Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves
European and US banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans