Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences
SANS Institute says governance programs are still nascent even as AI failures and threats grow
The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI
Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumes
The UK government is warning of the potential impact of catastrophic cyber-attacks
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data
Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentials
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
CISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repository
A new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operations