Cyber Security
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
Meta AI Hacked External Systems During Cybersecurity Testing
Brown Health Medical Group Breach Exposes 311,000 Records
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Liechtenstein Register Breach Exposes Data of 31,000 People
UKGI Left Officials’ Contact Details Exposed for 40 Hours
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Huntress traced credential-theft alerts to attackers who compiled the khunt toolkit inside Oracle to reach SYSTEM-level code execution on a Windows server.
Cybersecurity
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
VulnCheck disclosed a factory-shipped ENDLESSDOORS backdoor in Zbtlink router firmware that lets a remote attacker open an unauthenticated root shell.
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
A federal judge in Virginia sentenced Belarusian Maksim Silnikau, the creator of Ransom Cartel, to 16 years for running a ransomware-as-a-service operation.
Cybersecurity
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more than 100 million people.
Application Security
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Application Security
Meta AI Hacked External Systems During Cybersecurity Testing
Meta admitted its Muse Spark 1.1 model escaped a test environment and breached an unnamed third party's systems during evaluations by startup Irregular.
Cybersecurity
Brown Health Medical Group Breach Exposes 311,000 Records
Brown Health Medical Group of Massachusetts disclosed a historic file-server breach exposing personal, medical, and financial data belonging to 311,760 people.
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without the model.
Cybersecurity
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
CVE Vulnerability Alerts
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in a new advisory release.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
Application Security
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Cybersecurity
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Application Security
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Application Security
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
Application Security
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
CVE Vulnerability Alerts
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Cybersecurity
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Brown Health Medical Group Breach Exposes 311,000 Records
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more than 100 million people.
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Meta AI Hacked External Systems During Cybersecurity Testing
Meta admitted its Muse Spark 1.1 model escaped a test environment and breached an unnamed third party's systems during evaluations by startup Irregular.
Brown Health Medical Group Breach Exposes 311,000 Records
Brown Health Medical Group of Massachusetts disclosed a historic file-server breach exposing personal, medical, and financial data belonging to 311,760 people.
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Stealth researchers disclosed CoreBreak flaws in AWS Bedrock, Google ADK, and Vercel harnesses that let attackers invoke agent tools without the model.
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in a new advisory release.
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled Chinese hacking campaign.
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
A Claude Mythos 5 agent spent 34 hours trying to merge malware into an open-source project during a UK AI Security Institute evaluation, then covered ...
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
Google removed three ADK AI workflows after Pillar Security showed a GitHub issue could prompt-inject a triage agent into launching a privileged agent.
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.