Cybersecurity News

Aggregated daily from 10 sources. Updated automatically every morning.

CISA NCSC UK SANS ISC The Hacker News Bleeping Computer Krebs on Security Dark Reading SecurityWeek Exploit-DB CERT-In
245 items Last updated:
View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870 <=2.4.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 MZ Automation MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Chemical, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-16002 The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. View CVE Details Affected Products MZ Automation lib60870 Vendor:MZ Automation Product Version:MZ Automation lib60870: <=2.4.0 Product Status:known_affected Remediations Vendor fixMZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/
CISA Advisories
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-11917 A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authe
CISA Advisories
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected: cMT3092X firmware <20210218  EasyWeb <v2.1.20 CVSS Vendor Equipment Vulnerabilities v3 8.8 Weintek Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-60134 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. View CVE Details Affected Products Weintek cMT3092X Vendor:Weintek Product Version:Weintek cMT3092X firmware: <20210218, Weintek EasyWeb: <v2.
CISA Advisories
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.
Dark Reading News
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
Dark Reading News
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
Dark Reading News
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.
Dark Reading News
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
Dark Reading News
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
Dark Reading News
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
Dark Reading News
No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
NCSC UK Advisories
European and US banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.
Dark Reading News
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
Krebs on Security News
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
Dark Reading News
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.
Dark Reading News
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
Dark Reading News
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
Dark Reading News
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
Dark Reading News
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions.
Dark Reading News
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today.
Dark Reading News
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
Dark Reading News
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
NCSC UK Advisories
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Krebs on Security News
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.
Krebs on Security News
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
NCSC UK Advisories
An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme. 
NCSC UK Advisories
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
Krebs on Security News
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Exploit-DB Exploits
Langflow 1.9.0 - RCE
Exploit-DB Exploits
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
Exploit-DB Exploits