Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties.
The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.
The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]
Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek.
OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities
The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale.
The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek.
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.
The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek.
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]
The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.
The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek.
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]
The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations
The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs.
The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek.
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]
Cifas data finds account takeover and identity fraud are driving a surge in fraud cases
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.
The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek.
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others.
The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward.
The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.
The post Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks appeared first on SecurityWeek.
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds