Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands
The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents.
The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.
The company, previously known as ActiveFence, has raised a total of $280 million from investors.
The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek.
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
When Android users get a call from a non-contact, they will see more information about the caller, including their country.
The post WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update appeared first on SecurityWeek.
RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials
Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.
The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on SecurityWeek.
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.
Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
The post Silent Patches Don’t Stop Attackers – They Blind Defenders appeared first on SecurityWeek.
ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems
The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.
The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff appeared first on SecurityWeek.
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek.
The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.”
The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute.
The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector.
The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.
The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.
TCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements