Cybersecurity News
Aggregated daily from 10 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.
The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI.
The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude.
The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek.
I was asked for help with a problem similar to the following.
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.
The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek.
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.
The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek.
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.
The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.
The defining aspect of the attack is that bogus macOS software update screen stealthily
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.
Some defenses improved. The loose parts still got found first. Anyway,
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz.
Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.
The following versions of o6 Automation open62541 are affected:
open62541 on Windows and Linux >=from_1.3.0|<=1.3.17 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)
open62541 on Windows and Linux >=from_1.4.0|<=1.4.16 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)
open62541 on Windows and Linux >=from_1.5.0|<=1.5.4 (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)
open62541 on Windows and Linux master (CVE-2026-63362, CVE-2026-65423, CVE-2026-63035, CVE-2026-63559)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
o6 Automation GmbH
o6 Automation open62541
Integer Underflow (Wrap or Wraparound), Integer Overflow or Wraparound, Use After Free
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Tran
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected:
ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636)
CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636)
GuardLogix 5580 >=V36|<=V37 (CVE-2026-9636)
Compact GuardLogix 5380 >=V36|<=V37 (CVE-2026-9636)
1756-EN4TR V6.001 (CVE-2026-9636)
1756-EN4TR V7.001 (CVE-2026-9636)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.9
Rockwell Automation
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
Improper Check for Certificate Revocation
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-9636
A security issue exists within CompactLogix 5380, Co
View CSAF
Summary
Successful exploitation of these vulnerabilities could crash the device being accessed.
The following versions of MZ Automation lib60870 are affected:
lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.5
MZ Automation GmbH
MZ Automation lib60870
Out-of-bounds Read
Background
Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-61893
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.
View CVE Details
Affected Products
MZ Automation lib60870
Vendor:MZ Automation GmbH
Product Version:MZ Automation GmbH lib60870: 2.4.0
Product Status:known_affected
Remediations
MitigationMZ Automation recommends users update to versio
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.
The following versions of MZ Automation GmbH libiec61850 are affected:
libiec61850 <1.6.2 (CVE-2026-66720, CVE-2026-66369, CVE-2026-63550, CVE-2026-65421, CVE-2026-66364, CVE-2026-66349, CVE-2026-56758, CVE-2026-66360)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
MZ Automation GmbH
MZ Automation GmbH libiec61850
Out-of-bounds Read
Background
Critical Infrastructure Sectors: Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-66720
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.
The following versions of Johnson Controls OpenBlue Employee are affected:
OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497)
CVSS
Vendor
Equipment
Vulnerabilities
v3 2.4
Johnson Controls Inc.
Johnson Controls OpenBlue Employee
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-21662
The application doe
CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.
These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, c
View CSAF
Summary
Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.
The following versions of Watchfire Controller Software are affected:
BC550 12.30 (CVE-2026-5846)
BC750 11.33 (CVE-2026-5846)
BC750 12.35 (CVE-2026-5846)
BC760 12.38 (CVE-2026-5846)
BC760 13.00 (CVE-2026-5846)
BC760DC 12.39 (CVE-2026-5846)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.7
Watchfire
Watchfire Controller Software
Use of Hard-coded Cryptographic Key
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services
Countries/Areas Deployed: United States, Dominican Republic, Canada, Peru, El Salvador
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-5846
The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used