Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.
The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek.
ShinyHunters claims to have stolen 284 million records from McKesson
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek.
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility.
The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop.
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.”
The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. [...]
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.
The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek.
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]
Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.
The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek.
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.
The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek.
Security teams must treat autonomous agents as highly privileged identities.
The post What the Hugging Face Incident Teaches Security Leaders About AI Agent Access appeared first on SecurityWeek.
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.
The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek.
Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.
The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.
The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek.
FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.
The post Extortion Group Claims Manchester Airports Group Data Breach appeared first on SecurityWeek.
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act.
The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberScoop.
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year.
The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first on SecurityWeek.
Microsoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]