Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.
The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek.
The security defect allows unauthenticated attackers to modify or delete user data and public projects.
The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data.
The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek.
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoop.
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities.
The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop.
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
UNISOC modem flaw enabled kernel-level code execution through video calls
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
Hackers used compromised credentials to access enterprise and personal tax-related data.
The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek.
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.
The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek.
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act
Anthropic has been conducting tests to identify issues in how AI agents interact with each other.
The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek.
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.
The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek.
Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.
Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026