Cyber Security
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Pentagon Records Agency Breach Exposes Data on 3 Million
France Tax Agency Breached Seven Weeks via Stolen Passwords
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
FBI Tells ShinyHunters Members to Turn Themselves In
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
101 Malicious npm Packages Add Developers to WhatsApp Groups
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Vietnamese National Charged in $16 Million Crypto Scam
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Ransomware Attack Disrupts Keio Corporation Business Systems
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
Cybersecurity
MetaMask Discloses Incident, Exits Ethereum Validators
MetaMask disclosed a security incident affecting its staking infrastructure and is proactively exiting Ethereum validators it runs through the Lido protocol.
CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
CVE Vulnerability Alerts
WatchGuard Patches Critical Root Code Execution Flaw
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CVE Vulnerability Alerts
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Cybersecurity
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
CVE Vulnerability Alerts
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Application Security
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
Cybersecurity
France Tax Agency Breached Seven Weeks via Stolen Passwords
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
CVE Vulnerability Alerts
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Cybersecurity
FBI Tells ShinyHunters Members to Turn Themselves In
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Application Security
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
Application Security
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
101 Malicious npm Packages Add Developers to WhatsApp Groups
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
WatchGuard Patches Critical Root Code Execution Flaw
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Pentagon Records Agency Breach Exposes Data on 3 Million
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
France Tax Agency Breached Seven Weeks via Stolen Passwords
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
FBI Tells ShinyHunters Members to Turn Themselves In
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
101 Malicious npm Packages Add Developers to WhatsApp Groups
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Glow Security found over 13,000 sensitive screenshots from AI coding agents publicly exposed on GitHub across 343 companies in a finding called PixelLeak.
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Two former US Air Force members received a combined 189-month federal prison sentence for running a multi-year business email compromise and phishing scheme.