Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild
The shutdown operation involved peer list manipulation and Sality payload URL takedown.
The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek.
Threat group FulcrumSec claims MAG breach and leaks 550GB of data online
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts.
The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR.
The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek.
Peters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued.
The post Tina Peters, through attorney, backs off formal role in Shasta County elections appeared first on CyberScoop.
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes.
The post Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense appeared first on SecurityWeek.
The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities.
The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek.
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]
The Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states.
The post Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots appeared first on CyberScoop.
EMA survey finds 65% of enterprises have seen AI agents act beyond intended scope
Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.
The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek.
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek.
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.
The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek.
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.
The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek.
More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work.
The post The Collective Cyber Defense letter wrote your next vendor questionnaire appeared first on CyberScoop.