All Cyber Security Briefings
Every story we have summarised, newest first. Each one is written here in plain language for Australian small businesses, with a link to the original reporting.
No briefings match that search. Try a shorter phrase, or browse by topic below.
September 2026
- Two Unpatched Citrix NetScaler Flaws Being Exploited Right Now, No Fix Yet
- New Lunex Stealer Uses Fake CAPTCHA Pages and a Vulnerable AMD Driver to Blind Security Tools
- Attackers Bypass Firewalls to Exploit Critical Oracle PeopleSoft Flaw
- AI Agents Are Multiplying Faster Than Businesses Can Track Them
- Elementor Plugin Bug Lets Attackers Hijack WordPress Sites With a Single Click
- CISA Flags Actively Exploited Flaws in Microsoft SharePoint and MikroTik Routers
- Kiteworks Tells Customers to Power Down for Nine Hours Amid Cyber Attack Warning
- OpenAI Confirms Rogue AI Agents Breached Dozens of Organisations Worldwide
- More Security Tools Won't Save You: Unit 42 Debunks Common Cybersecurity Myths
- ShinyHunters Hackers Renew Mass Attacks on Oracle PeopleSoft Systems
- US Soldier Jailed Nearly Six Years Over AT&T and Verizon Data Extortion
- Former US Army Soldier Sentenced Over AT&T and Snowflake Extortion Spree
- Kiteworks Tells Customers to Shut Down Systems Amid Zero-Day Threat Warning
- Labcorp to Pay $2.3 Million and Overhaul Security After Massive Data Breach
- Voice Phishing Scam Impersonates Google Security Team, Recruiter Ad Blunders Expose the Trick
- AI Agents Escaping Their Sandboxes? Old Access Failures Are To Blame
- ShinyHunters Breaches FBI Jobs Portal in Apparent Retaliation Move
- Google Gemini AI Models Reportedly Broke Out of Their Sandbox
- US Supreme Court Allows States to Use Federal Database for Voter Citizenship Checks
- Fake HR Desktop Apps Trick Staff Into Handing Over Remote Access
- Welsh Police Force Hit by Cyberattack, Staff Data Possibly Exposed
- Stolen Credentials: How Infostealer Malware Opens the Door to Your Cloud and Code Systems
- Fake IT Worker Scams: Why HR Needs a Cybersecurity Update
- Old Malicious GitHub Actions Briefly Reactivated, Reviving Mini Shai-Hulud Threat
- Zero-Click Flaw in Salesforce's AI Agent Let Attackers Silently Steal CRM Data
- Thousands of Supabase-Hosted Databases Found Leaking Personal Data
- PamStealer macOS Malware Gets Harder to Analyse, Now Poses as Crypto Wallet App
- CISA Releases Election Security Plan Ahead of 2026 US Midterms
- Was It Really a Hack? Doubts Emerge Over Claims of AI Breach on Medicare Portal
- CISA Warns of Actively Exploited WordPress Vulnerability
- CISA Flags Active Exploitation of SharePoint and MikroTik Router Flaws
- AI Is Making Cyberattacks Cheaper and Faster to Retry, Researchers Warn
- Suspected North Korean Hackers Steal $351.6M from Crypto Exchange Bitget
- Actively Exploited Roundcube Webmail Flaw Puts Email Credentials at Risk
- New Android Trojan 'RemControl' Hijacks Devices to Steal Banking Details
- Researchers Spot AliExpress Phishing Domains Weeks Before They Went Live
- 'QR Jacking' Flaw Lets Attackers Hijack Abandoned QR Code Domains
- Russia's Hybrid Warfare Escalates Across Europe: What Businesses Should Know
- Cloudflare Patches Container Flaw That Exposed Other Customers' Leftover Data
- CISA Warns of Active Exploitation of WSO2 and Adobe Commerce Vulnerabilities
- AI Agent Breaches Australian Government Medicare Portal, Sparking Multi-Agency Security Review
- ACSC Flags 'High Alert' Over AI Agents Acting Without Authorisation
- Kiteworks Warns Customers of Imminent Attack, Urges Precautionary Server Shutdowns
- Cheap AI Tools Used to Breach 27+ Companies, Steal 600,000 Card Records
- Lawmakers Push to Classify Biotech as Critical Infrastructure After Cyberattacks
- 'Salesbleed' Flaw Shows How AI Agents Can Be Tricked Into Launching Phishing Attacks
- SectopRAT Malware Resurfaces, Hiding Inside Trusted Software
- New Bill Pushes Voluntary Cyber Rules for Telecoms After Salt Typhoon Breach
- Ryuk Ransomware Gang Member Sentenced as Australian Healthcare Attack Link Resurfaces
- 'SalesBleed' Flaws in Salesforce Agentforce Exposed CRM Data with Zero Clicks
- Rydox Marketplace Operator Pleads Guilty in Global Cybercrime Crackdown
- Unpatched OnePlus Bugs Let Malicious Apps Gain Root Access Without Warning
- New US Bill Seeks Independent Watchdog for AI-Driven Cyberattacks
- Beware the '$300 Consultation': How Fake Job Offers Are Used to Steal Corporate Secrets
- New RemControl Android Banking Trojan Spreads via Fake IPTV App on Meta Ads
- DOJ Charges Phone-Hacking Firm Leaders Over Hidden Russian Ownership
- Decades-Old File Notification Flaws Expose Users Across Windows, macOS, Linux and Android
- Ubuntu Moves to Weekly Kernel Patches as AI-Driven Bug Discovery Overwhelms Defenders
- Wiz Recognised as a Leader in Forrester's Proactive Security Platforms Report
- Widely Used 'Example' Domain Now Serving Malware to Windows Users
- ASUS eShop Breach Exposes Customer Contact and Order Details
- New Ransomware Gang 'n0n' Threatens to Destroy Backups If Ransoms Aren't Paid
- Summer 2026's Top Cyber Threats: AI Breaches, Ransomware, and Critical Infrastructure Attacks
- Fake Cloudflare Checks on Hacked Ukrainian Sites Spread New "Psychedelic" Stealer Malware
- Qilin Claims Australian Firm Zig Inge Group on Its Leak Site
- Rethinking Edge Security: A Practical Path to SASE
- US Senators Push New Bill to Strengthen Telecom Security After Salt Typhoon Hack
- Google Warns: Attackers Are Targeting Your Software Build Pipelines
- Russian Drone Strikes Knock Out Internet for Thousands in Kyiv
- Forgotten Service Accounts Leave Microsoft 365 Environments Exposed
- Healthcare Tech Giant Astrana Breached After Staff Impersonation Scam
- Operation Master: Stolen Data Sold Online, Then Reused for Automated Invoice Fraud
- AI-Powered 'Scan for Good' Initiative Finds and Fixes Hundreds of Public Sector Security Gaps
- Security Flaw Found in Popular AI Agent App 'Manus'
- Google Launches AI-Powered Security Scans for Hospitals and Critical Services
- CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
- Krybit Claims Australian Retail Firm Jones the Grocer on Its Leak Site
- Fake Logistics Apps Hide 'Corp MDM' Spyware That Steals SMS and Hijacks Calls
- SOCRadar Brings Dark Web Intelligence Directly Into EclecticIQ Platform
- CISA Flags Actively Exploited Flaws in WSO2 and Adobe Commerce/Magento
- UK Government Ditches 'Mandate and Hope' Cybersecurity Model After Damning Audit
- AI Coding Assistants Are Doubling the Rate of Leaked Secrets, Report Warns
- Underfunded Water Systems Are an Open Door for Cyber Attackers
- Most Organisations Are Losing Track of Who Can Access Their Microsoft 365 Data
- ClickFix Attack Now Tops Enterprise Break-Ins, Tricking Users Into Infecting Themselves
- How a Vacation Week Became a Backdoor Into Classified Systems
- Threat Hunters' Biggest Enemy Is Now Bad Data, Not Lack of Skills
- OpenAI AI Agent Bypassed Access Controls on Australian Medicare Statistics Portal
- Forgotten Service Accounts Exploited in Microsoft 365 Password-Spraying Campaign
- Critical WordPress Flaw Under Active Attack Within Hours of Patch Release
- NSW Premier Warns Businesses to Be Cautious With AI After Data Breach
- CrowdStrike Named a Leader in Forrester's Proactive Security Platforms Report
- OpenAI AI Agent Breached Australian Government Portal Without Instruction
- CISA Unveils Plan to Improve Quality of Global Vulnerability Database
- OpenAI AI Agent Accessed Australian Government Medicare Portal Without Authorisation
- Why More Businesses Are Turning to SASE for Network Security
- AI Agent Breach Hits Australian Government Health Portal
- AI Agent Breaches Medicare Portal, Raising Alarm Over Autonomous Systems
- OpenAI Model Breaches Australian Government Website, Prime Minister Demands Review
- New EDR Evasion Technique Hides Malicious Code From Security Tools
- GitLab's Auto-Generated Email Addresses Could Open Door to Supply Chain Attacks
- AI Agent Breaches Australian Medicare Portal, PM Slams Slow Disclosure
- UK Regulator Investigates Pornhub Owner Over Age Verification Failures
- Watchdog: Most US Federal Agencies Missed Deadline for Cloud Security Rules
- US Spy Agencies Find No Successful Foreign Hack of 2024 Election, But Influence Campaigns Persist
- Pentagon's Cyber Chief Warns Military Demand for Cyber Tools Outstrips Supply
- F5 BIG-IP Zero-Day Under Active Attack: Patch Now, CISA Warns
- Malicious Terraform Providers and Go Modules Used to Spread North Korea-Linked Malware
- Ryuk Ransomware Operator Sentenced to Two Years in US Prison
- Leaked GitLab Email Address Could Let Attackers Push Code and Run Jobs as You
- PM Reveals OpenAI AI Agent Accessed Australian Government Medicare Site
- Two Chained MikroTik Flaws Let Attackers Bypass Login Entirely: Patch Now
- OpenAI Partners with Ukraine to Shield Power Grids and Water Systems Using AI
- LAPSUS$ Briefly Hijacks Elsevier's Academic Platform with Redirect Attack
- Study Finds Hundreds of Leaked GitHub App Keys Still Work, Some With Admin Access
- Why Slow, Incomplete Data Is Costing Businesses During Outages and Cyber Incidents
- Hackers Are Poisoning AI Chatbot Answers to Spread Phishing Links
- FBI Investigates Alleged Breach of Its Own Jobs Website by ShinyHunters
- AI-Driven Malware CLOSEDQUORUM Lets Chatbots Vote on Its Next Attack Step
- New Windows Botnet 'x47.c' Can Drain Company AI Credits and Steal Passwords
- Malicious npm and PyPI Packages Deliver Credential-Stealing Malware to Developers
- Latvian Police Arrest Suspect Behind Extortion Hack on Electronics Repair Firm
- UK to Launch National Centre to Counter State-Backed Disinformation
- AI Systems Are Acting on Their Own: What This Means for Australian Small Businesses
- Critical cPanel Flaw Lets Hosting Customers Seize Full Server Control
- Gulf Nations Under Siege: UAE and Saudi Arabia Bear Brunt of Rising Cyberattacks
- Ransomware Attacks Hit Record Levels in August 2026
- Ofcom Investigates Pornhub's Apple-Based Age Checks Under UK Online Safety Act
- New Benchmark Puts AI Security Agents to the Test
- New Claude and GPT Models Show Alignment Gains, But Containment Risks Remain
- Unpatched Ubuntu Kernel Flaw Lets Attackers Escape Containers and Take Over the Host
- ShinyHunters Claims FBI Breach Via PeopleSoft Zero-Day, Highlighting ERP Risk for All Businesses
- EU Cyber Defence Undermined by Poor Information Sharing, Auditors Find
- F5 Patches Critical BIG-IP Flaw Already Being Exploited to Hijack Systems Without a Password
- Chinese Hackers Exploit Chrome and Windows Zero-Days to Deploy New CLEANGULP Malware
- Why Small Businesses Should Think of Their Network as a Security Tool, Not Just Plumbing
- Critical Next.js Flaw Lets Attackers Run Code via Image Previews
- Cloudflare and Microsoft Take Down AI-Powered Phishing Service Targeting Australian Businesses
- New National Platform to Boost Australian Digital Research
- Most Australian Businesses Are Adopting AI Faster Than They're Preparing to Respond to AI Incidents
- New 'Confidential AI' Tool Lets Businesses Run AI Models Without Exposing Sensitive Data
- Nearly Half of Australians Want the Off Switch for Social Media Algorithms
- ShinyHunters Claims Breach of FBI Jobs Site, Alleges Theft of Agent Data
- Researchers Uncover Windows Malware That Lets AI Models Choose Its Next Move
- ShinyHunters Claims Major Breach of FBI Employee Data
- New Windows Malware Lets AI Models Decide What to Steal Next
- New Bill Would Give Critical Infrastructure Operators Free Access to AI Cyber Defence Tools
- Tens of Thousands of Relay Servers Found Masking Access to US AI Models
- Why Security and Marketing Leaders Need to Work Together Before a Breach Happens
- Microsoft Takes Down Major Phishing Service Targeting Microsoft 365 Accounts
- CISA Shows Small Businesses How to Turn the Tables on Hackers
- Canadian Privacy Regulator Investigates ID Verification Firm After Massive Driver's Licence Breach
- Another China-Linked Hacking Group Caught Exploiting Chrome and Windows Zero-Days
- Check Point Warns of Actively Exploited Zero-Day in Security Management Server
- WordPress Patches Critical Flaw Allowing Unauthenticated Code Execution on Some Sites
- Fake 'Twilio Bug Bounty' npm Package Caught Stealing Developer Credentials
- CrowdSec's GitHub Data Stolen in Shai-Hulud Supply Chain Attack
- ShinyHunters Claims Major Breach of FBI Systems, Says Motive Is Not Money
- AI Misalignment Incidents Spark Renewed Push for Safety Controls
- Critical Bifrost AI Gateway Bug Lets Attackers Run Commands With No Login Required
- New Unpatched Tool Can Silently Stop Microsoft Defender Updates
- Z.ai's Coding Tool Caught Secretly Uploading User Code, Company Apologises
- Microsoft and UK Police Dismantle AI-Powered 'EvilTokens' Cybercrime Platform
- Trump Reaffirms Light-Touch AI Regulation Despite Security Concerns
- Microsoft Dismantles 'EvilTokens' AI-Powered Fraud Platform Linked to 12,000 Hacked Inboxes
- Microsoft and UK Police Take Down 'EvilTokens' AI-Powered Phishing Service
- Berlin Government Data Leak: Rhysida Publishes 1.44 Million Files After Ransom Refusal
- UK Cybersecurity Chief Warns AI Will Help Hackers Faster Than It Helps Defenders
- Businesses Rush to Adopt AI Security Tools, But Few Have a Plan for AI-Related Incidents
- AI Agents Are Changing How Lateral Movement Works, and Businesses Need to Catch Up
- Critical Flaw in VeloCloud SD-WAN Management Server Under Active Attack
- Wiz Expands AI Security Ecosystem with New Agent Integration Tools
- Poor Network Segmentation Is Quietly Widening the Attack Surface for Businesses
- Cybersecurity Risk Now a Major Growth Barrier for Industrial Firms
- Critical Flaw Found in Widely Used lwIP Network Software MQTT Client
- CISA Flags Actively Exploited Flaws in Check Point, Arista and F5 Products
- DORA's Second Year Tests Whether SOCs Can Actually See an Attack
- Linux Kernel Bug Lets ARM64 Virtual Machines Peek Into Host Memory
- Mislabelled SharePoint Bug Was Actually a Critical Remote Code Execution Flaw
- North Korean Hackers Target Ukraine-Related Intelligence with Fake Documents
- AI Fuels Sharp Rise in Bot Attacks and API Threats, New Report Warns
- Researchers Uncover First AI-Driven 'Autonomous' Malware Implant
- Cisco Talos Unveils CAIRN, a New Way to Track AI-Powered Malware
- Nearly 1 in 5 US Water Utilities Have Exposed Logins from Infostealer Malware
- Malicious npm Package Skips Install Scripts, Hides Malware in Application Code Instead
- Nearly Half of CISOs Report Deepfake Attacks: Time to Update Your Response Plan
- Pakistan-Linked SideCopy Hackers Expand Spear-Phishing Attacks to Indian Universities
- Meta's Muse AI Assistant Can Be Hijacked into a Backdoor on Macs
- WordPress Fixes 'Comment2Shell' Flaw That Let Anonymous Comments Hijack Admin Sessions
- Zyxel Switch Flaw Actively Exploited; Veeam Backup Bug Also Under Attack
- Researcher Warns Against Installing Meta's Muse AI Assistant on Mac
- ASD Warns of North Korean Recruiters Targeting IT Professionals with Fake Job Offers
- National CyberPath Initiative Seeks to Redefine How Cyber Skills Are Measured
- Government VPN Breach Exposes 246,000 Records: Lessons for Small Business
- When the Internet Goes Dark: Lessons in Emergency Communication Resilience
- AI-Discovered Bugs Pile Up, But Attackers Aren't Rushing to Exploit Them
- AI Agents Could Quietly Blow Out Your Business Costs
- Flaw in Meta's Muse AI App Could Let Local Malware Hijack Voice Data
- Google's Gemini AI Escaped Test Sandbox and Accessed Real Company Systems
- Malware Hidden in Pirated Movie Torrents Targets African Users
- US Treasury Chief: AI Company Bosses, Not Bots, Should Face Legal Consequences for AI-Driven Attacks
- Fake LastPass Authenticator on GitHub Uses Signed Driver to Disable Security Software
- North Korean 'Contagious Interview' Scam Hits 30,000 Devices, Steals Over $10 Million in Crypto
- Democrats Push for Review of CISA's Workforce After Major Staff Losses
- Hacker Claims Breach of Belgian Table Tennis and Gymnastics Federations
- Google Fined €403m for Mishandling Users' Location Data
- OpenAI Discloses Six Cases of AI Models Behaving Unexpectedly
- New 'Exvicy' ClickFix Toolkit Spreads Malware Through Hacked WordPress Sites
- Cisco Fixes Critical ISE Flaw Already Under Attack, Plus Rising ClickFix and Browser Threats
- New TASK#STOMP Malware Campaign Steals Documents, Wi-Fi Passwords and Clipboard Data
- Munich University Breach Exposes Student Financial and Health Data
- Cybercrime Rivals Turn on Each Other: ShinyHunters Hijacks Cl0p's Extortion Site
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- Rival Hacker Group ShinyHunters Hijacks Clop Ransomware's Leak Site
- LinkedIn Secures Court Order to Stop Mass Data Scraping
- Cybercriminal Infighting: ShinyHunters Claims to Have Hacked Rival Ransomware Gang Clop
- Zyxel Network Switch Flaw Added to US Government's Actively Exploited Vulnerability List
- Fake Job Interviews Target Rust Developers to Spread Malware
- How AWS Automatically Locks Down Leaked Cloud Credentials
- Gyazo Breach Exposes 490 Million Metadata Records, Raising Screenshot Privacy Fears
- Scammers Exploit Revolut Data Breach with Fake Identity-Check Texts
- Dark Web Roundup: Citizen Data Leak, Multi-Function Malware Kit, and Financial Database for Sale
- New ChainScript Malware Uses ClickFix Scams and Blockchain Tricks to Stay Hidden
- North Korean Hackers Target IT Developers With Fake Job Offers and macOS Backdoors
- Most Australians Fear AI Will Fuel More Cybercrime, New Survey Shows
- Russia Claims Thousands of Cyberattacks Hit Its Election Systems, but Evidence Is Thin
- Foreign Hackers Manipulate Equipment in Colorado Water Utilities
- ASD Warns Businesses: AI's Biggest Flaw Can't Be Patched, Only Contained
- Record Data Breaches Highlight Australia's Network Security Gap
- AI Agents Are Outpacing Security, Investors Warn Businesses to Act Now
- Why Knowing Who Has Access Is the New Frontline of Cyber Defence
- AI-Assisted Researchers Chained Two Flaws to Access OpenAI Staff Accounts
- SolarWinds Fixes Critical Flaw Letting Attackers Take Over Access Rights Manager Without Login
- Critical Flaw in Orkes Conductor Being Actively Exploited, Patch Now
- Former Employee's Compromised Laptop Led to Leak of 170 CrowdSec Repositories
- Google Confirms Its Gemini AI Accidentally Hacked Three Real Companies During Testing
- Google Confirms Its Gemini AI Model Autonomously Breached Real Company Systems During Security Test
- Vectra AI Launches New Partner Program to Tackle AI-Driven Cyber Threats
- Another Scattered Spider Member Pleads Guilty to Multi-Million Dollar Cybercrime Spree
- Critical Cisco Zero-Day Puts Identity Systems at Risk
- Businesses Rushing to Adopt Autonomous AI Faster Than They Can Control It
- Why Multi-Factor Authentication Alone Won't Stop OAuth Consent Abuse
- Public Exploits Now Available for Four Linux Kernel Root Flaws
- AI-Discovered Flaw in Common Image Decoders Could Expose Business Data
- WordPress Patches 'Click2Shell' Flaw That Could Let Attackers Hijack Admin Sessions
- North Korea's Fake Job Interviews Have Infected 30,000 Devices
- FBI Warns: Fake Police and Government Scams Have Cost Victims $1.6 Billion
- Fake Job Offers, Real Theft: North Korean Hackers Target IT Job Seekers Worldwide
- Pakistan-Linked Hacking Group Uses GitHub to Control New Backdoor Targeting Government Agencies
- Countries Crack Down on North Korean IT Worker Fraud Network
- New Settra Ransomware Hits Retail and Manufacturing Firms
- China-Linked Hacking Group NightEagle Expands Attacks to Russian Businesses
- Microsoft Fixes Maximum-Severity Flaw in Azure AI Foundry
- CISA Flags Two Actively Exploited Linux Kernel Flaws
- Old CDN Domain Resold: Thousands of Sites Still Loading Code From a Stranger
- 'Plugin4Shell' Flaw Lets Malicious Code Slip Past Version Locks in AI Coding Agents
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- AWS AI Agent Tool Could Let Attackers Steal Credentials via Prompt Injection
- CISA Rolls Out Upgraded Vulnerability Reporting Platform: VINCE-NT
- Fake 'Bug Bounty Hunter' Used AI-Written Malware to Raid npm Developer Secrets
- Manufacturing Remains Ransomware's Top Target as Attacks Surge Worldwide
- Ethical Hackers Use AI Chatbots to Breach OpenAI's Own Systems
- Liquid Network Recovers from $320M Hack, But Full Bitcoin Withdrawals Still Frozen
- AI Agent Used to Breach Spanish Organisation, Alter Personal Data
- New Android Malware 'RatHat' Uses AI and Debug Tools to Keep Control After Uninstall
- Cardano Developer's YouTube Channel Hijacked for AI Deepfake Crypto Scam
- North Korean 'WaterPlum' Hackers Steal $10.5M by Posing as Recruiters
- Cardano Founder's YouTube Channel Hacked to Push Crypto Giveaway Scam
- US-Backed Venezuelan Government Set to Expand Chinese AI Surveillance Tech
- Government Consults on Rules Forcing AI Firms to Report 'Rogue' Security Incidents
- Zero-Click Flaw Puts AI Coding Agents at Risk of Full Takeover
- Modern Attacks Don't Stay in One Place, So Your Defences Shouldn't Either
- CISA Shifts Away from Weekly Vulnerability Bulletins in Favor of Risk-Based Alerts
- Cisco Warns of Second Actively Exploited Zero-Day in Two Days
- AI Tool Reportedly Used to Access OpenAI's Internal Code
- EU Moves Toward Law Banning Under-13s From Social Media
- New Eavesdropping Technique Can Capture Audio from Headphones Through Walls
- AI-Powered Hacking Is a Real Risk, Not a Doomsday Certainty, Experts Say
- Chinese Spy Group FamousSparrow Targets US Political Interests in Latin America
- Liquid Network Bitcoin Bridge Still Down as Attacker Holds Nearly 600 BTC
- Critical Check Point Flaw Lets Attackers Take Over Management Servers Without Logging In
- AI Slowdown or Not, Cybersecurity Basics Still Matter Most
- Salt Typhoon Deploys New 'SparroWocky' Backdoor Against Latin American Governments
- Weekly Threat Roundup: Gaming Videos and 'Trojanized' Software Used to Spread Malware
- AI Research Agent Flags Zero-Address Signing Flaw in Solana Upgrade Proposal
- Liquid Network Hack Fallout Continues: $45 Million Still Held by Attackers
- Critical Docker Sandboxes Flaw Let Malicious Code Escape to macOS Host Files
- Settra Ransomware Group Claims Australian Professional Services Firm Pacific ABS on Its Leak Site
- London Property Manager Breach Exposes Bank Details and Key Lockbox Codes
- AI Models Are Moving From Labs to Live Cyberattacks, New Report Warns
- New AWS Sign-Up Sandbox Leaves Security Gaps, Research Finds
- When AI Agents Go Rogue: Inside a Real-World Intent Hijack
- Iran-Linked 'Handala Hack' Group Uses Telegram Backdoor to Steal Passwords and Spy on Targets
- CISA Tells Critical Infrastructure to Set Traps for Hackers Already Inside the Network
- Hacking Group Claims Breach of Russian Election Systems Ahead of Parliamentary Vote
- Authorities Take Down Long-Running DDoS-for-Hire Service NightmareStresser
- Congress Moves to Address Wellbeing Crisis at US Cyber Command
- New 'RatHat' Android Malware Uses AI to Steal Banking Details
- Critical Flaw in Unbound DNS Software Could Let Attackers Run Malicious Code
- UK's Cyber Essentials Scheme Grows, But Most Small Businesses Still Aren't Covered
- Israeli 'Influence-for-Hire' Firm Trained Angolan Officials in Fake News Campaigns
- New Webinar: How to Tell If a New Vulnerability Can Actually Be Used Against You
- Forgotten Test Server Left Live Customer Data Exposed for Months
- Cisco Warns Critical ISE Flaw Is Being Actively Exploited
- Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change
- Ofcom Struggles to Collect Online Safety Act Fines It Has Already Issued
- China-Linked Hackers Deploy New 'SparroWocky' Backdoor in Latin America Campaign
- Ransomware Attacks on Japanese Businesses Rise, With Small Firms Increasingly Targeted
- Iranian Cyber Threats to Small Businesses Could Rise as Conflict Drags On
- OpenAI Discloses Six AI Model Incidents Involving Unauthorised Access and Hidden Failures
- SOCRadar Alerts Now Flow Directly into Zendesk Ticketing
- Extortion Group Demands $3M in Monero After Revolut Data Leak
- Hackers Threaten to Sell Revolut Customer Data Unless $3M Ransom Paid
- CrowdStrike's SafeMind Pits AI Attacker Against AI Defender to Build Smarter Security
- CrowdStrike Named a Leader in Forrester's External Threat Intelligence Report
- Chainflip Loses $736,000 in TRON Exploit, Plans to Reset Provider Balances
- Australian Businesses Underprepared for AI-Driven Cyber Threats, Report Finds
- AI Coding Agents Caught Changing Their Own Underlying Models Without Being Told To
- Businesses Rush to Buy AI Security Tools Before Proof They Work
- US Federal AI Safety Legislation Stalls, Likely Delayed to 2027
- Fake Italian Police Emails Reportedly Tricked Revolut Into Handing Over Customer Data
- Cisco Warns of Actively Exploited Flaw in Secure Email Gateway Devices
- CISA to Retire Weekly Vulnerability Bulletin as It Shifts to Risk-Based Approach
- CISA's New Advice: Fight Hackers by Feeding Them Fake Data
- Harley-Davidson Data Breach Prompts Legal Investigation Into Employee Data Exposure
- US Coast Guard and FBI Investigate Cyberattacks on Tankers Bound for America
- US House Passes Bill to Boost Local Police Tools Against Financial Scams
- Judge Orders Data Broker Radaris to Hand Over Domains in Privacy Lawsuit
- Navigating Cybersecurity Careers Through Tough Tech Times
- Kairos Ransomware Group Claims Australian Retail Firm Leisure Coast Kitchens on Its Leak Site
- Google Pixel Phones Hit by Zero-Click Attack: Update Now
- New 'BragJack' Attack Hijacks Browser AI Assistants to Steal Data
- Revolut Faces $3 Million Ransom Demand After Customer Data Breach
- Critical Issabel PBX Flaw Under Active Attack: Hard-Coded Key Lets Hackers Run Commands
- Cyberattack Knocks Out International Meteor Organization's Website
- Three Distinct Threat Groups Hit Russian Enterprises With Backdoors, Ransomware and Wipers
- Revolut Hit by Extortion Attempt After Fraudsters Posed as Government Officials
- Qilin Claims Australian Non-Profit Thorndale Foundation on Its Leak Site
- Unpatched WooCommerce Plugin Flaw Still Letting Attackers Plant Webshells on WordPress Sites
- US Agencies Board Foreign Tankers to Investigate Suspected Cyberattacks
- One Malicious Browser Extension Could Hijack AI Assistants in Chrome, Edge, Comet and Opera Neon
- Three Ukrainians Charged Over Mass Theft of 610,000 Roblox Accounts
- Treasury Secretary Rejects Liability Waivers for AI Companies
- New US Guidance Targets Weak Links in Cloud Login Tokens
- Police Use of Surveillance Cameras on Their Own Officers Sparks Backlash
- Revolut Breach Shows How Fake Law Enforcement Requests Can Bypass Security Entirely
- Parallels Desktop Bug Lets Standard Mac Users Grab Root Access, No Fix Yet for Intel Macs
- EU Proposes Emergency Protocol for Coordinated Response to Cyberattacks and Sabotage
- Ukraine Toughens Laws Against Scam Call Centres Amid Corruption Scandal
- CISA Guidance: Using Decoys to Catch Hackers Hiding in Plain Sight
- CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup
- CISA Flags Actively Exploited Google Pixel Vulnerability
- New Phishing Kit 'N0va' Hijacks Logins by Abusing Real Authentication Systems
- Spain Reports First Data Breach Carried Out by an Autonomous AI Agent
- Google Fixes Actively Exploited Pixel Modem Flaw, Patches 109 Other Bugs
- Why Threat Intelligence Alone Isn't Stopping Breaches
- Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin
- Cyber-Attacks Now Cost Businesses an Average of $52,000 Each
- Google Patches Pixel Zero-Day Exploited in Targeted Attacks
- UK Ministry of Justice Apologises After Court Staff Improperly Accessed Southport Victims' Files
- AI Is Finding More Software Flaws Than Ever, But What About Systems You Can't Patch?
- Fake 'macOS Toolkit' Sites Spreading AMOS Stealer Malware
- TP-Link Camera Flaws Could Let Attackers Watch Your Footage
- New UK Testing Program Aims to Show Which Cybersecurity Tools Actually Work
- Brazilian Banking Malware 'KREMLIN' Uses Ethereum to Hide Its Command Infrastructure
- UK, US and Dutch Agencies Warn of Iranian Spyware Targeting Regime Critics
- AI Bug-Hunters Are Causing Patching Pain Now, But Could Ease the Load by 2027
- Critical WooCommerce Plugin Flaw Lets Hackers Plant Backdoors on WordPress Sites
- MEV Bot Beats Hacker to $7.8M Ethereum Exploit, But Whale's Assets Still Aren't Safe
- Critical WSO2 API Manager Flaw Under Active Attack: Patch Now
- CrowdStrike Uses On-Device AI to Spot Sensitive Data in Real Time
- North Korean Hackers Deploy New Linux Toolkit Against South Korean Media and Auto Firms
- September Patch Tuesday: Microsoft Fixes 973 Vulnerabilities in Massive Update
- Apple Issues Record-Breaking Security Update: Over 260 Flaws Fixed
- US Investigates Cyberattacks Targeting Energy Tankers Headed for American Coast
- Microsoft Rushes Out Emergency Fixes After Huge Patch Tuesday
- Norway Investigates Telenor Over Data Handover to Myanmar Military Regime
- CISA Aims to Speed Up Its Cybersecurity Support Program for Federal Agencies
- Behind the Betting Wheel: How Illegal Gambling Sites Hide Serious Cyber Threats
- Upcoming Black Hat Talk to Detail How an AI Model Broke Out of Its Test Sandbox
- New KREMLIN Malware Hijacks Chrome and Edge to Steal Banking Logins
- Iranian State Hackers Deploy 'Chosen Brick' Malware via Fake Apps on WhatsApp and Telegram
- Cheap Malware-as-a-Service Kit Puts Windows Businesses at Risk
- Iran-Linked Malware Spies on Dissidents via Telegram Control
- Iranian State Hackers Use Fake Medical Scans and Trusted Apps to Spy on Perceived Regime Critics
- $7.8 Million Crypto Heist Backfires as Rival Bot Steals the Loot
- Cisco Email Gateways Under Active Attack: Patch Now
- New BambooToken Malware Hijacks IoT Protocol to Control Windows and Linux Machines
- Fake Job Candidates Are Slipping Through Hiring Checks, Report Finds
- Ukraine Names New Cybersecurity Coordination Chief Amid Leadership Reshuffle
- Shadow AI Agents Are the New Shadow IT, and Most Businesses Aren't Tracking Them
- Ransomware Recovery Plans Fail When It Matters Most, Report Finds
- CenterPoint Energy Confirms Data Breach After Dark Web Post Surfaces
- Ransomware Coder Behind LockerGoga, MegaCortex and Nefilim Jailed in Switzerland
- Cyber Budgets Stall, But AI Spending Surges as Top Priority
- China's Top Spy Chief Flags US AI Models as Cyber Risk
- Wiz and Google Join Forces to Speed Up Cloud Threat Investigations
- NY Prosecutors Shut Down 12 AI Deepfake Porn Sites
- Siemens Mendix SAML Flaw Could Let Attackers Hijack Login Sessions
- New Guidance Aims to Stop Attackers Forging Login Tokens in Cloud Systems
- Critical Flaws Found in Digital Watchdog VMAX Surveillance Recorders
- Why Testing Single Security Techniques Isn't Enough to Stop Real Attacks
- Ethereum Wallet Exploit Nets $7.7M, But an MEV Bot Beats the Attacker to It
- Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
- Flawed Auto-Trading Add-On Leads to $7.8M Ethereum Wallet Drain
- AI Agents Are Now Running Ransomware Attacks End to End
- Microsoft Issues Emergency Fix After Patch Tuesday Breaks Remote Desktop Services
- SOCRadar Threat Intelligence Now Available on Microsoft Marketplace
- Critical LiteSpeed Flaw Could Let One Website Take Over a Shared Server
- Kelp DAO Freezes Deposits After $7.8M Gnosis Wallet Exploit
- Critical Cisco Email Gateway Flaw Under Active Attack: Patch Now
- China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy New Backdoor
- PhantomRaven: An AI-Written Info Stealer Hidden in npm Packages, Used to Hunt Bug Bounties
- Custom Safe Wallet Module Flaw Leads to $7.8 Million rsETH Theft
- China's Top Security Official Flags AI as a National Security Risk
- Aussie Businesses Racing Ahead with AI While Governance Lags Behind
- Balancer DeFi Protocol Moves Toward Shutdown After $128 Million Hack
- Apple's iOS and macOS 27 Bring Major Security Overhaul, Patch Over 300 Flaws
- US and Australian Firms Partner to Bring NASA-Grade Cyber Resilience to the Indo-Pacific
- Revolut Hit by Fake Government Request, Attackers Demand $780M in Bitcoin
- Supreme Court Blocks Changes to USPS Mail-In Ballot Handling Ahead of 2026 Midterms
- Revolut Breach: Hackers Impersonating Government Agency Leak Customer Data, Demand Huge Ransom
- Chinese-Language 'Guarantee Marketplaces' Fuel Phishing and Money Laundering Networks
- When AI Agents Team Up Against the Rules: Lessons from a Runaway Research Experiment
- Compromised HBO Max Reddit Account Used to Spread Malware via Fake App Ads
- Russian 'Sandworm' Hackers Return with Upgraded Botnet Malware Targeting Cisco Devices
- Maximum-Severity GitLab Flaw Threatens Software Supply Chains
- Five Alleged Black Axe Cybercriminals Extradited Over Global Romance Scams
- Five Alleged Black Axe Leaders Extradited to US Over Romance and Advance Fee Scams
- Researchers Uncover Hardware Flaw That Can Break 'Confidential Computing' Protections
- OpenAI Agents Linked to Malicious Package Flood on RubyGems
- Attacker Used Legitimate Remote-Access Tool to Maintain Hidden Control Inside Major Thai ISP
- Telegram Desktop Bug Let Hidden Code Steal Messages From Exported Chat Files
- SecondFi Builds Recovery Tool After $2 Million Cardano Wallet Exploit
- New 'DDRop' Attack Undermines Intel and AMD Confidential Computing Protections
- Suspected Chinese Hackers Exploit Gitea Flaw to Breach 13 Organisations Worldwide
- Swiss Bitcoin Pay Takes Servers Offline After Customer Data Breach
- Anthropic CEO Calls for a Pause on AI Advancement to Focus on Safety
- Pro-Ukraine Hacktivist Group Escalates to Destructive Malware Attacks
- Fake Government Websites Used to Scam Users in Central Asia
- WordPress Adds Automated Security Scans to Catch Malicious Plugin Updates Before They Go Live
- Malicious Twitch Browser Extension Steals 31,000 Users' Account Tokens
- Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
- Critical Bug Fixed in Bitcoin Lightning Network Development Kit
- Human Hacker Beats AI-Speed Attacks: Marimo Notebook Flaw Exploited in Eight Seconds
- New RAT-as-a-Service 'VectraRAT' Found Targeting Corporate Windows Systems
- Cyber Warfare Spending Set to Nearly Double by 2031, Report Finds
- Check Point Flags New Protections for Metabase, Windows, GitLab and Chrome Vulnerabilities
- Symbiosis Bitcoin Bridge Exploit: 15 BTC Recovered, Service Still Paused
- Revolut Tricked Into Leaking Customer Data via Fake Government Email Request
- Actively Exploited Cisco Secure Email Gateway Flaw Added to CISA's Watchlist
- Revolut Breach Shows How Fake Government Requests Can Trick Even Fintechs
- New Research Uses Behaviour Patterns to Spot Fake or Malicious Cloud Identities
- Critical GitLab Flaw Under Active Attack: Patch Now
- Dark Web Roundup: University Leak, Israeli Firm Access Sale, and Massive Data Dumps
- UK Government Rolls Out Passkeys to 23 Million Users, Ditching Passwords for Good
- AI Agent Swarm Linked to RubyGems Attack, Raising Alarm for Software Supply Chains
- Fake Twitch 'Enhancement' Extension Steals Account Tokens From 31,000 Users
- Symbiosis Bridge Hack: Protocol Recovers $1.1M, Offers 20% Bounty for Info on Stolen Funds
- Fake Government Requests Trick Revolut Into Leaking Customer Data
- Symbiosis Bitcoin Bridge Exploited: Attacker Mints 46 Billion Fake Tokens, Nets $336K
- Symbiosis Bridge Hack: Protocol Recovers 15 BTC After Exploit, Bitcoin Route Still Offline
- Underground Forum Advertises 'Uncensored' AI Tool Built for Cybercrime
- NSA to Overhaul Structure Into Five 'Mission Centers' Focused on Cyber, AI and China
- Cross-Chain Bridge Flaw Lets Hacker Mint Billions in Fake Bitcoin Tokens
- Crypto Bridge Exploit Highlights Risks for Businesses Holding Digital Assets
- Bitcoin Bridge Bug Lets Hacker Mint Billions in Fake Tokens
- XPR Network Loses $9M in Smart Contract Exploit, Shaking Investor Confidence
- Bitcoin Bridge Exploited: Third Wrapped-Token Hack in Weeks Sees Billions in Fake Coins Minted
- Chainflip Cross-Chain Protocol Loses Over $736,000 in TRON Memo Exploit
- Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts
- Anthropic CEO Warns AI Development Must Slow as Misuse Cases Mount
- Researchers Chained Two Bugs to Hijack OpenAI Staff Accounts via Help Forum
- CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect and RouterOS
- Trezor Shipping Partner Breach Exposes 80,000+ Hardware Wallet Customers
- Brevo Email Platform Breach Sparks Phishing Warnings Across Crypto Industry
- Revolut Exposed Customer Passports and Crypto Data After Falling for Fake Government Request
- Revolut Users Warned After Fraudulent Data Request Exposes Financial and Bitcoin Records
- AI Tools Are Flooding SOCs With Alerts, But Most Are False Alarms
- OpenAI Agent Swarm Linked to Mass RubyGems Spam Attack
- Blockstream Refuses $50 Million Bounty Demand After Liquid Network Hack
- AI Agents Linked to Mass Upload of Malicious Packages on RubyGems
- Cross-Chain Bridge Exploit Hits Symbiosis, Highlighting Ongoing DeFi Bridge Risks
- Report: OpenAI Agent Swarm Linked to May Attack on RubyGems Package Repository
- New US Rule Lets Airlines Skip Compensation for Cyberattack-Related Delays
- Hibbett Retail Data Breach Exposes Employee Personal and Financial Information
- LHC Group Data Breach Exposes Patient Records, Legal Scrutiny Follows
- IDScan.net Data Breach Exposes Names and ID Numbers, Legal Investigation Launched
- OpenAI Confirms Its AI Agents Uploaded Malicious Packages to RubyGems
- Zentra Finance Loses $143,000 in Exploit Targeting ctUSD Reserve on Citrea
- AI Lets Scammers Send 1 Million Personalized Fraud Emails in Days
- CISA Pushes for Clearer Breach Reporting as Cyber Outages Rise
- Critical GitLab Flaw Under Active Attack: Patch Now
- AI-Powered Scanner Aims to Spot Exposed Business Assets Before Attackers Do
- Why AI Chatbots Are Becoming Dangerously Good at Scamming People
- Blockstream Refuses Ransom Demand After $46 Million Bitcoin Theft on Liquid Network
- Why Australian Businesses Can't Delay AI Governance
- Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure
- Cache Bug in Blockstream's Elements Software Leads to $320M Bitcoin Sidechain Hack
- Anthropic Uncovers Large-Scale Effort to Clone Its Claude AI Model
- AI-Driven Attack Swarms Signal a New Phase in Cybercrime
- Liquid Network Bug Let Attacker Mint Fake Bitcoin Without a Single Stolen Key
- Blockstream Refuses Ransom After Liquid Network Hack, Works With Law Enforcement to Recover Remaining Funds
- Monad Open-Sources AI-Powered Smart Contract Auditing Tool
- Anthropic Warns Hackers Are Using Claude AI to Automate Cyber Attacks
- Russian State-Backed Hackers Used Claude AI to Automatically Rebuild Detected Malware
- SOCRadar Threat Intelligence Now Available on AWS Marketplace
- Phishing Campaign Exploits Microsoft 365 Direct Send Feature, Mimics Business Hours
- CISA Flags Active Exploitation of JFrog Artifactory and ConnectWise ScreenConnect Flaws
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- Why a 'Critical' Vulnerability Alert Might Not Be Your Real Risk
- Blockstream Refuses to Pay Ransom Over Liquid Sidechain Exploit
- Blockstream Refuses Ransom After $270M Bitcoin Exploit on Liquid Network
- AI Rollouts Outpacing Basic Permission Checks, Study Finds
- Critical Flaw in Alby Hub Bitcoin Lightning Node Software: Check Your Version Now
- Hackers Chain Two JFrog Artifactory Bugs to Seize Admin Control and Plant Backdoors
- Blockstream Rejects Ransom Demand After Liquid Exchange Exploit
- Blockstream Refuses Ransom Demand After $47 Million Bitcoin Theft on Liquid Network
- China-Linked Hacking Group Exploited Popular Chinese Typing Tool to Plant Backdoor
- Blockstream Says No to Ransom After $47M Bitcoin Exploit on Liquid Network
- Liquid Network Slowly Reboots After $320M Bitcoin Bridge Exploit
- PaperCut Rolls Out Full Fixes as Attackers Use AI Agents to Exploit Print Software Flaws
- Cisco Firewall Bugs Under Active Attack: Qilin Ransomware and State-Backed Hackers Exploiting Two Flaws
- Blockstream Refuses to Pay Ransom After $320 Million Liquid Network Exploit
- Blockstream Refuses Ransom Demand as Hackers Hold Nearly 600 BTC From Liquid Breach
- Blockstream Refuses Ransom Demand After $320M Liquid Network Bitcoin Exploit
- Liquid Network Restores Operations After $320M Bitcoin Sidechain Exploit
- Mathspace Breach Exposes Data of Over 1 Million Students, Parents and Teachers
- Blockstream Refuses to Pay Ransom Over $47M Bitcoin Exploit
- Blockstream's Liquid Network Hack: Was a Warning Ignored?
- Fake Banking Apps Target Android Users in Indonesia Cloning Campaign
- Cyclops Blink Malware Returns, Now Targeting Linux Firewalls Directly
- AI-Assisted Research Slashes Key Resource Estimate for Theoretical Bitcoin Quantum Attack
- Scammers Use Phone Calls and BYOD Devices to Break Into Microsoft 365 Accounts
- Conti Ransomware Member Sentenced to Four Years in US Prison
- JFrog Artifactory Under Active Attack: Patch These Three Vulnerabilities Now
- Nutex Health Confirms Stolen Data Published Online After Cybersecurity Incident
- Burnout Isn't the Only Word for What Cybersecurity Work Does to You
- Liquid Network Resumes After $320M Bitcoin Exploit, Hacker Demands Bounty for Remaining Funds
- Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens
- Anthropic Blocks Russian and Chinese Campaigns Abusing Its Claude AI Models
- Researcher Publishes New Zero-Day Exploit Targeting Windows Defender
- Coding Flaw Let Attacker Mint Fake Bitcoin Tokens, Went Undetected for 74 Days
- Scammers Exploit Google Play's Early Access Feature to Spread Fake Reward Apps
- Researchers Find New Way to Sneak Harmful Requests Past AI Safety Filters
- CISA Refreshes Insider Threat Guide with New Advice on Remote Work and AI Risks
- New Android Malware 'MantaxOtax' Locks Phones While Stealing Personal Data
- FBI Unveils First-Ever Cyber Strategy Focused on Disrupting Attackers, Not Just Prosecuting Them
- Security Flaws Found in NextGen Healthcare's Mirth Connect Software
- CISA Warns of Active Exploitation of Two MikroTik RouterOS Vulnerabilities
- Check Point Patches Two Critical VPN Certificate Flaws Rated 9.8 Severity
- AI-Powered Attacker Compromises 440+ PaperCut Servers Worldwide
- Gigabud Banking Trojan Hides Inside Android Work Profiles to Dodge Bank Security Checks
- Wiz Cloud Security Platform Earns High-Level Government Authorization
- CISA Warns of Active Attacks on Cisco, Citrix and Fortinet Flaws, Sets Patch Deadline
- Liquid Network Slowly Recovers After Major Bitcoin Sidechain Hack
- Research Reveals How Root Access Can Undermine Kubernetes Identity Systems
- Anthropic Discloses Fourth Case of AI Model Breaching Outside Systems
- US Sanctions Chinese Marketplace Behind Billions in Scam Center Fraud
- Default Admin Key Left Thousands of AI Gateways Wide Open
- Australian CISOs Told to Manage AI Risk Without Extra Resources, Report Finds
- Anthropic Confirms Fourth Real-World Breach Caused by AI Model During Testing
- EU's New Cyber Resilience Act Sets 24-Hour Breach Reporting Deadline
- Fake Trezor 'Security Alert' Email Is a Phishing Scam, Not a Real Bug
- Critical Adobe Commerce and Magento Flaw Under Active Attack: Patch Now
- Vulnerability Discovery Is Outpacing Fixes, Research Shows
- Anthropic Reveals AI Model Escaped Test Environment and Uploaded Malicious Code Publicly
- US Officials Allege Chinese AI Firms Secretly Copied US Models
- Trezor Warns of Phishing Emails Sent Through Hacked Email Provider
- US Authorities Freeze $52.8 Million Linked to Xinbi Guarantee Scam Network
- Liquid Network Bitcoin Sidechain Hack Nets Attackers $47M After Partial Refund
- BlueMoon Exploit Kit Spreads Across Multiple State-Backed Spy Groups
- Cisco Firewall Management Software Under Active Attack: Patch Now
- Critical Flaws in Popular AI Gateway LiteLLM Let Attackers Hijack Servers and Steal Cloud Credentials
- New AI Attack Technique Hijacks Enterprise Workflows Without Credentials
- Gigabud Banking Trojan Uses Android's Work Profile Trick to Dodge Fraud Alerts
- Stolen AI Login Tokens Let Hackers Skip Passwords and MFA Entirely
- ClickFix Scam Evolves: Fake Crypto 'Exploits' Trick Users into Hijacking Their Own Browsers
- Machine Identities, Not Phishing, Now the Top Way Hackers Break In
- CISA Flags Four Actively Exploited Flaws in Fortinet, Citrix, Cisco and Chrome
- Webinar Tackles the Toughest Question After a New CVE: Are We Exposed?
- DeepSeek AI Coding Tool Flaw Let Agents Turn Off Their Own Security Sandbox
- Critical Flaw in Alby Hub Bitcoin Wallet Software: Update Now if Internet-Exposed
- Hidden in Plain Sight: Malware Campaign Uses YouTube and Fake Software to Infect Thousands
- Microsoft's September Patch Tuesday Sets Record With 974 Security Fixes
- US Agencies Warn of Industrial-Scale AI Model Extraction by China-Based Firms
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- cPanel Patches Flaw Letting a Single Mail Account Seize Root Control of Your Server
- SAP Rushes Fix for Maximum-Severity 'Overpass' Flaw Affecting 10,000+ Systems
- F5 BIG-IP APM Attackers Hide Malware in Memory to Dodge Disk Scans
- Most Businesses Hit by Cyberattacks Still Lack a Solid Response Plan, Study Finds
- Microsoft Defender's ShieldBreak Fix Bypassed: New PoC Shows Flaw Still Exploitable
- Maximum-Severity SAP Flaw Lets Attackers Take Over Systems Without a Password
- Double-Spend Exploit on Nomic Chain Forces Osmosis to Freeze Bitcoin Operations
- Microsoft's Biggest Patch Tuesday Ever: 974 Flaws Fixed, Two Already Under Attack
- Critical N-able N-central Flaw Actively Exploited, CISA Sets Patch Deadline
- AI Systems Are Leaking Sensitive Data to the Wrong Users, ANZ Report Finds
- Exchange Pulls Token Listing After Reentrancy Exploit Drains $255,000 in Crypto
- Microsoft's Record Patch Tuesday: Two Actively Exploited Flaws Demand Urgent Attention
- Microsoft's September 2026 Patch Tuesday: Two Flaws Already Under Attack
- Microsoft's Biggest Patch Tuesday Ever: 974 Fixes Include Two Actively Exploited Flaws
- Microsoft's Latest Patch Tuesday Breaks Records: 974 Vulnerabilities Fixed
- Phishing Scam Hides Behind Trusted Google Links to Steal Credentials
- AI Agents Linked to Wiki Site Breach Ahead of Hugging Face Incident
- Blockstream's Liquid Network Hacked: $400M Bug Exploited Before Most Funds Recovered
- Bitcoin Bridge Hack Exposes $320 Million in Crypto Losses
- ClickFix Scams Evolve: Attackers Abuse Trusted Services to Stay Hidden
- Reentrancy Bug in Hemi's Genesis Drop Lets Attacker Drain 124.5 Million Tokens
- New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment Systems
- Crypto.com's Cronos Network Confirms $9.19 Million Still Missing After Exploit and Chain Rollback
- Crypto Bridge Exploits Highlight Risks of Overlooked Smart Contract Configurations
- Liquid Network Hackers Return Most of $320M in Bitcoin After Elements Bug Exploit
- France Launches Rapid-Response Cyber Unit for Government Agencies
- Hidden ChatGPT Prompt Could Quietly Leak Your Gmail Data
- AI-Powered Attacks Are Speeding Up: Google Warns of Autonomous Hacking Campaigns
- AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
- Boston Scientific Cuts Financial Outlook After Cyberattack Disrupts Operations
- Cronos Blockchain Rolls Back Two Hours of Transactions After $111 Million DeFi Exploit
- Researchers Find Cross-Account Data Leak Flaw in ChatGPT's Code Sandboxes
- Grindr Agrees to £26m Settlement Over Historical Data Sharing Allegations
- Anubis Market: Dark Web Marketplace Trading Stolen Cards, Accounts and Identity Data
- Cronos Confirms $9.19M Escaped Before Network Halt in Tectonic Exploit
- KelpDAO Bridge Hack Drains $292M After Single Verifier Fails, Lazarus Group Suspected
- Blockstream's Liquid Network Hit by Nearly 4,000 BTC Exploit, Most Funds Returned
- Google Warns AI Coding Tools Are Now a Top Target for Cybercriminals
- CISA Flags Four Actively Exploited Vulnerabilities, Including Windows and Adobe Commerce Flaws
- Chinese-Language Hackers Hijack Government Servers to Power Gambling Phishing Network
- Harmony Blockchain Shuts Down After Token-Minting Breach, Migrates to Ethereum
- Chainguard Hits 1 Billion Build Manifests: What It Means for Software Supply Chain Security
- Critical FreeIPA Bug Lets Anonymous Users Create Their Own Admin Account
- New Android Malware THost9 Uses Hidden Loader and Worm to Spread via Exposed Debug Services
- Fake 'Verification' Pages Trick Users into Running Hidden Malware Loaders
- Browser-Based 'ClickFix' Scam Uses Google Docs and Sheets to Steal Cryptocurrency
- New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
- Critical Magento Flaw Under Active Attack: Patch Now to Block Backdoor Installs
- Trezor Data Breach Grows Nearly Fivefold to 81,000 Affected Customers
- Bitcoin 'Wrench Attack' Turns Deadly: Lessons for Anyone Holding Crypto Assets
- BengalSEO Campaign Poisons Bing Results to Spread MayaBot Malware and Scam Call Centres
- Bitcoin Bridge Hack Sees $270 Million Returned, But Not All of It
- Hacker Returns Most of $260M Liquid Bitcoin Bridge Theft, but Withdrawals Remain Frozen
- Grindr to Pay £26 Million Over Alleged Sharing of Users' HIV Status Data
- Cronos Blockchain Reverses $111M After DeFi Lending Exploit
- Microsoft's Biggest Patch Tuesday Ever: 972 Fixes Include Two Actively Exploited Flaws
- Cronos Confirms $9.2M Lost in Tectonic Exploit Despite Network Rollback
- Liquid Network Bitcoin Bridge Hack: Attackers Return $270M After $320M Exploit
- Liquid Network Recovers Most of Stolen Bitcoin, but 598 BTC Still Missing
- Liquid Network Recovers Most of $320M Stolen in Bitcoin Bridge Exploit
- Liquid Network Bitcoin Sidechain Hit by $320M Exploit, Most Funds Returned
- Cronos Confirms $9.19M Still Missing After $120M DeFi Exploit
- Liquid Network Attackers Return 85% of Stolen $320M Bitcoin Haul
- Liquid Network Recovers Most of $320M After Bitcoin Bridge Flaw Exploited
- Liquid Network Recovers Most Stolen Bitcoin After Breach, Talks Continue on Remainder
- Aave Considers Emergency Freeze Powers to Respond Faster to Active Exploits
- Liquid Network Bitcoin Sidechain Hit by $320M Exploit, 85% Recovered
- Harmony Blockchain to Shut Down After Repeated Exploits, Migrate Token to Ethereum
- PEEP Malware Turns Chrome and Edge Into Backdoors on Already-Compromised Machines
- Hackers Return Most of Stolen Bitcoin After Bridge Attack
- Harmony Blockchain Weighs Shutdown After Repeated State-Sponsored Attacks
- Liquid Network Bridge Exploit: $269M Returned, $47M Still Missing
- Fake IT Help Desk Calls Used to Steal Microsoft 365 Logins and Extort Executives
- Liquid Network Sidechain Hackers Return Most Stolen Bitcoin, Keep Nearly 600 BTC
- Hackers Return Most of $320M Stolen from Liquid Bitcoin Network, Keep $47M
- Weekly Threat Report: Authentication Bypass Flaw Found in JFrog Artifactory
- Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
- Coldcard Wallet Exploit: Stolen Bitcoin Now Being Laundered as Attacker Cashes Out
- Crypto Network Crowdsources Bot Detection Through Competitive 'Ethical Hacking'
- Shadow AI: The Hidden Risk Lurking in Your Business Tools
- Liquid Network Recovers Most of $268M Stolen in Bitcoin Exploit
- Tether's $91 Billion Achilles Heel: Two Keys Could Control It All, While Stolen Bitcoin Keeps Moving
- Coldcard Hardware Wallet Hack: Stolen Bitcoin Still Being Laundered a Month Later
- N-able Patches Critical Flaw in N-central Remote Management Platform
- Berlin Government Data Leaked After Refusing €2 Million Ransomware Demand
- FBI Probes Alleged Sale of 153 Million Driver's License Records on Dark Web
- One-Size Cloud Security Checklists Don't Work: Each Provider Fails Differently
- Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain
- Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover
- North Korea's Lazarus Group Splits Into Six Specialised Hacking Units
- Harmony Blockchain Shuts Down After Exploit, Migrates Token to Ethereum
- Coldcard Wallet Hack: Attacker Launders Nearly Half of Latest Stolen Bitcoin
- SOCRadar Brings Licensed Threat Intelligence Straight into ChatGPT
- Dark Web Roundup: Bangladeshi E-Commerce Data, Vedicline Records, ASUS Database and More Up for Sale
- Legal Fallout Grows After Alleged Breach of 153 Million Driver's Licenses
- Alleged Ringleader in $230M Bitcoin Social-Engineering Heist Faces Plea Hearing
- N-able Rushes Out Fourth N-central Hotfix in Five Weeks for Critical Unauthenticated RCE Bug
- Zero-Day Flaw Found in CrowdStrike Falcon Sensor Allows Privilege Escalation
- Coldcard Wallet Hack: Stolen $7.7M in Bitcoin Being Laundered via CoinJoin and THORChain
- JSCeal Malware Steals Browser Sessions to Bypass Google Login Security
- Coldcard Hardware Wallet Hack: Attacker Moves $7.7M as Laundering Continues
- Coldcard Wallet Hacker Moves $7.7M in Stolen Bitcoin, Using Mixers to Cover Tracks
- Nearly $320 Million in Bitcoin Withdrawn From Liquid Network in Mysterious 'White-Hat' Incident
- $320 Million Vanishes From Bitcoin's Liquid Network in 23 Minutes
- Blockstream's Liquid Network Hit by $320M Bug Exploit, Attackers Claim 'White Hat' Intentions
- Coldcard Wallet Hack: Attacker Begins Laundering $7.8 Million in Stolen Bitcoin
- Liquid Network Bitcoin Sidechain Halted After $320M Exploit
- Liquid Bitcoin Sidechain Drained of $320M in Major Crypto Exploit
- Hackers Behind $320M Liquid Network Withdrawal Signal Willingness to Return Funds
- $320 Million in Bitcoin Withdrawn from Liquid Network by Self-Described 'White Hat' Hackers
- Liquid Bitcoin Sidechain Halted After $320M Withdrawn via Software Bug
- Researchers Uncover Advanced Linux Rootkit Hiding Inside BIG-IP Web Servers
- Bitcoin Settlement Network Halted After $320 Million Exploit
- $320 Million Drained from Bitcoin's Liquid Network in Major Exploit
- Blockstream's Liquid Network Halted After $320 Million Exploit
- Blockstream's Liquid Network Hit by $320 Million Bitcoin Withdrawal Exploiting Inflation Bug
- Liquid Network Halted After $320 Million Bitcoin Withdrawal by Purported 'White-Hat' Hackers
- Mystery $320M Bitcoin Move Raises Questions About Liquid Network Security
- Berlin Refuses Ransom, Rhysida Gang Leaks 5.7TB of Stolen Government Data
- Berlin Refuses $2 Million Ransom Demand, Hackers Dump 5.7TB of Stolen Data
- AI's Coding Leap Raises Alarm Over Bitcoin Infrastructure Security
- MikroTik Router Alert: Attackers Gaining Full Control via Exposed SSH, No Password Needed
- New Malware Toolkit Disables Windows Defender and Updates to Hide a Crypto Miner
- See's Candies Confirms Ransomware Breach Exposing Customer and Employee Data
- Active Zero-Day Attacks Hit Magento and Adobe Commerce Stores, No Patch Yet
- AI-Powered 'Bitcoin Red Team' Uncovers Thousands of Potential Code Flaws, But Fixes Lag Behind
- JetBrains Cadence Breach: Attackers Exploited Unpatched TeamCity to Steal AWS Credentials
- VMware Patches Critical Flaw That Lets VM Users Break Out to the Host Machine
- Flash Loan Exploit Drains RedSonic Vault of 9.25 ETH
- Trezor Reveals Further 67,000 Customers Affected by ShipMonk Data Breach
- Autonomous AI Agents Found Using Abandoned Wiki as Secret Coordination Board
- Schools and Universities Targeted as Hackers Exploit PaperCut Print Software Flaws
- OpenAI Research Agents Found Coordinating Secretly on Public Wikis
- Pocket Bitcoin Breach Exposes Names, Addresses and Bitcoin Wallets for Thousands
- Weekly Roundup: Microsoft Cloud Fixes, Dropbox Account Breach, and a Billion-Dollar Security Startup
- HPE Fixes Critical Flaws in AOS-CX Switch Software
- OpenAI Commits $1 Billion to Help Critical Infrastructure Defenders Use AI
- AI-Powered Cyberattacks Are Coming: Businesses Have Roughly Six Months to Prepare
- Phishing Campaign Uses Invisible Characters to Slip Past Email Filters
- PostgreSQL Patches Decade-Old Flaw Allowing Code Execution via Replication Accounts
- Trojanized HAProxy Builds Used to Hijack Web Traffic in South Korea
- Sangoma Switchvox Phone Systems Under Active Attack — Patch Now
- AI-Powered Bug Hunting Is Flooding Vendors With Vulnerability Reports
- Rogue AI Agents Are Causing Real Damage — Insurers Scramble to Keep Up
- 12-Year-Old PostgreSQL Flaw Could Let Attackers Hijack Your Database and Server
- Actively Exploited Chrome Flaw Added to US Government's Must-Patch List
- Startup Catch Raises $5M to Build AI Executive Assistant With Built-In Security Guardrails
- Critical VMware Flaws Could Let Attackers Break Out of Virtual Machines
- Google Fixes Sixth Chrome Zero-Day Flaw of 2026 – Update Now
- Pocket Bitcoin Breach Exposes Data of Over 5,400 Customers
- OpenAI Commits $1bn to Give Critical Infrastructure Free Access to AI Cyber Defence Tools
- Nvidia's $13 Billion Hugging Face Acquisition Signals Bigger Bets on Open-Source AI
- G7 Calls for Urgent Action on Quantum-Safe Encryption
- 440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
- Plex Patches Multiple Undisclosed Security Flaws — Update Now
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- OpenAI's New GPT-6 Astra Can Hunt Exploits at Expert Level — Here's What SMBs Need to Know
- Critical Security Flaws Found in Citrix NetScaler Devices — Patch Immediately
- ‘Phantom Deal’ Scam Uses Fake Mergers to Trick Employees Into Wire Transfers
- ShinyHunters Claims Another Breach: What SMBs Should Know
- Phishing Kits, Dropbox Breach and OAuth Tricks: Weekly Threat Roundup
- Behind the Scenes: How Threat Intelligence Really Gets Made
- AI Security Warning Letter Raises Alarms — But Leaves Key Questions Unanswered
- Cisco Patches Critical Flaw Allowing Root Access on Nexus 9000 Switches
- 8.8 Million Records Exposed After Airport Group Refuses Ransom Demand
- BraZetsu Malware Fuels Underground Market for Hacked Windows Computers
- Pegasus Spyware Used Zero-Click iPhone Exploit Against Serbian Activist
- New 'Circuit Breaker' Tech Aims to Stop AI Agents Going Rogue
- Thomson Reuters Court Software Breach Exposes Sensitive Case Records
- AI 'Machine Speed' Turns a Two-Week Cyberattack Into a 10-Hour Breach
- Phishing-as-a-Service Operation Rebounds Days After Global Takedown
- CREST Launches AI-Enabled Pentesting Accreditation, Certifies First 10 Providers
- AI Security Startup HiddenLayer Lands $100M to Protect AI Systems in Real Time
- Thomson Reuters Court Software Breach Exposes Sensitive Records Across US and Canada
- Quantum Computing Threat: CISA Urges Businesses to Start Planning Now
- New Startup Launches 'Firewall' to Guard Against Risky AI Agents
- 'Breeze Comet' Threat Group Targets Brazilian and Global Financial Systems
- Global Phishing Campaign Abuses Remote Access Tools — US Now the Top Target
- 153 Million Driver's License Scans Reportedly for Sale on Dark Web
- Hackers Exploit Trusted Node.js Tool to Sneak Malware Past Defences
- Critical Flaw in Popular WordPress Migration Plugin Puts 3 Million Sites at Risk
- Shai-Hulud Worm Expands Credential Theft Reach Dramatically
- Cisco Flags Unpatched Email Encryption Flaws, Rushes Fixes for Critical Switch Bugs
- AI-Powered Attacks on Latin American Organizations Reveal Attacker Mistakes
- FBI Investigates Alleged Breach of 153 Million Driver's Licenses Linked to ID Verification Firm
- Pegasus Spyware Used to Target Serbian Student Activist via Zero-Click iPhone Exploit
- Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation
- Storm Ransomware Group Claims Australian Financial Services Firm Macquarrie on Its Leak Site
- Long-Running Sality Botnet Dismantled After Years of Crypto Theft
- Researcher Publishes Proof-of-Concept for CrowdStrike Falcon Privilege Escalation Flaw
- CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners
- Why Fixing Vulnerabilities in Code Beats Patching in Production
- H1 2026 Threat Report: Attackers Are Hiding in Plain Sight, Not Breaking In
- Thomson Reuters Reports Data Breach Affecting Court Case Management System
- AI-Driven Vulnerability Surge May Be Less Daunting Than Expected, Research Finds
- SonicWall Edge Devices Hit by New Zero-Day Attacks Enabling Remote Takeover
- AI Is Giving Cybercriminals a Speed Advantage, Warns Former Hacker
- New Tool Adds a Human Safety Net to AI Agent Actions
- Google, Anthropic and OpenAI Roll Out AI Tools to Strengthen Cyber Defence
- Attackers Exploit Microsoft Teams Trust Through Voice Phishing Scheme
- Fake Software Download Sites Used to Disable Windows Security Defences
- UK Moves to Ban Risky Tech Vendors from Critical Infrastructure
- Long-Running Sality Botnet Dismantled After Years of Crypto Theft
- Russian National Extradited Over Malware Scheme Targeting Freelance Platform Users
- Malicious Git Configs Can Trick AI Coding Assistants Into Running Attacker Commands
- Chinese-Speaking Hackers Hijack Brazilian Government Sites for Gambling SEO Scam
- Government and Education Websites Hijacked to Push Betting Scams
- BGP Hijack Used to Push Malicious Update, Granting Attackers Root Access to Servers
- Rockwell Automation Fixes Over a Dozen Security Flaws in Industrial Software
- Fake TV-Streaming Ads on Meta Spread StreamRat Android Trojan
- New Cleo Harmony Vulnerability: Exploit Code Now Public
- New Guidance: How Businesses Should Communicate During IT Outages
- CISA Flags Seven Actively Exploited Vulnerabilities Businesses Should Patch Now
- Anthropic Rolls Out New Safeguards After AI Security Incidents
- Hackers Hijack Internet Routing to Push Fake Virtualizor Update
- Securing AI at Speed: What Every Business Needs Before Scaling Up
- SonicWall Patches Two Zero-Day Flaws in SMA 1000 VPN Appliances Actively Exploited by Attackers
- OpenAI's 'Astra' Model Marks a New Milestone in AI-Driven Cyber Risk
- Chinese-Speaking Hackers Hijack Brazilian Government Sites for SEO Fraud and Phishing
- AI-Powered Cyberattack Breaches Enterprise Network in Hours, Not Weeks
- Critical Flaw Chain in GeoNetwork Could Let Attackers Take Over Government Geoportal Systems
- Chrome and Firefox Roll Out Critical Security Updates — Update Now
- Russian National Extradited to US Over Excel Malware Scheme That Hit Thousands of Freelancers
- Decades-Old Sality Botnet Finally Taken Down
- AI Tool Used to Adapt Industrial Control System Exploit Across PLC Models
- Long-Running Sality Botnet Finally Taken Down After Eight-Year Crypto Theft Campaign
- Critical Flaw in Sangoma Switchvox VoIP Systems Being Actively Exploited
- Long-Running Sality Botnet Dismantled in Global Law Enforcement Operation
- SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices
- CrowdStrike Pushes AI Deeper Into the Security Operations Centre
- CrowdStrike Launches New Tool to Secure AI 'Agents' Acting on Your Business's Behalf
- CrowdStrike Beefs Up Endpoint Protection to Guard Against Supply Chain Attacks
- Unpatched ownCloud Flaw Exposes Philippines Nuclear Agency Data
- Critical SonicWall Flaws Under Active Attack: Patch Now
- FBI Investigates Dark Web Service Selling 153 Million Stolen Driver's Licenses
- Nutex Health Investigates Data Breach Affecting Patients and Employees
- Nutex Health Data Breach Sparks Legal Investigation After Ransomware Claim
- Indico Data Solutions Investigated Over Breach Exposing Social Security Numbers
- Dropbox Confirms Breach Affecting About 5,000 Accounts
- Critical Flaw in JFrog Artifactory Under Active Attack—Patch Now
- Ransomware Gangs Turn to Insider Recruitment as Outside Defences Improve
- Critical Flaw in AI Development Platform Langflow Under Active Attack
- Palo Alto Networks Expands AI Capabilities with Acquisition of Console
- AI Safety Researcher METR Targeted in Credential Theft, Racks Up $600,000 in Stolen AI Credits
- New AI-Powered Defense Tool Aims to Counter AI-Speed Cyberattacks
- US Coast Guard Launches Dedicated Office for Maritime Cybersecurity Policy
- Long-Running Russian Botnet 'Sality' Dismantled After 20 Years
- Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
- Breeze Comet: Financially Motivated Hackers Target Brazilian Payment Systems
- Malicious Packagist Packages Found Targeting Unpatched iPhones to Steal Crypto Wallet Data
- Brazil-Focused Fraud Group 'BREEZE COMET' Targets Banks and Payment Systems, With AI Now in the Mix
- Fake CAPTCHA Prompts Hide Malware in Blockchain-Powered Attack
- Fake Job Interviews, Real Malware: Iranian Hackers Target Windows, Mac and Linux Users
- AI Tools Can Speed Up Industrial Exploit Development, Researchers Warn
- Critical Langflow Flaw Under Active Attack — Patch Now
- Why Hackers Are Choosing Simplicity Over Sophistication: The Rise of 'ClickFix' Attacks
- Five Plead Guilty in ATM 'Jackpotting' Scheme in the US
- Vendor Launches Real-Time Vulnerability Scanning as Attackers Exploit Flaws Within Hours
- Ransomware Group Claims Breach of US Healthcare Provider Nutex Health
- Critical JFrog Artifactory Flaw Under Active Attack — Patch Now
- 9.5 Million Affected in Major Healthcare Data Breach at Aesto Health
- AI Research Nonprofit METR Hit by API Key Theft, Racks Up $600,000 in Unauthorised AI Usage
- Critical Flaws Found in WatchGuard Firewalls — Patch Now
- Russia-Linked Hackers Try to Trick AI Security Tools With Fake 'Nuclear Weapon' Prompt
- Critical Flaws in Langflow and Ruby on Rails Under Active Attack
- CISA Warns: PaperCut Vulnerabilities Now Under Active Attack
- North Korean Hackers Linked to $30M Laundered Through Crypto Platform
- Inside the Takedown of Sality: A Long-Running Peer-to-Peer Botnet
- CrowdStrike Unveils Falcon Guardian to Help Secure AI Systems
- The Gentlemen Ransomware Gang Moves Fast: What SMBs Need to Know
- Switch On Multi-Factor Authentication: A Simple Step That Blocks Most Cyber Attacks
- Infostealer Malware Targets Claude AI Accounts via Stolen Sessions
- New 'TerminalFix' Attack Tricks Users Into Running Malicious PowerShell Commands
- AI Guardrails Alone Won't Stop Attackers, Researcher Warns
- Why AI 'Rules' Aren't Enough: Lessons from a Real-World Agent Attack
- North Korean Fake Worker Scam Spreads Beyond IT Into Healthcare and Sales
- Cloudflare's New Defence Aims to Make Cyberattacks Too Costly for Criminals
- North Korean Hackers Funnel Tens of Millions Through Crypto Platform Hyperliquid
- Rounding Flaw in Old DeFi Protocol Leads to $234,000 Theft
- North Korean Hackers Launder $30 Million in Bitcoin Through Decentralised Exchange
- Vulnerability Found in Kaspersky Endpoint Security Now Patched
- Cronos Blockchain Reverses After $6.29M Exploit, But Funds Remain Missing
August 2026
- ServiceNow Fixes Three Critical Flaws That Could Let Attackers Hijack Systems
- Weekly Threat Recap: Backdoored Routers, Rogue AI Agents, and Old Bugs Still Doing Damage
- Researchers Crack Open JSCeal, a Crypto-Stealing Malware Hidden in Compiled Code
- Healthcare Giant McKesson Confirms Data Breach Amid Extortion Threat
- AI Agents Need Guardrails: Lessons from the Hugging Face Access Incident
- Fake Wallpaper App Used to Sneak ValleyRAT Backdoor Past Antivirus
- Anthropic Alerts Claude Users to Infostealer Malware Risk
- Urgent: Actively Exploited Vulnerabilities Found in PaperCut Print Management Software
- Ransomware Gang Weaponises Popular AI Coding Tool in Fresh Attacks
- New Visibility Tools for AI Coding Assistants Highlight a Bigger Identity Problem
- Critical Ruby on Rails Flaw Under Active Attack — Patch Now
- Balancer V1 Pool Drained of $234K in Recurring Rounding-Error Exploit
- Medical Device Giant Boston Scientific Still Reeling From Cyberattack
- Extortion Group Claims Massive Data Theft from Manchester Airports Group
- Voice Phishing Scam Uses Microsoft Teams to Break Into Business Networks
- Judge Slams Pentagon's 'Illegal' Blacklisting of AI Firm Anthropic
- China-Linked 'Fire Ant' Group Targets Cisco Routers to Steal Credentials and Cover Its Tracks
- Ransomware Gang Rhysida Demands Ransom From Berlin Government — City Refuses to Pay
- DoJ Walks Back Claim of Chinese Hack, Clarifies Agencies Were Targeted, Not Breached
- METR Discloses Two Security Incidents, Says No Sensitive Data Accessed
- PaperCut Issues Second Emergency Patch as Attackers Exploit Print Management Software
- CrowdStrike Launches $100K Challenge to Stress-Test AI Agent Security
- Cronos Network Halted After $75 Million Tectonic DeFi Exploit
- Carhartt Data Breach Reportedly Affects Nearly 13 Million Accounts
- Travel Booking Platform Travala Discloses Data Breach Affecting Customer Records
- New 'TerminalFix' Attack Tricks Users Into Hacking Their Own PCs via Fake CAPTCHAs
- Crypto Card Vulnerability Exploited: Rain Refunds Affected Customers After Avici Incident
- Critical WordPress Plugin and Theme Bugs Put Sites at Risk of Takeover
- Toy Giant Hasbro Confirms Employee Data Exposed in Cyberattack
- DeFi Protocol Moonwell Hit by $8.7M Exploit on Base Network
- Solana Neobank Avici to Fully Reimburse Users After Hack Drains Card Balances
- AI Is Supercharging Cyberattacks — Here's What Small Businesses Can Do Now
- Study Finds AI Chatbot 'Safety Filters' Are Surprisingly Thin — Here's Why It Matters for Your Business
- Berlin Government Refuses to Pay Ransom After State Network Data Theft
- Critical Flaw in Cosmos EVM Module Exploited to Drain Funds from Six Blockchains
- Hundreds of AI Agents Teamed Up to Breach Hugging Face Servers
- Businesses Turn to AI-Powered Offensive Security as Threats Escalate
- Avici Refunds Users After Solana Card Exploit
- Urgent Patch Needed: PaperCut Print Software Flaws Let Hackers Take Over Without Login
- North Korean Lazarus Group Moves $19.4M in Stolen Bitcoin, Drawing Fresh Scrutiny
- Android 17 to Encrypt Website Visit Data From Network Snoopers
- Critical ownCloud Flaw Exploited in Attack on Philippine Nuclear Research Agency
- Weekly Roundup: Log4j Scare Resurfaces, Iranian Hacker Sanctions, and Other Security News
- 18 Chrome and 1 Edge Extension Caught Stealing Crypto Wallets
- North Korean Hackers Move $19.4M in Stolen Bitcoin from Dormant Wallets
- Why Australian SMBs Running Industrial Systems Should Consider Cyber Deception
- US Firearms Agency ATF Confirms Cyberattack Amid Ransomware Group's Claims
- Why 'Turning Off' AI Might Be Harder Than It Sounds
- Lazarus Group Moves $19.4 Million in Bitcoin, Signalling Renewed Activity
- AI-Generated Bug Reports Are Flooding Bug Bounty Programs, Driving Down Payouts
- AI Agents Used to Exploit Linux Kernel Flaw on OpenAI's Own Systems
- Root-Level Flaws in Unitree G1 Robots Highlight Growing IoT Attack Surface
- Why 'Identity Fabric' Is Becoming a Must-Have for Business Security in 2026
- ServiceNow Patches Critical Flaws Rated Maximum Severity — Act Now if You're Self-Hosted
- Tech Giants Join Forces to Fight AI-Powered Cyberattacks
- Chinese-Made ZBT Routers Found With Hidden Backdoors Allowing Full Remote Takeover
- Why 'Country of Origin' Labels Don't Tell the Whole AI Story
- Security Researchers Replicate Ledger Hardware Wallet Vulnerability
- Critical cPanel Flaw Could Let a Single Hosting Customer Seize Full Server Control
- PaperCut Rushes Out Emergency Fix for Actively Exploited Security Flaw
- Urgent: PaperCut Print Software Under Active Attack — Patch Now
- New HOOKEDGE Backdoor Linked to Russian State Hackers Hits European Governments
- The Sandbox to Reimburse Users After $700K Token Bridge Hack
- White-Label Routers Made in China Found With Built-In Backdoors
- Ledger Patches Ethereum App Flaw That Could Have Let Attackers Swap Transactions
- AI Is Helping Hackers Move Faster Than Old-School Security Tools Can Keep Up
- OpenAI Admits Its AI Models Exploited Flaws Due to 'Reward Hacking'
- AI Guardrails Can Backfire: Why Businesses Need Control Over Their AI Safety Settings
- Black Hat 2026: AI Agents and Vulnerability Reporting Take Centre Stage
- Next.js Rushes Out Fixes for Two Critical Bugs Allowing Remote Takeover
- Weekly Threat Roundup: Massive IoT Botnet, Water System Attacks, and Fake Software Traps SMBs Should Know About
- US Order Targets Hidden Backdoors in Power Grid Equipment
- AI Agents Behind Hugging Face Breach Reportedly Tried to Hide Their Tracks
- Security Flaw Found in Amazon's AI Coding Tool Could Leak Sensitive Data
- Visa Expands AI Tool to Automatically Fix Cyber Vulnerabilities
- AI Giants Warn: Businesses Must Prepare Now for AI-Powered Cyberattacks
- New GoCaracal Malware Uses Ethereum Blockchain to Stay in Contact With Hackers
- Two Alleged Hackers Charged in Australia After US-Australia Cybercrime Investigation
- Emergency Security Warning Issued for Bitcoin's Core Lightning Software
- US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them
- Security Flaw Found in Mitsubishi Electric CNC Machine Controllers
- Password Security Flaw Found in Rockwell Automation's OTTO Fleet Manager
- Mitsubishi Electric Industrial Devices Vulnerable to Denial-of-Service Attacks
- Critical Vulnerabilities Found in Fuel-Boss Fuel Management Systems
- Critical Security Flaws Found in Xiiaozet LK100W Devices
- Critical Security Flaws Found in Ebyte NA111-M Industrial Device
- Critical Flaws Found in ASE2000 Industrial Test Tool Used in Energy and Water Sectors
- AI Agents Learn to Say 'No': OpenAI Tightens Trust Rules After Hugging Face Incident
- AI Is Speeding Up Cyberattacks — Is Your Security Ready to Keep Pace?
- Two Australians Charged Over Alleged TeamPCP Supply Chain Hacking Attacks
- Okta's Strong Earnings Signal Rising Demand for AI Identity Security
- AI Uncovers Critical Security Flaw in Bitcoin's Lightning Network
- AI Is Now a Daily Tool for Nearly Half of Security Teams, New Report Finds
- Russian State-Backed Hackers Target EU Officials Through Signal and WhatsApp
- From Naval Officer to CISO: Why Trust Is the Real Job in Cybersecurity Leadership
- Two Australian Men Arrested Over 'TeamPCP' Software Supply Chain Attacks
- Two Alleged Members of 'TeamPCP' Hacking Group Arrested in Australia
- New Malware Campaign Disables Security Software Using a Trusted Driver
- Crypto Lending Platform Moonwell Loses $8.7M in Price Manipulation Exploit
- Cyberattack on Medical Device Giant Boston Scientific Disrupts Global Operations
- Cosmos Blockchain Exploit Lets Hacker Mint $50M in Tokens, Cash Out $60K
- Hidden Code, Hidden Danger: How Attackers Use JavaScript Obfuscation to Power Phishing Kits
- Why AI-Powered Cybersecurity Tools Are Only as Good as Their Data
- DeFi Platform Moonwell Suspends Borrowing After $8.7M Exploit
- AI-Discovered Bugs Trigger Emergency Lockdown for Bitcoin's Core Lightning Network
- New GoCaracal Malware Uses Ethereum Blockchain to Hide Its Command Servers
- New Malware 'GoCaracal' Uses Ethereum Blockchain as Backup Hacking Channel
- US Authorities Take Down Chinese Hacking-for-Hire Platform Linked to Military and Infrastructure Attacks
- Crypto Lender Moonwell Loses $8.7 Million in Exploit—No Code Flaw Required
- GPUThor Attack Bypasses ECC Protection on NVIDIA Workstation GPUs
- Pro-Russian Hacker Group Claims Cyberattack on Norway's Public Digital Services
- DeFi Platform Moonwell Loses $9 Million in Price Manipulation Exploit
- US Cybersecurity Agency Flags Six Actively Exploited Vulnerabilities, Including Citrix NetScaler Flaw
- Urgent: Citrix NetScaler Flaw Under Active Attack — Patch Now
- Researcher Finds Claude Code's 'Auto Mode' Can Be Tricked Into Running Malicious Code
- Bitcoin Lightning Network Flaws Confirmed – Patch Coming Soon
- Russian State Hackers Target European Diplomats with New Backdoor Malware
- State-Linked Hackers Unveil New Espionage Malware 'GoCaracal'
- Law Firm Investigates Longhorn Investments Data Breach
- New AI Tool Uncovers Fresh HTTP Request-Smuggling Attacks
- Fake North Korean IT Workers: What Australian Businesses Should Watch For
- Car Infotainment Systems Targeted by Android Malware Botnet
- FBI Takes Down Chinese Hacking Infrastructure Targeting US Critical Networks
- Iranian State-Backed Hackers Add New Backdoor and Tunneling Tool to Arsenal
- AI Helps Hackers Write Malware Faster—But Not Better, Study Finds
- Critical Flaw Found in Ledger's Ethereum Wallet App
- New Phishing Toolkit 'NovaCookies' Hijacks Microsoft 365 Logins via Fake Docusign Alerts
- Boston Scientific Hit by Cybersecurity Incident, Global Operations Disrupted
- CISA Red Team Breaches Two Critical Infrastructure Firms — One Never Noticed
- Adobe and Nvidia Release Critical Security Updates — Patch Now
- CISA Report: Most Cyberattacks Exploit Basic, Known Software Flaws
- CISA Flags Six More Vulnerabilities Under Active Attack
- Unpatched Flaws in Popular Video Player Software Could Let Hackers Steal Files and Run Code
- AI Is Rewriting the Rulebook for Security Operations Centres
- 'NovaCookies' Phishing Kit Lets Criminals Hijack Microsoft 365 Accounts for $320 a Month
- CISA Warns: Over 100 Water Systems Hit in Cyberattacks Linked to Iran
- MFA Isn't a Silver Bullet: Why Multi-Factor Authentication Can Still Let Attackers In
- AI Agent 'Cheats' Booking Limits: What the Claude Gym-Booking Test Means for Your Business
- Choosing the Right AI Model for Your Security Team: What Australian SMBs Should Know
- Google Fixes Over 300 Security Flaws in Latest Chrome Update
- OpenAI Shuts Down Russian Influence Campaign Using ChatGPT
- Interpol Operation Targets West African Cybercrime Network Behind 'Black Axe'
- Nigeria Pushes Sovereign Cloud Strategy to Strengthen Cybersecurity and National Security
- INTERPOL Crackdown Nets 58 Arrests in Global Cyber Fraud Operation
- Boston Scientific Cyberattack Disrupts Product Shipments
- Nutex Health Reports Data Breach Involving Unauthorized Access
- New 'SLEEPWALKER' Backdoor Hides Silently Until a Secret Signal Activates It
- Independent Review Examines How OpenAI Agents Coordinated a Multi-Day Hack of Hugging Face
- Critical Gitea Flaw Under Active Attack — Patch Now Before It Drops Malware
- AI Voice Scam Targets Stolen iPhone Owners to Bypass Apple's Security Lock
- CISA Alerts Businesses to Actively Exploited Gitea Vulnerability
- AI Email Summaries Can Be Manipulated by Hidden Malicious Code
- Security Flaw in NVIDIA AI Tool Could Let Hackers Poison Business AI Assistants
- US Treasury Sanctions Iran-Linked Hackers Over Critical Infrastructure Attacks
- Linux Foundation to Oversee New Open Standard for Verifying AI System Security
- Ledger Fixes Flaw in Ethereum App That Could Have Tricked Wallet Users
- Cyber Costs Are Skyrocketing—And Small Businesses Are Being Left Behind
- AI Safety Firm Alice Raises $140M to Strengthen Enterprise AI Defenses
- Security Flaw in NVIDIA's NemoClaw Could Let Hackers Hijack Local AI Models
- Critical Login Bypass Flaws Found in Popular WordPress SSO Plugin
- WhatsApp Now Supports Multiple Passkeys for Stronger, Phishing-Resistant Logins
- WhatsApp Boosts Account Security with Multiple Passkeys and Caller ID Alerts
- Hands-On Cyber-Physical Systems Training Returns for ICS Security Professionals
- Security Flaw in Marimo Notebooks Allowed Malicious Commands to Run Automatically
- Two Companies, Two Outcomes: What a CISA Red Team Test Reveals About Cyber Defence
- Security Flaw Found in Rently Smart Home Devices Could Expose User Data
- Security Flaw Found in PayRange Payment API Could Expose Sensitive Data
- Critical Security Flaws Found in Ebyte NE2-D11 Industrial Devices
- Critical Flaws Found in Bendix Truck Brake Control Systems
- Critical Flaw in ZoneMinder Video Surveillance Software Could Allow Full Server Takeover
- Critical Flaw in Siemens SIMATIC IoT2050 Advanced Devices Allows Full Remote Takeover
- Critical Flaw Found in FURUNO Marine AIS Transponder Could Let Attackers Change Device Settings
- CISA Flags Actively Exploited Gitea Vulnerability — Patch Now
- Phishing Kit 'Mirage2FA' Bypasses Two-Factor Authentication, Hits 4,500 Companies
- Fake npm Packages Used to Host Phishing CAPTCHA Scams
- New RATs Hide Commands Inside FTP Server Banners
- New Malware Targets Car Infotainment Systems, Feeds Global Botnet
- AI Is Reshaping Vulnerability Management for Businesses of All Sizes
- AI-Written Malware Is Here — But Your Existing Defences May Already Stop It
- The 'Safety Penalty': Are Restrictive AI Models Slowing Down Cyber Defence?
- When Software Fixes Go Quiet: Why 'Silent Patches' Put Businesses at Risk
- Coldcard Wallet Exploit Linked to $114.7 Million in Stolen Bitcoin
- Hackers Actively Exploiting WordPress SAML Login Plugin Flaws
- Taiwan Charges Nine, Including Nvidia and Super Micro Staff, Over Illegal AI Server Exports to China
- CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability
- Critical Oracle WebLogic Vulnerability Under Active Attack—Patch Now
- Urgent Zimbra Email Flaw Under Attack: Patch Now, Experts Warn
- New ClickFix Malware Trick Hides Attacks as Plain Text Files
- Hyperledger Besu Patches Security Flaw Affecting Ethereum Nodes
- Fake Minecraft Downloads Used to Spread 'Weedhack' Malware
- Cybersecurity Firm ReliaQuest Hit by Phishing Attack, Says Damage Was Contained
- Metaverse Platform The Sandbox Hit by Bridge Exploit, Attacker Mints Tokens Without Backing
- New 'SynkLoader' Malware Combines Old Tricks with Modern Evasion to Steal Passwords
- ToxicPanda Banking Trojan Evolves, Expanding Beyond Personal Finance Apps
- Cybercriminals Get Smarter: AI, Trusted Tools and Old Vulnerabilities Fuel New Wave of Attacks
- The CISO's Hidden Challenge: Hired for Security, Judged on Business Results
- AI Is Finding Security Flaws Faster Than Businesses Can Fix Them
- Uber Hit with Nearly $1 Billion GDPR Fine Over Automated Account Suspensions
- New Malware Loaders WordlistLoader and SynkLoader Target Windows Users
- CISA Flags Actively Exploited Oracle Server Vulnerability - Patch Now
- Crypto Investment Platforms Bitcoin IRA and iTrustCapital Hit by Data Breaches
- Spring Framework Sees Surge in Security Patches: 91 Flaws Fixed This Year
- AI Coding Tools Are Boosting Productivity — But Also Piling Up Security Debt
- Critical Keycloak Flaw Lets Hackers Hijack Accounts Without a Password
- Chinese Hackers Use Fake Graduation Invites to Breach Myanmar Government Systems
- The Hidden Danger of AI 'Super-Users' in Your Business
- Venezuelan National Sentenced to Record 8 Years for ATM 'Jackpotting' Scheme
- Apollo Global Data Breach Exposes Personal Information
- AI Is Speeding Up Cyberattacks - Why Patching Alone Won't Save Your Business
- Iran-Linked Hackers Knock UK Power Plant Offline for Four Days
- TikTok to Pay $400 Million in US Settlement Over Children's Privacy Violations
- Tether Freezes $93K in Stolen Crypto Tied to Cybercrime Case
- DeFi Lending Platform Term Finance Loses $8.5 Million in Governance Exploit
- Chinese Cybercrime Group Uses AI to Supercharge Attacks on Web Servers
- Anthropic Widens Access to AI Security Tool, Commits $35M to Open Source Defenders
- Urgent: Active Attacks Targeting TeamCity Servers in Australia
- Ledger Fixed a Critical Ethereum Wallet Flaw — But Kept Quiet About It for Two Weeks
- Crypto Bridge Exploit Shows How a Single Coding Flaw Can Be Catastrophic
- DeFi Platform Term Finance Loses $8.5M After Attacker Buys Governance Votes for Pocket Change
- Crypto Lending Platform Loses $8.5 Million After Attacker Buys Control
- Ledger Patches Ethereum Signing Flaw — Update Your Wallet Now
- Ledger Patches Security Flaw in Ethereum Wallet App
- The Sandbox Cross-Chain Bridge Hacked, Creating Fake SAND Tokens
- Sandbox Metaverse Platform Hit by Bridge Exploit, Billions in Tokens Minted
- Crypto Bridge Exploit Lets Attacker Mint Billions in Fake Tokens
- TikTok to Pay $400 Million Over Child Privacy Violations
- The Sandbox Halts Token Bridge After Attacker Mints Unbacked Tokens
- Coldcard Wallet Maker Tightens Security After $130M Bitcoin Theft Linked to Old Flaw
- Sandbox Halts Token Bridging After Exploit on Base and BNB Chains
- Banking Trojans on the Rise: What Small Businesses Should Know About Manic, Grandoreiro and ToxicPanda 2.0
- BounceBit Shuts Down Its Blockchain After Hackers Exploit Security Flaw
- Exchanges Halt SAND Trading After Suspected 500M+ Token Minting Exploit
- BounceBit Shuts Down Blockchain After $286.5M Token Exploit
- SafePal Breach Exposes Data of Nearly 40,000 Customers
- Hackers Are Now Targeting the Tools Behind Your Software, Not Just the Code
- New Research Warns of Risks in Emerging Industrial Networking Protocols
- AI-Powered Backdoor Hidden in Fake npm Packages Targets Linux Systems
- Apollo Global Management Discloses Social Engineering Data Breach
- OWASP Releases New Security Blueprint to Tackle Risks in AI Skills and Add-ons
- Bitcoin Hardware Wallet Maker Patches Flaws After $130 Million Exploit
- Former NSA Chief Launches Advisory Firm for Cyber and Geopolitical Risk
- Microsoft Defender's Own Driver Can Be Turned Into a Security-Killing Tool
- New Android Malware Targets In-Car Entertainment Systems for Ad Fraud and Proxy Networks
- BounceBit Halts Blockchain After $3 Million Token Theft
- Weekly Roundup: T-Mobile's Physical Response to Hackers, Threema DDoS, and More
- New Attack Technique Tricks AI Chatbots Into Ignoring Safety Rules
- New Phishing Toolkit Turns Passkeys Against You—Even After You Reset Your Password
- BounceBit Shuts Down Its Blockchain After $3.1 Million Token Exploit
- Local Governments Need Cybersecurity Volunteers—Here's Why It Matters to Everyone
- Cybersecurity Experts Urged to Help Protect Local Government
- OpenAI Tightens Security Controls Following AI Model Leak Incident
- AI Model Update Boosts Automated Vulnerability Scanning for Businesses
- Chipmakers Race to Quantum-Proof Hardware as Future Threat Looms
- US Charges 17 in Iran-Linked Hacking Case Tied to HBO Extortion Plot
- Critical Flaw in 'Isolated-vm' Tool Could Let Attackers Take Over Host Systems
- Actively Exploited Zimbra Flaw Added to CISA's Must-Patch List
- AI-Powered Security Tools Are Changing How Businesses Detect Cyber Threats
- Rust Supply Chain Attack Hits Solana Ecosystem, Opens Door to Remote Code Execution
- Cisco Issues Urgent Patches for Nine Flaws, Five Rated Maximum Severity
- North Korean Hackers Linked to Malicious Rust Software Package
- COLDCARD Hardware Wallet Maker Rushes Firmware Fix After $114M Bitcoin Theft
- Defense Contractors Feel Ready for CMMC—But Can They Prove It?
- Microsoft Releases 22 New Security Patches — Update Now
- CISA Warns Businesses to Urgently Patch Exploited TrueConf Software Flaws
- Critical GitLab Flaw Under Active Attack — Patch Immediately
- Critical Microsoft Entra ID Flaw Exploited in the Wild — But No Action Needed From Customers
- MANTRA Chain Halted After Exploit Freezes Deposits and Withdrawals
- Expired Website Domain Used to Steal Over $1,000 ETH in Tornado Cash Phishing Attack
- MANTRA Chain Halts Network After Exploit Drains Confidence, Token Hits Record Low
- Law Firm Investigates Data Breach at Apple American Group
- New CUSTODY Framework Aims to Keep AI Agents on a Tighter Leash
- Malicious Code Found in Popular Rust Software Libraries Used by Millions
- Suspected Russian Hackers Exploit Google and WhatsApp Login Features to Hijack Accounts
- Delta Flight Wi-Fi Hack Highlights Growing Airline Cybersecurity Risks
- White House Memo Opens Door to Private-Sector 'Cyber Marque' Operations
- Password Vault Flaw Puts MSP and SMB Credentials at Risk
- Why Police Are Struggling to Keep Up With Cybercrime
- Trusted Tools, New Tricks: This Week's Cyber Threats Exploit What You Already Rely On
- US Warns of AI-Generated Malware Targeting Critical Infrastructure Systems
- US Charges Iranian Hackers Over $6M Bitcoin Ransom Theft Scheme
- MAYAChain Exploit Balloons from $1.36M to Nearly $11M in Losses
- Pakistan-Linked Hacking Group Updates Tools to Target Afghan Government Systems
- Active Attacks Target Zimbra Email Servers via Newly Disclosed Flaw
- Researchers Find Way to Trick Grok Chatbot Into Leaking Private Chat Data
- Understanding Digital Surveillance: What Businesses Should Know
- Russian State-Linked Hackers Exploit Login Systems to Target High-Profile Individuals
- Critical Flaw Found in Popular JavaScript Sandbox Tool 'isolated-vm'
- Citrix Patches Critical Authentication Bypass Flaw in NetScaler Products
- Banking Trojan 'Grandoreiro' Returns With New Tricks Despite Police Takedown
- Unpatched Zimbra Servers Under Active Attack: What SMBs Need to Know
- Hackers Compromise 14,000 IP Cameras in Russia and Ukraine
- US Charges 17 Alleged Iranian Hackers in Global Hacking-for-Profit Scheme
- Atlassian and Splunk Release Fixes for Dozens of Serious Security Flaws
- Critical MLflow Flaw Being Exploited to Steal Cloud Credentials
- ‘Zombie Card’ Attack Shows Expired Visa Cards Can Be Tricked Into Working Again
- Security Flaw Found in Johnson Controls Simplex Incident Manager Could Expose User Credentials
- CISA Flags Two Actively Exploited TrueConf Server Vulnerabilities
- Cisco Fixes Critical Security Flaws in Crosswork and Secure Workload Products
- 'Shady AI' Emerges as a Major Governance Risk for Businesses
- New 'CDN Tsunami' Attack Method Could Massively Amplify Website Outages
- New 'Manic' Android Malware Blends Banking Fraud with Spyware Tactics
- AI Tool Helps Viasat Strengthen Satellite Security After 2022 Russian Cyberattack
- Critical Flaws Found in NASA Spacecraft Control Software Could Allow Unauthorized Commands
- New ToxicPanda 2.0 Android Malware Escalates Banking Fraud Threats Worldwide
- OpenAI Tightens AI Model Security After Recent Incidents
- New 'SPECTRE' Malware Uses Advanced Tricks to Hide from Security Software
- Chinese-Speaking Hackers Deploy AI to Automate Attacks After Breaching Web Servers
- Hackers Are Hijacking Trusted Work Chat Tools to Steal Logins
- 40 Fake Firefox Extensions Found Stealing Cryptocurrency Wallet Data
- Critical Citrix NetScaler Flaw Lets Attackers Bypass Login — Patch Now
- Phishing Scam Drains Over $1,000 ETH from Cryptocurrency User
- Critical GitLab Vulnerability Under Active Attack — Patch Immediately
- AI-Powered Attacks Target Siemens Industrial Control Systems in Critical Infrastructure
- Critical Elementor Pro Flaw Lets Hackers Take Over WordPress Sites Without Logging In
- CrowdStrike Recognised as Top Performer in Cloud Security Rankings
- Unfiltered AI Tool 'Kriminal' Raises Alarms as Cybercrime Enabler
- AI Agents Could Become Your Newest Insider Threat, Expert Warns
- Researchers Demonstrate Data-Leaking Attack on Cloudflare Workers
- OpenAI Pauses AI Training to Strengthen Safety Monitoring
- Chinese-Linked Hacking Group Targets Central Asian Organisations with Remote Access Trojans
- Maya Protocol Shuts Down After $1.7M Crypto Exploit
- Maya Protocol Halted After Attacker Exploits Six Bugs to Steal $1.4 Million in Bitcoin
- CodeSecCon: Free Virtual Event Focuses on Building Safer Software
- T-Mobile Cut a Cable to Kick Chinese Hackers Off Its Network
- New Espionage Campaign 'SilkParasite' Deploys Five Undocumented Hacking Tools
- Urgent Warning: Active Cyberattacks Targeting Industrial Control Systems, Including Siemens PLCs
- CISA Flags Actively Exploited MLflow Vulnerability — Act Now
- AI Security Startup Prevalent AI Secures $22 Million Funding Boost
- Over 14,500 Dahua Cameras Hacked in Global Attack Campaign
- US Charges 17 Iranian Hackers, Offers $10 Million for Information Leading to Arrests
- Phishing 3.0: When AI Attackers Meet AI Defenders
- Nearly 2,000 Hacked WordPress Sites Turned Into Malware Distribution Network
- Cl0p Ransomware Gang Exposes 40+ Victims in Major Software Exploit Campaign
- CISA Flags Four Critical Flaws Under Active Attack — Patch Now
- Urgent: Patch Now — Microsoft, VMware and Apple Flaws Under Active Attack
- Breaking Down Cyberattacks in Plain English: The Case for Crime Script Analysis
- Oracle Releases Massive Security Update With 943 Patches
- Google and Mozilla Release Critical Security Updates for Chrome and Firefox
- CareCloud Data Breach Now Affects 3.7 Million People, Far More Than First Reported
- Microsoft Uncovers 30+ Domains Linked to New Mac-Targeting Malware
- Hackers Deploy Custom Web Shell to Steal Engineering Data via PTC Windchill Flaw
- Maya Protocol Hit by $1.7M Crypto Exploit, Stolen Bitcoin Traced
- When AI Models 'Cheat the Test': Understanding the Risks of Benchmaxxing
- Urgent: Active Attacks Targeting N-able/N-central IT Management Software in Australia
- Decred Cryptocurrency Network Patches Critical Security Flaws
- Cross-Chain Trading Platform Loses $11 Million in Bitcoin After Exploit
- China-Linked Hackers Use AI to Power Near-Autonomous Cyberattack in APAC
- Critical GitLab Zero-Click Flaw Leaves Self-Managed Users Guessing
- Harmony Protocol to Roll Back Blockchain After Token Forgery Attack
- New 'CoSnitch' Technique Tricks Microsoft Copilot Into Exposing Its Own Security Weaknesses
- Lazarus Group's $292M DeFi Hack Still Shaking Crypto Markets Months Later
- AI Agents Gone Rogue: What Small Businesses Should Learn From Sandbox Failures
- Massive Credential Theft Targets Microsoft Entra Users: What SMBs Need to Know
- New Docuseries Pulls Back the Curtain on Life as a CISO
- One Click, Data Gone: Flaws Found in Microsoft Copilot Personal
- Hackers Actively Exploiting AI and Industrial Software Flaws to Steal Cloud Credentials
- New Scam Alert: 'Ransom Busters' Preys on Ransomware Victims with Fake Recovery Offers
- Webinar Explores Whether Cybersecurity Can Keep Up With AI-Speed Attacks
- From Self-Taught Hacker to AI Security Leader: A Career Built on Curiosity
- AI Uncovers Serious Security Flaws in Bitcoin Hardware Wallets
- Google Uses AI-Powered Code Review to Outpace Attackers Exploiting Stolen Source Code
- Baylor Genetics Data Breach Sparks Legal Action Over Exposed Personal Information
- Why 'Patch Everything Eventually' No Longer Works Against Today's Cyber Threats
- New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
- Fake 'Ransom Busters': Ransomware Gang Poses as Recovery Experts to Steal Payments
- Researchers Warn AI Coding Agents Can Catch and Spread 'Mind Viruses'
- New Malware 'TWINLOOT' Hides Inside Microsoft SharePoint and Teams to Steal Passwords
- Startup Xpander Secures $7.5M to Help Businesses Manage AI Agents Safely
- Fortinet Buys Virtue AI to Strengthen AI Security Offerings
- Siemens Simcenter Nastran Vulnerability Could Allow Remote Code Execution
- Multiple Security Flaws Found in CISA's Malcolm Network Monitoring Tool
- CISA Flags Four Actively Exploited Bugs in Microsoft, VMware and Apple Products
- Fake RubyGems Packages Caught Stealing Browser Data and Crypto Wallets
- One Attacker's Server Has Been Quietly Scraping Salesforce and ServiceNow Data for Over a Year
- WordPress Form Plugin Flaw Puts 300,000 Sites at Risk of Takeover
- Heights Finance Data Breach Exposes Details of 1.2 Million People
- SafePal Data Exposure Hits Nearly 40,000 Customers Due to Order-Tracking Flaw
- Critical GitLab Flaw Let Attackers Tamper With Data Without Logging In
- Attackers Exploit macOS Screen Sharing Flaw to Hijack Macs for Crypto Mining
- Apple Patches Dozens of WebKit Flaws in Latest macOS and iOS Updates
- US Cybersecurity Agency Warns of Actively Exploited Flaw in AI Framework 'Ray'
- Old Coldcard Wallet Flaw Blamed for $115 Million in Stolen Bitcoin
- Years-Old Coldcard Wallet Flaw Still Being Exploited to Steal Bitcoin
- Law Firm Investigates USA DeBusk Data Breach Affecting Personal Information
- Answering a Video Call Could Hijack Your Android Phone, Researchers Warn
- Critical GitLab Flaw Could Let Hackers Delete Projects Without Logging In
- AI Agents Turned Rivals: Anthropic Testing Reveals Self-Replicating Malware Risk
- Threat Modeling Expert Highlights Lessons from Hugging Face AI Attack
- GitHub Workflow Flaw in Snowflake Repo Shows Risk of Automated Issue Handling
- Critical WordPress Plugin Flaw Puts 600,000+ Sites at Risk of Takeover
- SafePal Plugin Flaw Exposes Data of Nearly 40,000 Customers
- Iranian Hackers Refine 'Cavern' Malware to Hide Inside Everyday Web Traffic
- Apple Warns Record Number of Users of Suspected Spyware Attacks
- New Linux Botnet 'Evooo1Bot' Turns Hacked Devices Into Attacker Toolkits
- French Tax Authority Breach Exposes Data of 680,000 People
- Data Breach Halts Bitcoin Purchases, Puts 250,000 Crypto Users at Risk
- Weekly Threat Recap: Old Bugs, Exposed Services and Browser Hijacks Keep Costing Businesses
- How a Simple Naming Mistake Let AI Models Target a Real Company
- CISA Flags Actively Exploited Flaw in Ray-Project AI Framework
- AI Assistants Could Be Leaking Your Business Secrets Without You Knowing
- SafePal Breach Exposes 40,000 Crypto Wallet Customers' Personal Data
- Coldcard Hardware Wallet Flaw Linked to $100M Bitcoin Theft
- AI Testing Reveals Risk: Claude Agents Deployed Self-Replicating Malware Under Conflicting Instructions
- Unresolved Unisoc Modem Flaw Lets Attackers Take Over Android Devices via Video Call
- Harmony Blockchain to Roll Back Chain After Forged Token Exploit
- SafePal Data Breach Exposes Details of 40,000 Customers
- macOS Screen Sharing Flaw Exploited to Secretly Mine Cryptocurrency
- New Linux Botnet 'Evooo1Bot' Hijacks Vulnerable Devices for Proxy Networks
- Hackers Exploit macOS Screen Sharing Flaw to Hijack Systems for Crypto Mining
- SAP Commerce Cloud Under Attack Just Days After Critical Flaw Disclosed
- Hackers Exploit Old macOS Screen Sharing Flaw to Secretly Mine Cryptocurrency
- Suspected China-Linked Hackers Exploit Critical VMware vCenter Flaw to Deploy Ransomware
- Hackers Claim Massive Data Theft from Microsoft Azure, Targeting Major Global Brands
- SafePal Breach Exposes 39,000 Users, Fueling Phishing Fears
- SafePal Data Breach Raises Fears of Real-World Attacks on Crypto Holders
- SafePal Bitcoin Wallet Breach Exposes Customer Details, Raising Safety Concerns
- How AI Is Learning to Think Like a Security Analyst
- Historic Hardware Wallet Hack: $112M in Bitcoin Stolen via Coldcard Firmware Flaw
- SafePal Data Breach Exposes Nearly 40,000 Users' Personal Information
- Hackers Exploit macOS Screen Sharing Flaw to Mine Cryptocurrency
- Researchers Show Encrypted AI 'Reasoning Traces' Can Be Exposed, Leaking Passwords and Personal Data
- Study Reveals $575 Million Lost to Address Errors and Exploits on Ethereum and BNB Chain
- Apple Fixes macOS Bug Used to Secretly Mine Cryptocurrency
- SafePal Confirms Data Breach Exposing Thousands of Customers' Personal Data
- SafePal Data Breach Exposes Nearly 40,000 Customers to Phishing Risk
- Critical macOS Screen Sharing Flaw Exploited for Silent Crypto Mining
- SafePal Crypto Wallet Data Exposure Puts 40,000 Users at Phishing Risk
- SafePal Data Breach Exposes Nearly 40,000 Customer Orders, Phishing Risk Rises
- Baylor Genetics Investigates Data Breach Exposing Patient and Employee Information
- SafePal Data Breach Exposes Nearly 40,000 Customers' Personal Information
- SafePal Discloses Data Exposure Linked to Plugin Security Flaw
- SafePal Data Breach Exposes Nearly 40,000 Customers' Details
- Critical macOS Flaw Exploited to Secretly Mine Cryptocurrency
- SafePal Data Breach Exposes Order Details of 40,000 Crypto Wallet Users
- SafePal Crypto Wallet Provider Discloses Breach Affecting 40,000 Customers
- Crypto Wallet Maker SafePal Confirms Data Breach Affecting 40,000 Customers
- Crypto Wallet Provider SafePal Reportedly Exposes Data of 40,000 Customers
- Critical SAP Commerce Cloud Flaw Under Active Attack — Patch Immediately
- French Tax Data Breach Exposes 678,000 Individuals and Businesses, Raising Bitcoin-Theft Fears
- Critical macOS Screen Sharing Bug Actively Exploited to Install Crypto Miners
- Security Audit Catches Critical XRP Ledger Bugs Before They Could Be Exploited
- Law Firm Investigates AdaptHealth Data Breach Affecting Personal Information
- Law Firm Investigates Lennar Corporation Data Breach Affecting Personal Information
- Why Today's Top Security Leaders Need Business Skills, Not Just Tech Skills
- Cybercriminals Spend Millions Buying Expired Domains to Spread Scams and Malware
- AI Is Fueling a Flood of New Vulnerabilities—Can AI Also Help Fix It?
- Why Identity and Access Management Is Now a Compliance Must-Have
- French Tax Data Breach Puts 678,000 Taxpayers at Risk of Scams
- Scottish Prosecutor's Office Data Breach Linked to Third-Party Vendor
- Why Boards Keep Getting Caught Off Guard by Tech Risk
- Chinese Hacking Group Adds Stealth Rootkit to Evade Detection
- Cyera's $1 Billion Acquisition Signals New Era of AI Agent Security
- Hardware Wallet Exploit Leads to $112M Bitcoin Theft
- Weekly Roundup: Rapid7 Cuts Jobs, Boeing 737 Hack Demoed, and Refrigeration Systems Found Vulnerable
- Fake Google Ad Costs Crypto Trader $550,000 in Phishing Scam
- Security Scanner Bug, Not LiteLLM, Behind Breach Affecting 2,500 Organisations
- New Free Tool Reveals Who's Tracking You Online
- New Free Tool Reveals Who's Tracking Your Business Online
- New Attack Technique Lets Hackers Hijack Your Logged-In Browser Sessions
- Google Cloud Charts Path to Quantum-Safe Security by 2029
- Fake Job Interview Pages Used to Steal Google and Facebook Logins in Global Phishing Campaign
- Apple Alerts Users in 110 Countries to Possible Spyware Targeting
- RingCentral Data Breach May Have Exposed 1.6 Million Users' Personal Information
- Beacon CRM Breach Exposes Data from Over 1,000 Charities
- Trezor Warns 14,000 Customers After Data Breach at Shipping Partner ShipMonk
- Hackers Actively Exploiting Unpatched Flaw in GeoServer Software
- New macOS Malware 'AmnesiaStealer' Targets Passwords and Browser Data
- Fake Google Ad Scams Crypto User Out of $550,000
- Crypto Investor Loses $550,000 to Fake Google Ad Phishing Scam
- AI Security Sweep Flags Nearly 8,000 Potential Flaws in Bitcoin Software
- Critical VMware vCenter Vulnerability Under Active Global Attack
- Why Curiosity Is Cybersecurity's Most Underrated Skill
- Fake Google Ads Used to Steal $550,000 in Crypto Phishing Scam
- Cybersecurity Industry Consolidates: 21 M&A Deals Announced in July 2026
- Hackers Move Fast: Adobe Commerce Flaw Exploited Right After Patch Release
- WordPress Patch Fixes Serious Remote Code Execution Flaw
- Trezor Data Breach Exposes Details of Nearly 14,000 Bitcoin Wallet Buyers
- Chinese AI Models Outperform Restricted US Systems on Cybersecurity Tasks, Industry Warns
- Siemens Solid Edge Software Vulnerable to Malicious File Attacks
- Siemens Parasolid Software Vulnerable to File-Based Attack, Update Urged
- Siemens LOGO! Soft Comfort Software Has Encryption Flaws — Update Now
- Siemens License Server Flaws Could Let Attackers Elevate Privileges, Access Files
- Siemens Building Controllers Vulnerable to Network-Based Disruption
- Security Flaws Found in ANDRITZ HIPASE-250 and 250 SCALA Devices Used in Energy Sector
- Security Flaw Found in Johnson Controls Metasys Building Management System
- Security Flaw Found in Flow Neuroscience Brain Stimulation Device
- Critical Flaw Found in Siemens Video Management Software—Update Now
- CISA Flags Vulnerabilities in Johnson Controls Airwall Security Devices
- Cybersecurity Investment Surges as Team8 Raises $365 Million
- Fortinet Fixes Critical Login Flaws in FortiWeb and FortiManager
- New Phishing Toolkit Mimics Popular Checkout and Login Pages
- 'Jewelbug' Hacker Group Blends Espionage with Cryptocurrency Theft
- White House Enlists Private Security Firms to Fight Foreign Cybercrime Gangs
- Critical VMware vCenter Flaw Now Being Actively Exploited
- New Windows Zero-Day 'ShieldBreak' Lets Attackers Gain Full System Control
- Harmony Blockchain Hack: Attacker Mints Billions in ONE Tokens, Rollback Considered
- Flaws in Belgium's Digital ID Browser Extension Expose Citizens to Remote Attacks
- Hackers Actively Targeting SharePoint Flaw After Exploit Code Goes Public
- North Korea's Lazarus Group Moves $16.6 Million in Bitcoin
- Coldcard Bitcoin Wallet Hit by Security Breach
- Long-Running 'City-Forum' Campaign Targets Salesforce and ServiceNow Data
- North Korean Hackers Exploited Windows Zero-Day to Plant New Backdoor
- Walmart's Collaborative Security Model: What SMBs Can Learn from 'Purple Teaming'
- Microsoft SharePoint Flaw Under Active Attack After Exploit Code Goes Public
- 737 Fake VPN Extensions Found Hijacking Browser Traffic in Chrome Web Store
- Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Handover
- AI Security Startup Mindgard Secures $30 Million in Funding
- Uber Freight Investigating Alleged Data Breach Claimed by Hacking Group
- WhatsApp Rolls Out Scam Alerts as Signal Boosts Key Verification
- New 'City-Forum' Attacks Exploit Guest Access in Salesforce and ServiceNow
- Walmart's Security Playbook: Trust and Communication Over Chaos
- Flaw in Major AI Providers' APIs Exposed Hidden Reasoning Data, Including Secrets
- Businesses Getting Better at Blocking Attacks – But Attackers Are Slipping Through the Cracks Anyway
- Cyberattack Disrupts Global Logistics Giant Ceva, Delaying Shipments Across Europe
- Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities
- Intel and AMD Patch Over 80 Security Flaws in Latest Updates
- Harmony Blockchain Hit by Massive Token Minting Exploit
- Supply Chain Attack on LiteLLM Hits Over 2,500 Organizations
- Harmony Blockchain Hit by Exploit, Native Token Crashes 30%
- Critical VMware vCenter Flaw Now Under Active Attack, Giving Hackers Persistent Access
- North Korean Hackers Exploit New Windows Zero-Day to Seize Control of Victim Systems
- Ivanti Patches Remotely Exploitable Flaws in Endpoint Manager
- Brief but Dangerous: Malicious LiteLLM Package May Have Hit 2,100+ Organisations
- Industrial Equipment Makers Patch Security Flaws — Here's What Businesses Should Know
- Critical SAP Commerce Cloud Flaw Rated Maximum Severity — Patch Now
- SonicWall Fixes Critical Flaws in Discontinued Management Platform
- New 'ShieldBreak' Exploit Bypasses Windows Defender Patch, Grants Full System Access
- Cisco Firewall Flaw Being Actively Exploited to Crash Devices
- XRP Bridge Hack: Attacker Exploits Relayer Flaw, Funds Traced to Tornado Cash
- Cisco Fixes Actively Exploited Firewall Flaw That Can Knock Devices Offline
- Harmony Blockchain Hit by $Billions Exploit, Token Crashes 40%
- Harmony Protocol Suffers Major Exploit, Token Price Plummets 30%
- Fake Deposit Bug Lets Hackers Steal $200K in Cryptocurrency Bridge Attack
- Microsoft's August 2026 Patch Tuesday Fixes 421 Vulnerabilities, 62 Critical
- Microsoft's August Patch Tuesday Brings Another Wave of Security Fixes
- Microsoft's Latest Patch Batch Fixes Nearly 400 Security Flaws — One Already Under Attack
- Microsoft's August Update Fixes Nearly 400 Flaws, One Already Under Attack
- Gunra Ransomware Gang Bypasses MFA by Exploiting Old Fortinet Vulnerabilities
- Microsoft's Latest Patch Tuesday Fixes 398 Bugs — One Already Under Attack
- New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
- Zoom's Drawing Tool Had a Dangerous Flaw — Update Now
- Microsoft's August Patch Tuesday Fixes 421 Flaws — Including One Under Active Attack
- Fake Job Interviews Used to Trick IT Workers Into Installing Malicious VPN Software
- Adobe Sounds Alarm on Critical Flaws in ColdFusion and Campaign Classic
- AI-Discovered Flaw Lets Attackers Break Into Microsoft SharePoint Without a Password
- DeadLock Ransomware Gang Uses Blockchain Tech to Dodge Takedowns
- BTCPay Server Community Offers Bounty After Critical Flaw Exploited
- Zoom Fixes Serious Flaw That Let Meeting Attendees Hack Other Participants
- Coldcard Hardware Wallet Attack Sparks Mass Bitcoin Security Overhaul
- AI Governance Isn't an IT Problem—It's a Leadership Problem
- SAP Issues Urgent Patches for Critical Security Flaws
- New US Initiative Aims to Shield Water Utilities From Cyberattacks
- Nearly 200,000 XRP Stolen in Coreum Cross-Chain Bridge Exploit
- OpenAI Releases Cybersecurity-Focused AI Model with Fewer Safety Restrictions
- Hardware Wallet Exploit Sparks Wave of Bitcoin Fund Transfers
- Malicious SIM Cards Can Hijack IoT Devices Like EV Chargers and Industrial Routers
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Accidental Exposure
- Cybersecurity Startup Corma Secures $60 Million to Build Defensive AI Tools
- Three Actively Exploited Vulnerabilities Added to CISA's Critical List — Cisco, Microsoft and Metabase Affected
- Security Flaw Found in Pulsetto Vagus Nerve Stimulator Device
- Critical Security Flaws Found in Mira Hormone Monitor Devices and App
- Critical Flaws Found in Johnson Controls Access Control Systems
- Coreum Bridge Exploit Drains 200,000 XRP in Under Two Hours
- Fake Crypto Startup Sting Exposes North Korean Fake IT Workers
- Malicious Chrome Extension Sneaks Back Into Web Store After Ban
- Fake USB Devices Can Trick Windows 11 Into Handing Over Full Control
- AI Coding Assistants Tricked Into Leaking Secrets via 'Split Instruction' Attacks
- New Kimwolf v7 Botnet Targets Android IoT Devices with Advanced Evasion Tricks
- From WannaCry Hero to Cautionary Tale: The Marcus Hutchins Story
- OpenAI Launches GPT-5.6-Cyber to Boost Cybersecurity Defences
- BTCPay Server Offers Bounty to Recover Stolen Bitcoin After Exploit
- Gunra Ransomware Targets Fortinet and Schneider Electric Vulnerabilities to Infiltrate Networks
- Ravencoin Warns of Critical Bug That Could Let Attackers Rewrite Transaction History
- Hackers Shut Down Turbine at Polish Power Plant via Private Cellular Network
- Mozilla Replaces Firefox Signing Key After Accidental Public Exposure
- Critical Flaw in Ravencoin's KAWPOW Algorithm Exploited, Forcing Major Blockchain Rollback
- WordPress Plugin Vendor BdThemes Hit by Supply Chain Attack, Creating Rogue Admin Accounts
- Patch Now: August Update Fixes Actively Exploited Windows Flaw Among 415 Security Bugs
- BTCPay Server Community Offers Bounty After Lightning Wallet Hack
- BTCPay Server Exploit Drains Bitcoin Wallets, $190,000 Bounty Offered for Recovery
- BTCPay Server Backers Offer 3 BTC Bounty Following Critical Exploit
- AI Gym-Booking Assistant Goes Rogue: Lessons for Businesses Using AI Agents
- New 'Aeternum' Malware Uses Blockchain to Hide Its Command Centre
- 'GhostJacking' Attack Reveals Hidden Risks in AI Agent Security
- Iran-Linked Hackers Suspected in Widening Attacks on US Water Systems
- Critical Zero-Day in Metabase Analytics Tool Could Expose Countless Business Systems
- Beyond the Checklist: Why Aussie Businesses Need to Rethink How They Patch
- Advanced iPhone Hacking Tools Once Reserved for Spies Now Spreading to Cybercriminals
- BTCPay Server Hit by Critical Exploit; Bounty Offered for Recovery
- New China-Linked Ransomware 'StormEncryptor' Signals Evolving Threat to Businesses
- BTCPay Server Offers Bitcoin Bounty After Wallet Exploit
- Outdated Cybercrime Laws Leave Ethical Hackers Exposed
- What Sherlock Holmes Can Teach Us About Social Engineering
- Weekly Threat Recap: AI Risks, a Metabase Zero-Day, and Router Backdoors Highlight Basic Security Gaps
- OpenAI's Next AI Model Could Enable Fully Autonomous Cyberattacks, Experts Warn
- Crypto Exchange Coinsbuy Loses $8M in Cross-Chain Hack
- New Startup Aims to Close Security Gaps in AI Cloud Infrastructure
- Cisco Flags High-Severity Flaws in ClamAV Antivirus Software—Exploit Code Already Public
- North Korean Hackers Go Offline with Custom AI to Supercharge Cyberattacks
- 'Ghostjacking': How Hackers Trick AI Security Tools by Poisoning Their Own Logs
- Passkeys Aren't Bulletproof: New Research Shows Ways Attackers Can Bypass Them
- New Gunra Ransomware Threat Targets Businesses with Double-Extortion Tactics
- AI Is Supercharging Software Development — Is Your Security Keeping Pace?
- Iran-Linked Hackers Widen Attacks on US Water Systems
- Hackers Exploit Unpatched TrueConf Servers to Deliver Malicious Installers
- Metabase Rushes Out Patch After Hackers Exploit Flaw as Zero-Day
- Hackers Used a New 'Private Network' Trick to Sabotage Polish Energy Facility
- Urgent Patch Alert: Actively Exploited Flaw Found in Progress LoadMaster Software
- Levi Strauss Confirms Data Theft After Social Engineering Attack
- Fake VS Code Extension 'Solidity Pro' Caught Stealing Crypto Wallets and Credentials
- Critical BTCPay Server Flaw Lets Attackers Drain Bitcoin Lightning Nodes
- OpenAI Hits Pause on New AI Model After It Shows Alarming Cybersecurity Skills
- Critical Security Flaws Found in Widely Used Belgian eID Software
- Volunteer Security Sweep Finds Nearly 5,000 Flaws Across Bitcoin Infrastructure
- AI Platforms Under Attack: What the Hugging Face Breach Means for Business Security
- Crypto Platform Coinsbuy Hacked for Over $8 Million, Funds Laundered via Monero
- Microsoft Uncovers Malware Hiding Commands in Blockchain Smart Contracts
- Shenzhen Employee Jailed for Bitcoin Extortion Posing as Overseas Hacker
- AI-Powered Red Team Uncovers Critical Flaws in Bitcoin Software
- OpenAI Pauses 'Astra' AI Model Over Autonomous Hacking Concerns
- One-Click Flaw in Atlassian's Rovo AI Could Have Exposed Business Data
- Why Hackers Get Nicknames: Inside the Naming of Cyber Threat Groups
- Atlassian's AI Assistant Rovo Could Be Tricked Into Leaking Jira and Confluence Data
- Bitcoin Hardware Wallet Hack Sparks Mass Fund Migration
- Hidden CSS Tricks in Emails Can Steal Passwords Across Major Webmail Platforms
- Aztec Hacker Launders 500 ETH Through Tornado Cash as Crypto Thefts Surge
- Critical Metabase Flaw Being Actively Exploited — Patch Immediately
- N-able Rushes Second Hotfix as Hackers Continue Targeting N-central RMM Tool
- Critical Flaw in Progress Kemp LoadMaster Added to US Government's Actively Exploited Vulnerabilities List
- BTCPay Server Users Urged to Update After Critical Flaw Exploited to Steal Funds
- Critical BTCPay Server Flaw Exploited to Steal Bitcoin from Lightning Nodes
- Hackers Exploit Blockchain Smart Contracts to Hide Malware
- Bitcoin Lightning Network Exploit Drains Merchant Wallets
- Bitcoin Payment Tool Exploit Lets Attackers Drain Merchant Wallets
- OpenAI's AI Agents Accidentally Attacked Hugging Face, Timeline Reveals
- BTCPay Server Rushes Out Emergency Patch After Two-Factor Bypass Found
- Identity Theft, Not Malware: Why 90% of Cyberattacks Now Start With Stolen Logins
- OpenAI Pauses Development of AI Model Over Cybersecurity Capability Concerns
- Nearly 800 Fake npm Packages Caught Spreading Malware Across Windows, Mac and Linux
- New Mac Malware Uses Fake 'Fix It' Prompts to Steal Crypto and Passwords
- Fake IT Help Desk Calls Used to Steal Corporate Cloud Data, Researchers Warn
- AI-Written Software Patches Fail Half the Time, Study Finds
- Critical BTCPay Server Flaw Under Active Attack — Update Now
- Critical BTCPay Server Flaw Under Active Attack — Update Now to Protect Bitcoin Funds
- Weekly Roundup: Low-Quality AI Bug Reports, Port Cyberattacks, and Wall Street Targeted by Hackers
- Bitcoin Users Targeted: Trezor Phishing Ad and BTCPay Server Flaw Under Active Attack
- Critical WordPress Flaw Could Let Hackers Take Over Your Website — Update Now
- Hackers Use Fake CAPTCHAs and Blockchain Tricks to Spread Malware
- Fake CAPTCHA Scam Uses Blockchain to Deliver Malware
- Aviation Alert: Legacy Air Traffic Communication System Vulnerable to Message Injection Attacks
- Actively Exploited Flaw in Progress LoadMaster Added to CISA's Must-Patch List
- Open Source Software Is Growing Up: What That Means for Small Businesses
- Decades-Old Linux Kernel Flaw Lets Attackers Escape Containers and Seize Root Access
- Voice Phishing Extortion Gang Rebrands Multiple Times After Making Millions
- Phishing Attack Hijacks Microsoft 365 Accounts to Spy on Payroll and Finance Emails
- AI Research Tool Uncovers New Web Attack Techniques, Including Apache Zero-Day
- Truck Brake Recall Quietly Fixed Hidden Cybersecurity Flaws
- NatJack Attacks Exploit NAT Tables to Hijack Connections and Spoof DNS
- Black Hat USA 2026: What SMBs Should Know About the Latest Cybersecurity Product Announcements
- Microsoft and Apple Roll Out Critical Security Patches — Update Now
- Windows Hello for Business Flaw Lets Malware Hijack Cloud Logins
- GitHub Issues Used to Hijack AI Coding Assistants' CI Pipelines
- North Korean Hackers Hijack Telegram Accounts to Target Crypto Professionals
- Data Breach at Unlimited Technology Systems Exposes 3.8 Million People's Personal and Health Data
- Google Releases Chrome 151 Update to Fix Critical Security Flaws
- Hacking Group 'TeamPCP' Has Been Quietly Attacking Servers Since 2020, Researchers Find
- Volunteer Hackers Uncover Nearly 5,000 Flaws in Bitcoin Software After Wallet Hack
- Microsoft Warns of ClickFix Malware Campaign Abusing Blockchain to Evade Takedowns
- Coldcard Bitcoin Wallet Flaw Exposes Years-Long Seed Theft Risk, AI Audit Finds Dozens More Bugs
- CrowdStrike Uncovers Hackers Hiding Malicious Commands on VMware ESX Servers
- Microsoft Warns of ClickFix Malware Using Blockchain to Hide Attack Instructions
- Coldcard Hardware Wallet Flaw Linked to $130M Bitcoin Theft
- Coldcard Hardware Wallet Flaw Blamed for $130M Bitcoin Theft
- Zeus Wallet Shuts Down Systems After Cyberattack, Says Customer Funds Are Safe
- Fake XRP Airdrop Scams Target Crypto Investors, Foundation Warns
- Microsoft Warns Hackers Are Using Blockchain to Hide Malware from Takedown Efforts
- Cybercriminals Are Working Together Faster Than Law Enforcement Can Keep Up
- AI Agents Are Breaking Out of Testing Labs — And Businesses Should Take Notice
- Security Researcher Exposes Weakness in ChatGPT's 'Secure' Sandbox
- Lessons from the DNC: Why a 'Security-First' Culture Needs More Than Just Rules
- How the Words We Use About AI Threats Shape Our Security Decisions
- New 'Zapscape' Flaw Could Let Attackers Break Out of Virtual Machines
- Cisco Fixes 12 Security Flaws in SD-WAN and IOS XE Software, Three Rated Critical
- Zeus Wallet Suspends Operations After Cybersecurity Breach
- Canadian Man Pleads Guilty to Snowflake Data Extortion Spree
- Canadian Man Admits Role in Massive Snowflake Data Extortion Spree
- Bitcoin Ecosystem Audit Uncovers Nearly 5,000 Security Flaws
- Microsoft Uncovers Malware Campaign Abusing BNB Smart Chain
- Researchers Find New Way to Sneak Past Intel and AMD's Spectre Chip Defenses
- Wall Street Hedge Funds Hit by Wave of Sophisticated Cyberattacks
- ThreatsDay Roundup: RCE Flaws, One-Click Exploits, and Trusted Tools Turned Against You
- AI-Powered Security Audit Uncovers Dozens of Critical Bitcoin Software Flaws
- Snowflake Hacker Pleads Guilty in US Court
- Google Warns of Hackers Using Phone Calls and Fake Websites to Target Financial Firms
- AI Security Scan Uncovers Over 1,000 Critical Flaws in Cryptocurrency Projects
- Coldcard Wallet Hack Sparks Bitcoin Custody Debate Amid ETF Inflows
- Same Scammers, New Names: Vishing Extortion Gang Rebrands to Evade Detection
- AI Browsers Can Be Hijacked Without a Single Click, Researchers Warn
- Hackers Move Millions in Stolen Crypto from Coldcard Wallet Exploit
- Thousands of Rockwell Industrial Controllers Found Exposed Online, Including Near Water Utility Attacks
- Why Ticking Compliance Boxes Won't Stop Cyberattacks
- Security Flaw Found in Medixant RadiAnt DICOM Medical Imaging Software
- Security Flaw Found in Johnson Controls TL280 Devices
- Multiple Security Flaws Found in ABB Ability Zenon Industrial Software
- Weak Random Number Bug in Popular Crypto Library Linked to $5.7 Million in Wallet Thefts
- Coldcard Hardware Wallet Firmware Exploit Reportedly Drains Up to $100M in Bitcoin
- Apple's iCloud Private Relay Can Leak Your Real IP Address, Researchers Warn
- ZEUS Wallet Suspends Services After Security Breach
- 'Ask AI' Buttons Could Be Quietly Manipulating Your AI Assistant
- Critical Flaw in Paperclip Software Could Have Let Attackers Seize Admin Control
- Coldcard Wallet Hack Costs Investors 1,800 BTC, Sparks Rush to Regulated Alternatives
- Crypto Platform Zeus Wallet Goes Offline After Security Incident
- ‘Token Jacking’: How Hackers Are Stealing AI Resources From Businesses
- Meta's AI Went Rogue During a Security Test — What SMBs Should Know
- Ransomware Kingpin Sentenced to 16 Years in Prison
- Hackers Exploit SQL Injection to Hijack Oracle Databases and Gain Full System Control
- Security Gaps in AWS, Google and Vercel AI Agent Tools Could Let Attackers Bypass Safety Checks
- Zeus Wallet Goes Offline After Cyberattack, Founder Says Funds Safe
- Chinese Router Maker Zbtlink Caught Shipping Devices With Built-In Backdoor
- Coldcard Wallet Exploit Highlights Risks of Trusting Old Firmware
- Coldcard Hardware Wallet Hack: Stolen Crypto Moved to Mixers
- Cisco Issues Urgent Patches for Critical Networking Vulnerabilities
- Ransomware-as-a-Service Kingpin Sentenced to 16 Years in Landmark US Case
- US Cybersecurity Agency Warns of Active Attacks on JetBrains TeamCity Servers
- Critical JetBrains TeamCity Flaw Now Under Active Attack
- Coldcard Bitcoin Theft: Attacker Sits on $1,159 BTC While Stolen Funds Get Laundered
- Hacker Pleads Guilty in Massive Data Breach Affecting 100 Million People
- AI-Assisted Audit Finds 85 Critical Flaws in Bitcoin Ecosystem Projects
- Cybersecurity Industry Pushes for Broader AI Benchmarks
- Volunteer Security Sweep Uncovers Nearly 5,000 Issues in Bitcoin Software
- AI Fuels a New Golden Age for Global Fraud Syndicates
- New 'PleaseFix' Attack Exposes Hidden Risk in AI-Powered Browsers
- ZEUS Wallet Suspends Services After Cybersecurity Incident, Third Lightning Outage in a Week
- AI Browsers Still Vulnerable to Prompt Injection Attacks, Researchers Warn
- How Simple Web Styling Code Could Be Used to Steal Your Email Data
- Researchers Uncover $50,000 Exploit Chain Targeting Samsung Phones via Bixby
- 15 Security Flaws Found in TP-Link Devices Raise Questions About Automated Network Setup
- Fake 'ClickFix' Sites Now Screen Visitors Before Delivering Mac Malware
- OpenAI Shuts Down Cambodia-Based Scam Network Abusing ChatGPT
- Google Patches AI 'Agent-to-Agent' Flaw That Could Have Hit Software Supply Chains
- Bitcoin Red Team Uncovers 85 Critical Bugs Across 390 Open Source Projects
- Warning: Discounted 'Claude' AI Access Sold on Cybercrime Forums Puts User Data at Risk
- Security Flaws in Paperclip AI Agent Platform Could Let Attackers Run Malicious Commands
- Black Hat USA 2026: What SMBs Should Know About the Latest Cybersecurity Vendor Announcements
- Critical Flaws Patched in Veeam, HashiCorp Terraform MCP, and Django - Update Now
- Hackers Hide Malicious Server Addresses Inside Fake Ethereum Transactions
- Cyber Warfare Is Reshaping Global Conflict — Here's Why That Matters to Businesses
- Sophisticated Cyberattacks Target Major Wall Street Hedge Funds
- Passkeys Aren't Foolproof: New Malware Attacks Target Google's Synced Passkeys
- Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
- Linux Kernel Flaw Lets Local Users Seize Full Control of Systems
- New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages
- Data Breach at Brown Health Medical Group Exposes Information of 311,000 People
- Coldcard Hardware Wallet Flaw Exploited by 15 Hackers, $130M in Bitcoin Stolen
- New Industry Alliance Sets Ground Rules for Sharing AI Security Incidents
- Critical Gitea Vulnerability Lets Attackers Steal Server Files Without Logging In
- Exposed n8n API Tokens Put Automation Workflows at Risk
- AI Models Behaving Badly: Report Flags Rogue Behaviour from Anthropic and OpenAI Systems
- US Cyber Agency Warns: Attackers Actively Exploiting Flaws in Popular Business Software
- 77 Fake Extensions Caught Stealing Developer Data from Open VSX Marketplace
- Massive Supply Chain Attack Hits Over 400 NPM Software Packages
- Angola's Top Telecom Hit by Cyberattack Right Before Major Stock Launch
- AI Agent Caught Trying to Sneak Malware Into Open-Source Software — Then Covered Its Tracks
- US Cyber Agency Warns of Active Attacks on Langflow, Tomcat, and N-central Software
- Cyberattacks Reportedly Strike Water Utilities Across at Least 12 US States
- AI-Powered Attackers Outpace Defenders, Forcing Bitcoin Swap Service Offline
- Supply Chain Attack Hits QuickFox VPN Users with Hidden Backdoor
- AI Models Went Rogue in UK Cybersecurity Test, Researchers Warn
- New Guidance Helps Business Leaders Ask the Right Questions About AI Cyber Risks
- Bitcoin Swap Service Shuts Down as AI-Powered Attackers Outpace Defenders
- New 'Smoke#Screen' Campaign Hijacks Remote Access Tools to Infiltrate Networks
- Popular Phishing Toolkit Now Bypasses MFA Using a New Trick
- Coldcard Wallet Exploit Highlights Growing Role of AI in Crypto Security
- Black Hat USA 2026: Cybersecurity Vendors Unveil Latest Innovations
- Hackers Steal Over $100 Million in Bitcoin From 'Secure' Accounts
- Firmware Flaw in Coldcard Bitcoin Wallet Raises Self-Custody Security Concerns
- Why Traditional Security Tools Aren't Enough to Manage AI Risk
- Coldcard Wallet Flaw Blamed on Faulty Code, Losses Near $120M
- Coldcard Wallet Flaw Linked to $100 Million in Bitcoin Losses
- Cybersecurity Firm Oligo Secures $60 Million to Boost Runtime Security Tools
- Why Passion, Not Perfection, Keeps CISOs Going: Lessons from Ping Identity's Security Chief
- AI Email Assistants Could Become Tools for Hackers, Researchers Warn
- AI Security Startup Zenity Secures $125 Million to Expand Protection for Business AI Tools
- Massive npm Supply Chain Attack Hits Hundreds of Packages via Keyv Worm
- Beware Fake Adobe and Zoom Update Pop-Ups Hiding Remote Access Malware
- AI-Powered Scanning Uncovers Over 14,000 Hidden Flaws in Open-Source Software
- AI Meeting Notetaker Flaw Exposed Government and Corporate Video Calls
- Security Flaw Found in Thermo Fisher Genetic Analyzer Software Could Allow DNA Data Tampering
- Hard-Coded Encryption Key Flaw Found in Vehicle Alarm Systems
- Cybersecurity Startup Obsidian Secures $85M to Tackle AI Agent Risks
- CISA Flags Three More Actively Exploited Software Flaws — Is Your Business Affected?
- 15 Security Flaws Found in TP-Link Omada Networking Gear
- AI 'Vibe Hacking': How Cybercriminals Are Using AI as a Built-In Hacking Assistant
- Google Pulls AI Agent Workflows After Researchers Expose Prompt-Injection Flaw
- Coldcard Wallet Flaw Puts $114 Million in Bitcoin at Risk — Users Told to Move Funds Now
- Security Flaw in Google's Gemini AI Agent System Could Expose Secrets
- cPanel Fixes Critical Flaw Allowing Hosting Customers to Run SQL as Database Root
- Old Server Hardware Flaw Leaves Thousands of Data Centers Exposed
- Coldcard Hardware Wallet Exploit Blamed for Over $100M in Bitcoin Theft
- New Russian 'DOUBLECUP' Malware Service Hides Malicious Code in Cached Images
- Data Breach at Madera Community Hospital Exposes Info of 150,000 People
- Coldcard Warns Bitcoin Hardware Wallet Users: Active Exploit Still Draining Funds
- Coldcard Bitcoin Wallet Hack Losses Top $100 Million as Attacks Continue
- Coldcard Hardware Wallet Exploit Tops $100M in Stolen Bitcoin
- CISA Warns: N-able N-central Flaw Actively Exploited, Patch Now
- Device Code Phishing Surges 1,500% as Attackers Bypass Traditional Security Controls
- Microsoft Pays Out $20 Million to Security Researchers in Bug Bounty Program
- Securing AI Agents: Why Preventing 'Escape' Matters for Businesses
- Nidec Reports Update on Ransomware Attack at Taiwanese Subsidiary
- Coldcard Hardware Wallet Exploit Linked to Over $100 Million in Stolen Bitcoin
- New York Invests $9 Million to Shore Up Cybersecurity at 153 Water Utilities
- Urgent: New Bypass Flaw Found in N-able RMM Software Gives Attackers Admin Access
- New Research Tool Aims to Trace AI-Generated Videos Back to Their Source
- Anthropic: AI Security Incidents Traced to Access Controls, Not Faulty Models
- Bitcoin Swap Platform Boltz Suspends Services After AI-Assisted Attack Attempts
- Malicious npm Packages Target Alibaba Developer Tool Users With Hidden Remote Access Trojan
- Coldcard Hardware Wallet Flaw Exposes Weakness in Bitcoin Key Generation
- Coldcard Wallet Exploit Drains Over 1,367 BTC, Raising Self-Custody Security Concerns
- Fake XRP Staking Sites Drain Millions from Cryptocurrency Investors
- Coldcard Wallet Exploit Shows Even 'Offline' Storage Isn't Foolproof
- Malware Could Bypass Passkey Security in Google Password Manager, Researchers Warn
- INC Ransomware Gang Ramping Up Attacks on SonicWall VPN Flaws
- AI Gateways Like LiteLLM Are Becoming Prime Targets for Attackers
- Black Hat USA 2026: What Small Businesses Should Know About the Latest Security Product Announcements
- Chinese Threat Actor Weaponises DeepSeek AI Agent in Attack on Security Firm
- Visa Acquires Fraud-Detection Firm BioCatch in $2.4 Billion Deal
- Bitcoin Bridge Service Boltz Suspends Operations After AI-Assisted Attacks
- Cyberattack Strikes Liechtenstein's Corporate Ownership Register
- This Week in Cyber: AI Overreach, an $88M Crypto Heist, and the Danger of Forgotten Digital Access
- CISO Burnout: When Accountability Outweighs Authority
- River Bank Confirms Hackers Deleted Data Stolen in June Ransomware Attack
- Cybersecurity Firm Horizon3 Secures $250 Million to Expand Growth
- UK Data Regulator Watching Closely After AI Agents Used in Hacks
- N-able Rushes Out Fix After Hackers Bypass Patch for N-central Servers
- Actively Exploited Flaw Found in N-able N-central: What SMBs Using Remote Management Tools Need to Know
- AI Tools Are Reshaping Security Operations—But Where They Fit Matters Most
- Coldcard Hardware Wallet Exploit Drains 1,367 BTC as Bitcoin Community Responds
- Phishing Scam Targets XRP Cryptocurrency Users with Fake Websites
- Hardware Wallet Flaw Blamed for Nearly $90 Million in Bitcoin Thefts
July 2026
- Cheap Streaming Boxes Could Be Turning Your Business Wi-Fi Into a Fraud Machine
- PipeWire Flaw Lets Attackers Escape Linux Sandboxes via Audio Access
- New Global Guidance Aims to Strengthen Software Supply Chain Transparency
- AI Agents Are Breaking Rules on Their Own, Researchers Call for Independent Investigations
- New Guidance Urges Businesses to Isolate Critical Operational Technology from Other Networks
- Agentic AI in Cyber Defence: Promising but Requires Caution
- Russian State-Sponsored Hackers Targeting Zimbra Email Servers to Steal Data
- Russian State-Backed Hackers Target Zimbra Email Users in Phishing Campaign
- AI Model Went Off-Script: OpenAI System Reportedly Hacked Hugging Face to 'Win' a Test
- LG Moves to Block Smart TV Apps That Turn TVs Into Hidden Proxy Servers
- WordPress's Two-Bug Combo: What the wp2shell RCE Teaches Us About Code Review
- Apple Patches macOS Terminal Flaw Used to Sneak Data Out via DNS Requests
- New Guidance Helps Businesses Check If Their Tech Vendors Are Ready for Quantum-Safe Security
- Exposed Cloud Functions: A Growing Entry Point for Attackers
- Researcher Uses AI to Chain Exploit and Reach PostHog's Production Database
- Microsoft's Latest Patch Tuesday Fixes a Record 570 Security Flaws
- AI Model Autonomously Builds Full Chrome Exploit, Raising Alarm for Defenders
- Russian State-Sponsored Hackers Targeting Network Devices, Warns Joint Advisory
- Router Security Alert: Russian State-Sponsored Hackers Targeting Network Devices
- CISA's GitHub Credential Leak: A Wake-Up Call for Secure Code Practices
- How AI 'Model Harnesses' Are Changing the Cyber Threat Landscape
- Widespread Attacks Target Website Content Management Systems – Is Your Site at Risk?
- Exposed: Shady Startup Buying Software Vulnerabilities Run by Convicted Felons
- Manually Rotated ADFS Certificates Can Leave 'Ghost' Signing Keys Exposed