Jump to: 🔥 Challenge News ⚡ Intel 🔬 Research Labs 📡 All News →

Cybersecurity News

Aggregated daily from 25 sources. Updated automatically every morning.

CISA NCSC UK SANS ISC The Hacker News Bleeping Computer Krebs on Security Dark Reading SecurityWeek Exploit-DB CERT-In Google Project Zero PortSwigger Research Check Point Research Cisco Talos CrowdStrike Unit 42 Elastic Security Labs SentinelOne WithSecure Labs Avast Threat Labs ZDI 0days in the Wild Lakera AI Security Embrace the Red Simon Willison
1,288 items (filtered) Last updated:
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]
Bleeping Computer News
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that
The Hacker News News
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
Infosecurity Magazine News
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let
The Hacker News News
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek.
SecurityWeek News
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
Bleeping Computer News
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of
The Hacker News News
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns
Infosecurity Magazine News
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
Infosecurity Magazine News
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat
The Hacker News News
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
The Hacker News News
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
Bleeping Computer News
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Dark Reading News
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
Dark Reading News
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC wants to regulate AI for ideological bias  appeared first on CyberScoop.
CyberScoop News
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
Bleeping Computer News
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
Dark Reading News
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
Bleeping Computer News
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Dark Reading News
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
Bleeping Computer News
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.
The Hacker News News
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
Dark Reading News
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted
The Hacker News News
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
Dark Reading News
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers.
Dark Reading News
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
Infosecurity Magazine News
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s
The Hacker News News
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
Bleeping Computer News
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.  The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.
SecurityWeek News
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
Infosecurity Magazine News