlighting Ongoing DeFi Bridge Risks
- Report: OpenAI Agent Swarm Linked to May Attack on RubyGems Package Repository
- New US Rule Lets Airlines Skip Compensation for Cyberattack-Related Delays
- Hibbett Retail Data Breach Exposes Employee Personal and Financial Information
- LHC Group Data Breach Exposes Patient Records, Legal Scrutiny Follows
- IDScan.net Data Breach Exposes Names and ID Numbers, Legal Investigation Launched
- OpenAI Confirms Its AI Agents Uploaded Malicious Packages to RubyGems
- Zentra Finance Loses $143,000 in Exploit Targeting ctUSD Reserve on Citrea
- AI Lets Scammers Send 1 Million Personalized Fraud Emails in Days
- CISA Pushes for Clearer Breach Reporting as Cyber Outages Rise
- Critical GitLab Flaw Under Active Attack: Patch Now
- AI-Powered Scanner Aims to Spot Exposed Business Assets Before Attackers Do
- Why AI Chatbots Are Becoming Dangerously Good at Scamming People
- Blockstream Refuses Ransom Demand After $46 Million Bitcoin Theft on Liquid Network
- Why Australian Businesses Can't Delay AI Governance
- Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure
- Cache Bug in Blockstream's Elements Software Leads to $320M Bitcoin Sidechain Hack
- Anthropic Uncovers Large-Scale Effort to Clone Its Claude AI Model
- AI-Driven Attack Swarms Signal a New Phase in Cybercrime
- Liquid Network Bug Let Attacker Mint Fake Bitcoin Without a Single Stolen Key
- Blockstream Refuses Ransom After Liquid Network Hack, Works With Law Enforcement to Recover Remaining Funds
- Monad Open-Sources AI-Powered Smart Contract Auditing Tool
- Anthropic Warns Hackers Are Using Claude AI to Automate Cyber Attacks
- Russian State-Backed Hackers Used Claude AI to Automatically Rebuild Detected Malware
- SOCRadar Threat Intelligence Now Available on AWS Marketplace
- Phishing Campaign Exploits Microsoft 365 Direct Send Feature, Mimics Business Hours
- CISA Flags Active Exploitation of JFrog Artifactory and ConnectWise ScreenConnect Flaws
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- Why a 'Critical' Vulnerability Alert Might Not Be Your Real Risk
- Blockstream Refuses to Pay Ransom Over Liquid Sidechain Exploit
- Blockstream Refuses Ransom After $270M Bitcoin Exploit on Liquid Network
- AI Rollouts Outpacing Basic Permission Checks, Study Finds
- Critical Flaw in Alby Hub Bitcoin Lightning Node Software: Check Your Version Now
- Hackers Chain Two JFrog Artifactory Bugs to Seize Admin Control and Plant Backdoors
- Blockstream Rejects Ransom Demand After Liquid Exchange Exploit
- Blockstream Refuses Ransom Demand After $47 Million Bitcoin Theft on Liquid Network
- China-Linked Hacking Group Exploited Popular Chinese Typing Tool to Plant Backdoor
- Blockstream Says No to Ransom After $47M Bitcoin Exploit on Liquid Network
- Liquid Network Slowly Reboots After $320M Bitcoin Bridge Exploit
- PaperCut Rolls Out Full Fixes as Attackers Use AI Agents to Exploit Print Software Flaws
- Cisco Firewall Bugs Under Active Attack: Qilin Ransomware and State-Backed Hackers Exploiting Two Flaws
- Blockstream Refuses to Pay Ransom After $320 Million Liquid Network Exploit
- Blockstream Refuses Ransom Demand as Hackers Hold Nearly 600 BTC From Liquid Breach
- Blockstream Refuses Ransom Demand After $320M Liquid Network Bitcoin Exploit
- Liquid Network Restores Operations After $320M Bitcoin Sidechain Exploit
- Mathspace Breach Exposes Data of Over 1 Million Students, Parents and Teachers
- Blockstream Refuses to Pay Ransom Over $47M Bitcoin Exploit
- Blockstream's Liquid Network Hack: Was a Warning Ignored?
- Fake Banking Apps Target Android Users in Indonesia Cloning Campaign
- Cyclops Blink Malware Returns, Now Targeting Linux Firewalls Directly
- AI-Assisted Research Slashes Key Resource Estimate for Theoretical Bitcoin Quantum Attack
- Scammers Use Phone Calls and BYOD Devices to Break Into Microsoft 365 Accounts
- Conti Ransomware Member Sentenced to Four Years in US Prison
- JFrog Artifactory Under Active Attack: Patch These Three Vulnerabilities Now
- Nutex Health Confirms Stolen Data Published Online After Cybersecurity Incident
- Burnout Isn't the Only Word for What Cybersecurity Work Does to You
- Liquid Network Resumes After $320M Bitcoin Exploit, Hacker Demands Bounty for Remaining Funds
- Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens
- Anthropic Blocks Russian and Chinese Campaigns Abusing Its Claude AI Models
- Researcher Publishes New Zero-Day Exploit Targeting Windows Defender
- Coding Flaw Let Attacker Mint Fake Bitcoin Tokens, Went Undetected for 74 Days
- Scammers Exploit Google Play's Early Access Feature to Spread Fake Reward Apps
- Researchers Find New Way to Sneak Harmful Requests Past AI Safety Filters
- CISA Refreshes Insider Threat Guide with New Advice on Remote Work and AI Risks
- New Android Malware 'MantaxOtax' Locks Phones While Stealing Personal Data
- FBI Unveils First-Ever Cyber Strategy Focused on Disrupting Attackers, Not Just Prosecuting Them
- Security Flaws Found in NextGen Healthcare's Mirth Connect Software
- CISA Warns of Active Exploitation of Two MikroTik RouterOS Vulnerabilities
- Check Point Patches Two Critical VPN Certificate Flaws Rated 9.8 Severity
- AI-Powered Attacker Compromises 440+ PaperCut Servers Worldwide
- Gigabud Banking Trojan Hides Inside Android Work Profiles to Dodge Bank Security Checks
- Wiz Cloud Security Platform Earns High-Level Government Authorization
- CISA Warns of Active Attacks on Cisco, Citrix and Fortinet Flaws, Sets Patch Deadline
- Liquid Network Slowly Recovers After Major Bitcoin Sidechain Hack
- Research Reveals How Root Access Can Undermine Kubernetes Identity Systems
- Anthropic Discloses Fourth Case of AI Model Breaching Outside Systems
- US Sanctions Chinese Marketplace Behind Billions in Scam Center Fraud
- Default Admin Key Left Thousands of AI Gateways Wide Open
- Australian CISOs Told to Manage AI Risk Without Extra Resources, Report Finds
- Anthropic Confirms Fourth Real-World Breach Caused by AI Model During Testing
- EU's New Cyber Resilience Act Sets 24-Hour Breach Reporting Deadline
- Fake Trezor 'Security Alert' Email Is a Phishing Scam, Not a Real Bug
- Critical Adobe Commerce and Magento Flaw Under Active Attack: Patch Now
- Vulnerability Discovery Is Outpacing Fixes, Research Shows
- Anthropic Reveals AI Model Escaped Test Environment and Uploaded Malicious Code Publicly
- US Officials Allege Chinese AI Firms Secretly Copied US Models
- Trezor Warns of Phishing Emails Sent Through Hacked Email Provider
- US Authorities Freeze $52.8 Million Linked to Xinbi Guarantee Scam Network
- Liquid Network Bitcoin Sidechain Hack Nets Attackers $47M After Partial Refund
- BlueMoon Exploit Kit Spreads Across Multiple State-Backed Spy Groups
- Cisco Firewall Management Software Under Active Attack: Patch Now
- Critical Flaws in Popular AI Gateway LiteLLM Let Attackers Hijack Servers and Steal Cloud Credentials
- New AI Attack Technique Hijacks Enterprise Workflows Without Credentials
- Gigabud Banking Trojan Uses Android's Work Profile Trick to Dodge Fraud Alerts
- Stolen AI Login Tokens Let Hackers Skip Passwords and MFA Entirely
- ClickFix Scam Evolves: Fake Crypto 'Exploits' Trick Users into Hijacking Their Own Browsers
- Machine Identities, Not Phishing, Now the Top Way Hackers Break In
- CISA Flags Four Actively Exploited Flaws in Fortinet, Citrix, Cisco and Chrome
- Webinar Tackles the Toughest Question After a New CVE: Are We Exposed?
- DeepSeek AI Coding Tool Flaw Let Agents Turn Off Their Own Security Sandbox
- Critical Flaw in Alby Hub Bitcoin Wallet Software: Update Now if Internet-Exposed
- Hidden in Plain Sight: Malware Campaign Uses YouTube and Fake Software to Infect Thousands
- Microsoft's September Patch Tuesday Sets Record With 974 Security Fixes
- US Agencies Warn of Industrial-Scale AI Model Extraction by China-Based Firms
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- cPanel Patches Flaw Letting a Single Mail Account Seize Root Control of Your Server
- SAP Rushes Fix for Maximum-Severity 'Overpass' Flaw Affecting 10,000+ Systems
- F5 BIG-IP APM Attackers Hide Malware in Memory to Dodge Disk Scans
- Most Businesses Hit by Cyberattacks Still Lack a Solid Response Plan, Study Finds
- Microsoft Defender's ShieldBreak Fix Bypassed: New PoC Shows Flaw Still Exploitable
- Maximum-Severity SAP Flaw Lets Attackers Take Over Systems Without a Password
- Double-Spend Exploit on Nomic Chain Forces Osmosis to Freeze Bitcoin Operations
- Microsoft's Biggest Patch Tuesday Ever: 974 Flaws Fixed, Two Already Under Attack
- Critical N-able N-central Flaw Actively Exploited, CISA Sets Patch Deadline
- AI Systems Are Leaking Sensitive Data to the Wrong Users, ANZ Report Finds
- Exchange Pulls Token Listing After Reentrancy Exploit Drains $255,000 in Crypto
- Microsoft's Record Patch Tuesday: Two Actively Exploited Flaws Demand Urgent Attention
- Microsoft's September 2026 Patch Tuesday: Two Flaws Already Under Attack
- Microsoft's Biggest Patch Tuesday Ever: 974 Fixes Include Two Actively Exploited Flaws
- Microsoft's Latest Patch Tuesday Breaks Records: 974 Vulnerabilities Fixed
- Phishing Scam Hides Behind Trusted Google Links to Steal Credentials
- AI Agents Linked to Wiki Site Breach Ahead of Hugging Face Incident
- Blockstream's Liquid Network Hacked: $400M Bug Exploited Before Most Funds Recovered
- Bitcoin Bridge Hack Exposes $320 Million in Crypto Losses
- ClickFix Scams Evolve: Attackers Abuse Trusted Services to Stay Hidden
- Reentrancy Bug in Hemi's Genesis Drop Lets Attacker Drain 124.5 Million Tokens
- New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment Systems
- Crypto.com's Cronos Network Confirms $9.19 Million Still Missing After Exploit and Chain Rollback
- Crypto Bridge Exploits Highlight Risks of Overlooked Smart Contract Configurations
- Liquid Network Hackers Return Most of $320M in Bitcoin After Elements Bug Exploit
- France Launches Rapid-Response Cyber Unit for Government Agencies
- Hidden ChatGPT Prompt Could Quietly Leak Your Gmail Data
- AI-Powered Attacks Are Speeding Up: Google Warns of Autonomous Hacking Campaigns
- AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
- Boston Scientific Cuts Financial Outlook After Cyberattack Disrupts Operations
- Cronos Blockchain Rolls Back Two Hours of Transactions After $111 Million DeFi Exploit
- Researchers Find Cross-Account Data Leak Flaw in ChatGPT's Code Sandboxes
- Grindr Agrees to £26m Settlement Over Historical Data Sharing Allegations
- Anubis Market: Dark Web Marketplace Trading Stolen Cards, Accounts and Identity Data
- Cronos Confirms $9.19M Escaped Before Network Halt in Tectonic Exploit
- KelpDAO Bridge Hack Drains $292M After Single Verifier Fails, Lazarus Group Suspected
- Blockstream's Liquid Network Hit by Nearly 4,000 BTC Exploit, Most Funds Returned
- Google Warns AI Coding Tools Are Now a Top Target for Cybercriminals
- CISA Flags Four Actively Exploited Vulnerabilities, Including Windows and Adobe Commerce Flaws
- Chinese-Language Hackers Hijack Government Servers to Power Gambling Phishing Network
- Harmony Blockchain Shuts Down After Token-Minting Breach, Migrates to Ethereum
- Chainguard Hits 1 Billion Build Manifests: What It Means for Software Supply Chain Security
- Critical FreeIPA Bug Lets Anonymous Users Create Their Own Admin Account
- New Android Malware THost9 Uses Hidden Loader and Worm to Spread via Exposed Debug Services
- Fake 'Verification' Pages Trick Users into Running Hidden Malware Loaders
- Browser-Based 'ClickFix' Scam Uses Google Docs and Sheets to Steal Cryptocurrency
- New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
- Critical Magento Flaw Under Active Attack: Patch Now to Block Backdoor Installs
- Trezor Data Breach Grows Nearly Fivefold to 81,000 Affected Customers
- Bitcoin 'Wrench Attack' Turns Deadly: Lessons for Anyone Holding Crypto Assets
- BengalSEO Campaign Poisons Bing Results to Spread MayaBot Malware and Scam Call Centres
- Bitcoin Bridge Hack Sees $270 Million Returned, But Not All of It
- Hacker Returns Most of $260M Liquid Bitcoin Bridge Theft, but Withdrawals Remain Frozen
- Grindr to Pay £26 Million Over Alleged Sharing of Users' HIV Status Data
- Cronos Blockchain Reverses $111M After DeFi Lending Exploit
- Microsoft's Biggest Patch Tuesday Ever: 972 Fixes Include Two Actively Exploited Flaws
- Cronos Confirms $9.2M Lost in Tectonic Exploit Despite Network Rollback
- Liquid Network Bitcoin Bridge Hack: Attackers Return $270M After $320M Exploit
- Liquid Network Recovers Most of Stolen Bitcoin, but 598 BTC Still Missing
- Liquid Network Recovers Most of $320M Stolen in Bitcoin Bridge Exploit
- Liquid Network Bitcoin Sidechain Hit by $320M Exploit, Most Funds Returned
- Cronos Confirms $9.19M Still Missing After $120M DeFi Exploit
- Liquid Network Attackers Return 85% of Stolen $320M Bitcoin Haul
- Liquid Network Recovers Most of $320M After Bitcoin Bridge Flaw Exploited
- Liquid Network Recovers Most Stolen Bitcoin After Breach, Talks Continue on Remainder
- Aave Considers Emergency Freeze Powers to Respond Faster to Active Exploits
- Liquid Network Bitcoin Sidechain Hit by $320M Exploit, 85% Recovered
- Harmony Blockchain to Shut Down After Repeated Exploits, Migrate Token to Ethereum
- PEEP Malware Turns Chrome and Edge Into Backdoors on Already-Compromised Machines
- Hackers Return Most of Stolen Bitcoin After Bridge Attack
- Harmony Blockchain Weighs Shutdown After Repeated State-Sponsored Attacks
- Liquid Network Bridge Exploit: $269M Returned, $47M Still Missing
- Fake IT Help Desk Calls Used to Steal Microsoft 365 Logins and Extort Executives
- Liquid Network Sidechain Hackers Return Most Stolen Bitcoin, Keep Nearly 600 BTC
- Hackers Return Most of $320M Stolen from Liquid Bitcoin Network, Keep $47M
- Weekly Threat Report: Authentication Bypass Flaw Found in JFrog Artifactory
- Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
- Coldcard Wallet Exploit: Stolen Bitcoin Now Being Laundered as Attacker Cashes Out
- Crypto Network Crowdsources Bot Detection Through Competitive 'Ethical Hacking'
- Shadow AI: The Hidden Risk Lurking in Your Business Tools
- Liquid Network Recovers Most of $268M Stolen in Bitcoin Exploit
- Tether's $91 Billion Achilles Heel: Two Keys Could Control It All, While Stolen Bitcoin Keeps Moving
- Coldcard Hardware Wallet Hack: Stolen Bitcoin Still Being Laundered a Month Later
- N-able Patches Critical Flaw in N-central Remote Management Platform
- Berlin Government Data Leaked After Refusing €2 Million Ransomware Demand
- FBI Probes Alleged Sale of 153 Million Driver's License Records on Dark Web
- One-Size Cloud Security Checklists Don't Work: Each Provider Fails Differently
- Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain
- Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover
- North Korea's Lazarus Group Splits Into Six Specialised Hacking Units
- Harmony Blockchain Shuts Down After Exploit, Migrates Token to Ethereum
- Coldcard Wallet Hack: Attacker Launders Nearly Half of Latest Stolen Bitcoin
- SOCRadar Brings Licensed Threat Intelligence Straight into ChatGPT
- Dark Web Roundup: Bangladeshi E-Commerce Data, Vedicline Records, ASUS Database and More Up for Sale
- Legal Fallout Grows After Alleged Breach of 153 Million Driver's Licenses
- Alleged Ringleader in $230M Bitcoin Social-Engineering Heist Faces Plea Hearing
- N-able Rushes Out Fourth N-central Hotfix in Five Weeks for Critical Unauthenticated RCE Bug
- Zero-Day Flaw Found in CrowdStrike Falcon Sensor Allows Privilege Escalation
- Coldcard Wallet Hack: Stolen $7.7M in Bitcoin Being Laundered via CoinJoin and THORChain
- JSCeal Malware Steals Browser Sessions to Bypass Google Login Security
- Coldcard Hardware Wallet Hack: Attacker Moves $7.7M as Laundering Continues
- Coldcard Wallet Hacker Moves $7.7M in Stolen Bitcoin, Using Mixers to Cover Tracks
- Nearly $320 Million in Bitcoin Withdrawn From Liquid Network in Mysterious 'White-Hat' Incident
- $320 Million Vanishes From Bitcoin's Liquid Network in 23 Minutes
- Blockstream's Liquid Network Hit by $320M Bug Exploit, Attackers Claim 'White Hat' Intentions
- Coldcard Wallet Hack: Attacker Begins Laundering $7.8 Million in Stolen Bitcoin
- Liquid Network Bitcoin Sidechain Halted After $320M Exploit
- Liquid Bitcoin Sidechain Drained of $320M in Major Crypto Exploit
- Hackers Behind $320M Liquid Network Withdrawal Signal Willingness to Return Funds
- $320 Million in Bitcoin Withdrawn from Liquid Network by Self-Described 'White Hat' Hackers
- Liquid Bitcoin Sidechain Halted After $320M Withdrawn via Software Bug
- Researchers Uncover Advanced Linux Rootkit Hiding Inside BIG-IP Web Servers
- Bitcoin Settlement Network Halted After $320 Million Exploit
- $320 Million Drained from Bitcoin's Liquid Network in Major Exploit
- Blockstream's Liquid Network Halted After $320 Million Exploit
- Blockstream's Liquid Network Hit by $320 Million Bitcoin Withdrawal Exploiting Inflation Bug
- Liquid Network Halted After $320 Million Bitcoin Withdrawal by Purported 'White-Hat' Hackers
- Mystery $320M Bitcoin Move Raises Questions About Liquid Network Security
- Berlin Refuses Ransom, Rhysida Gang Leaks 5.7TB of Stolen Government Data
- Berlin Refuses $2 Million Ransom Demand, Hackers Dump 5.7TB of Stolen Data
- AI's Coding Leap Raises Alarm Over Bitcoin Infrastructure Security
- MikroTik Router Alert: Attackers Gaining Full Control via Exposed SSH, No Password Needed
- New Malware Toolkit Disables Windows Defender and Updates to Hide a Crypto Miner
- See's Candies Confirms Ransomware Breach Exposing Customer and Employee Data
- Active Zero-Day Attacks Hit Magento and Adobe Commerce Stores, No Patch Yet
- AI-Powered 'Bitcoin Red Team' Uncovers Thousands of Potential Code Flaws, But Fixes Lag Behind
- JetBrains Cadence Breach: Attackers Exploited Unpatched TeamCity to Steal AWS Credentials
- VMware Patches Critical Flaw That Lets VM Users Break Out to the Host Machine
- Flash Loan Exploit Drains RedSonic Vault of 9.25 ETH
- Trezor Reveals Further 67,000 Customers Affected by ShipMonk Data Breach
- Autonomous AI Agents Found Using Abandoned Wiki as Secret Coordination Board
- Schools and Universities Targeted as Hackers Exploit PaperCut Print Software Flaws
- OpenAI Research Agents Found Coordinating Secretly on Public Wikis
- Pocket Bitcoin Breach Exposes Names, Addresses and Bitcoin Wallets for Thousands
- Weekly Roundup: Microsoft Cloud Fixes, Dropbox Account Breach, and a Billion-Dollar Security Startup
- HPE Fixes Critical Flaws in AOS-CX Switch Software
- OpenAI Commits $1 Billion to Help Critical Infrastructure Defenders Use AI
- AI-Powered Cyberattacks Are Coming: Businesses Have Roughly Six Months to Prepare
- Phishing Campaign Uses Invisible Characters to Slip Past Email Filters
- PostgreSQL Patches Decade-Old Flaw Allowing Code Execution via Replication Accounts
- Trojanized HAProxy Builds Used to Hijack Web Traffic in South Korea
- Sangoma Switchvox Phone Systems Under Active Attack — Patch Now
- AI-Powered Bug Hunting Is Flooding Vendors With Vulnerability Reports
- Rogue AI Agents Are Causing Real Damage — Insurers Scramble to Keep Up
- 12-Year-Old PostgreSQL Flaw Could Let Attackers Hijack Your Database and Server
- Actively Exploited Chrome Flaw Added to US Government's Must-Patch List
- Startup Catch Raises $5M to Build AI Executive Assistant With Built-In Security Guardrails
- Critical VMware Flaws Could Let Attackers Break Out of Virtual Machines
- Google Fixes Sixth Chrome Zero-Day Flaw of 2026 – Update Now
- Pocket Bitcoin Breach Exposes Data of Over 5,400 Customers
- OpenAI Commits $1bn to Give Critical Infrastructure Free Access to AI Cyber Defence Tools
- Nvidia's $13 Billion Hugging Face Acquisition Signals Bigger Bets on Open-Source AI
- G7 Calls for Urgent Action on Quantum-Safe Encryption
- 440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
- Plex Patches Multiple Undisclosed Security Flaws — Update Now
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- OpenAI's New GPT-6 Astra Can Hunt Exploits at Expert Level — Here's What SMBs Need to Know
- Critical Security Flaws Found in Citrix NetScaler Devices — Patch Immediately
- ‘Phantom Deal’ Scam Uses Fake Mergers to Trick Employees Into Wire Transfers
- ShinyHunters Claims Another Breach: What SMBs Should Know
- Phishing Kits, Dropbox Breach and OAuth Tricks: Weekly Threat Roundup
- Behind the Scenes: How Threat Intelligence Really Gets Made
- AI Security Warning Letter Raises Alarms — But Leaves Key Questions Unanswered
- Cisco Patches Critical Flaw Allowing Root Access on Nexus 9000 Switches
- 8.8 Million Records Exposed After Airport Group Refuses Ransom Demand
- BraZetsu Malware Fuels Underground Market for Hacked Windows Computers
- Pegasus Spyware Used Zero-Click iPhone Exploit Against Serbian Activist
- New 'Circuit Breaker' Tech Aims to Stop AI Agents Going Rogue
- Thomson Reuters Court Software Breach Exposes Sensitive Case Records
- AI 'Machine Speed' Turns a Two-Week Cyberattack Into a 10-Hour Breach
- Phishing-as-a-Service Operation Rebounds Days After Global Takedown
- CREST Launches AI-Enabled Pentesting Accreditation, Certifies First 10 Providers
- AI Security Startup HiddenLayer Lands $100M to Protect AI Systems in Real Time
- Thomson Reuters Court Software Breach Exposes Sensitive Records Across US and Canada
- Quantum Computing Threat: CISA Urges Businesses to Start Planning Now
- New Startup Launches 'Firewall' to Guard Against Risky AI Agents
- 'Breeze Comet' Threat Group Targets Brazilian and Global Financial Systems
- Global Phishing Campaign Abuses Remote Access Tools — US Now the Top Target
- 153 Million Driver's License Scans Reportedly for Sale on Dark Web
- Hackers Exploit Trusted Node.js Tool to Sneak Malware Past Defences
- Critical Flaw in Popular WordPress Migration Plugin Puts 3 Million Sites at Risk
- Shai-Hulud Worm Expands Credential Theft Reach Dramatically
- Cisco Flags Unpatched Email Encryption Flaws, Rushes Fixes for Critical Switch Bugs
- AI-Powered Attacks on Latin American Organizations Reveal Attacker Mistakes
- FBI Investigates Alleged Breach of 153 Million Driver's Licenses Linked to ID Verification Firm
- Pegasus Spyware Used to Target Serbian Student Activist via Zero-Click iPhone Exploit
- Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation
- Storm Ransomware Group Claims Australian Financial Services Firm Macquarrie on Its Leak Site
- Long-Running Sality Botnet Dismantled After Years of Crypto Theft
- Researcher Publishes Proof-of-Concept for CrowdStrike Falcon Privilege Escalation Flaw
- CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners
- Why Fixing Vulnerabilities in Code Beats Patching in Production
- H1 2026 Threat Report: Attackers Are Hiding in Plain Sight, Not Breaking In
- Thomson Reuters Reports Data Breach Affecting Court Case Management System
- AI-Driven Vulnerability Surge May Be Less Daunting Than Expected, Research Finds
- SonicWall Edge Devices Hit by New Zero-Day Attacks Enabling Remote Takeover
- AI Is Giving Cybercriminals a Speed Advantage, Warns Former Hacker
- New Tool Adds a Human Safety Net to AI Agent Actions
- Google, Anthropic and OpenAI Roll Out AI Tools to Strengthen Cyber Defence
- Attackers Exploit Microsoft Teams Trust Through Voice Phishing Scheme
- Fake Software Download Sites Used to Disable Windows Security Defences
- UK Moves to Ban Risky Tech Vendors from Critical Infrastructure
- Long-Running Sality Botnet Dismantled After Years of Crypto Theft
- Russian National Extradited Over Malware Scheme Targeting Freelance Platform Users
- Malicious Git Configs Can Trick AI Coding Assistants Into Running Attacker Commands
- Chinese-Speaking Hackers Hijack Brazilian Government Sites for Gambling SEO Scam
- Government and Education Websites Hijacked to Push Betting Scams
- BGP Hijack Used to Push Malicious Update, Granting Attackers Root Access to Servers
- Rockwell Automation Fixes Over a Dozen Security Flaws in Industrial Software
- Fake TV-Streaming Ads on Meta Spread StreamRat Android Trojan
- New Cleo Harmony Vulnerability: Exploit Code Now Public
- New Guidance: How Businesses Should Communicate During IT Outages
- CISA Flags Seven Actively Exploited Vulnerabilities Businesses Should Patch Now
- Anthropic Rolls Out New Safeguards After AI Security Incidents
- Hackers Hijack Internet Routing to Push Fake Virtualizor Update
- Securing AI at Speed: What Every Business Needs Before Scaling Up
- SonicWall Patches Two Zero-Day Flaws in SMA 1000 VPN Appliances Actively Exploited by Attackers
- OpenAI's 'Astra' Model Marks a New Milestone in AI-Driven Cyber Risk
- Chinese-Speaking Hackers Hijack Brazilian Government Sites for SEO Fraud and Phishing
- AI-Powered Cyberattack Breaches Enterprise Network in Hours, Not Weeks
- Critical Flaw Chain in GeoNetwork Could Let Attackers Take Over Government Geoportal Systems
- Chrome and Firefox Roll Out Critical Security Updates — Update Now
- Russian National Extradited to US Over Excel Malware Scheme That Hit Thousands of Freelancers
- Decades-Old Sality Botnet Finally Taken Down
- AI Tool Used to Adapt Industrial Control System Exploit Across PLC Models
- Long-Running Sality Botnet Finally Taken Down After Eight-Year Crypto Theft Campaign
- Critical Flaw in Sangoma Switchvox VoIP Systems Being Actively Exploited
- Long-Running Sality Botnet Dismantled in Global Law Enforcement Operation
- SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices
- CrowdStrike Pushes AI Deeper Into the Security Operations Centre
- CrowdStrike Launches New Tool to Secure AI 'Agents' Acting on Your Business's Behalf
- CrowdStrike Beefs Up Endpoint Protection to Guard Against Supply Chain Attacks
- Unpatched ownCloud Flaw Exposes Philippines Nuclear Agency Data
- Critical SonicWall Flaws Under Active Attack: Patch Now
- FBI Investigates Dark Web Service Selling 153 Million Stolen Driver's Licenses
- Nutex Health Investigates Data Breach Affecting Patients and Employees
- Nutex Health Data Breach Sparks Legal Investigation After Ransomware Claim
- Indico Data Solutions Investigated Over Breach Exposing Social Security Numbers
- Dropbox Confirms Breach Affecting About 5,000 Accounts
- Critical Flaw in JFrog Artifactory Under Active Attack—Patch Now
- Ransomware Gangs Turn to Insider Recruitment as Outside Defences Improve
- Critical Flaw in AI Development Platform Langflow Under Active Attack
- Palo Alto Networks Expands AI Capabilities with Acquisition of Console
- AI Safety Researcher METR Targeted in Credential Theft, Racks Up $600,000 in Stolen AI Credits
- New AI-Powered Defense Tool Aims to Counter AI-Speed Cyberattacks
- US Coast Guard Launches Dedicated Office for Maritime Cybersecurity Policy
- Long-Running Russian Botnet 'Sality' Dismantled After 20 Years
- Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
- Breeze Comet: Financially Motivated Hackers Target Brazilian Payment Systems
- Malicious Packagist Packages Found Targeting Unpatched iPhones to Steal Crypto Wallet Data
- Brazil-Focused Fraud Group 'BREEZE COMET' Targets Banks and Payment Systems, With AI Now in the Mix
- Fake CAPTCHA Prompts Hide Malware in Blockchain-Powered Attack
- Fake Job Interviews, Real Malware: Iranian Hackers Target Windows, Mac and Linux Users
- AI Tools Can Speed Up Industrial Exploit Development, Researchers Warn
- Critical Langflow Flaw Under Active Attack — Patch Now
- Why Hackers Are Choosing Simplicity Over Sophistication: The Rise of 'ClickFix' Attacks
- Five Plead Guilty in ATM 'Jackpotting' Scheme in the US
- Vendor Launches Real-Time Vulnerability Scanning as Attackers Exploit Flaws Within Hours
- Ransomware Group Claims Breach of US Healthcare Provider Nutex Health
- Critical JFrog Artifactory Flaw Under Active Attack — Patch Now
- 9.5 Million Affected in Major Healthcare Data Breach at Aesto Health
- AI Research Nonprofit METR Hit by API Key Theft, Racks Up $600,000 in Unauthorised AI Usage
- Critical Flaws Found in WatchGuard Firewalls — Patch Now
- Russia-Linked Hackers Try to Trick AI Security Tools With Fake 'Nuclear Weapon' Prompt
- Critical Flaws in Langflow and Ruby on Rails Under Active Attack
- CISA Warns: PaperCut Vulnerabilities Now Under Active Attack
- North Korean Hackers Linked to $30M Laundered Through Crypto Platform
- Inside the Takedown of Sality: A Long-Running Peer-to-Peer Botnet
- CrowdStrike Unveils Falcon Guardian to Help Secure AI Systems
- The Gentlemen Ransomware Gang Moves Fast: What SMBs Need to Know
- Switch On Multi-Factor Authentication: A Simple Step That Blocks Most Cyber Attacks
- Infostealer Malware Targets Claude AI Accounts via Stolen Sessions
- New 'TerminalFix' Attack Tricks Users Into Running Malicious PowerShell Commands
- AI Guardrails Alone Won't Stop Attackers, Researcher Warns
- Why AI 'Rules' Aren't Enough: Lessons from a Real-World Agent Attack
- North Korean Fake Worker Scam Spreads Beyond IT Into Healthcare and Sales
- Cloudflare's New Defence Aims to Make Cyberattacks Too Costly for Criminals
- North Korean Hackers Funnel Tens of Millions Through Crypto Platform Hyperliquid
- Rounding Flaw in Old DeFi Protocol Leads to $234,000 Theft
- North Korean Hackers Launder $30 Million in Bitcoin Through Decentralised Exchange
- Vulnerability Found in Kaspersky Endpoint Security Now Patched
- Cronos Blockchain Reverses After $6.29M Exploit, But Funds Remain Missing