Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.”
The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute.
The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector.
The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.
The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.
TCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job.
The post Hired for One Job, Judged on Another: The CISO’s Real Problem appeared first on SecurityWeek.
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation.
The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWeek.
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.
The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek.
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses.
The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek.
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.
The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek.
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
The post Rethinking Application Security for the AI Era appeared first on SecurityWeek.
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.
The post Iran-Linked Hackers Shut Down UK Power Plant for Four Days appeared first on SecurityWeek.
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly.
The post TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy appeared first on SecurityWeek.
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.
The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on SecurityWeek.
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision.
The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.