Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
With no formal training and no career plan, Waisman built a path from Argentina's early hacking scene to leading security at an AI-powered offensive security firm.
The post CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW appeared first on SecurityWeek.
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]
Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.
The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek.
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand.
The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek.
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.
The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek.
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.
The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek.
The security defect allows unauthenticated attackers to modify or delete user data and public projects.
The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data.
The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek.
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoop.
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities.
The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop.
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
UNISOC modem flaw enabled kernel-level code execution through video calls
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
Hackers used compromised credentials to access enterprise and personal tax-related data.
The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek.
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.
The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek.
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act