Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Silent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.
A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.
A list of topics we covered in the week of August 17 to August 23 of 2026
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.
OpenAI has strengthened ChatGPT's protections for teens, but some of its strongest parental controls still depend on linked accounts.
Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.
Malwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.
A researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.
With the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.
We found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers.
Google has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical.
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
A polite reply to a wrong-number text may seem harmless. But scammers use it to profile their victims and fuel a multibillion-dollar fraud industry.
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings in a single workflow.
<p>A year of MDR casework shows attackers repeatedly exploiting demand for AI tools</p>Categories: Threat ResearchTags: AI, malvertising, infostealer, Sophos X-Ops
Apple has released updates fixing 27 vulnerabilities in iOS, iPadOS, and macOS Tahoe, including a potentially serious image-processing flaw.
As one developer found out when his Google Doc containing company passwords showed up in Google search results.
Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.
Learn how North Korean IT worker threat cluster "PurpleDelta" uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to infiltrate organizations. Discover key indicators of compromise and mitigation strategies to protect your company from these fraudulent employment operations.
The Russian influence network CopyCop is targeting Western-backed AI and infrastructure projects in Armenia, including the Firebird AI data center, to undermine the country’s westward geopolitical realignment.
The researcher who found RoguePlanet has discovered ShieldBreak, a new way to bypass Microsoft’s fix and gain SYSTEM privileges.
TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.
Attackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers.
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.