Cyber Security
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Critical FortiMail Zero-Day Exploited With No Patch Yet
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Kiteworks Patches Second Max-Severity Flaw in a Week
Self-Healing WordPress Backdoor Defies Standard Removal
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
MetaMask Discloses Incident, Exits Ethereum Validators
TeamViewer Patches Critical Access-Control Bypass Flaw
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Pentagon Records Agency Breach Exposes Data on 3 Million
France Tax Agency Breached Seven Weeks via Stolen Passwords
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
FBI Tells ShinyHunters Members to Turn Themselves In
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
101 Malicious npm Packages Add Developers to WhatsApp Groups
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Application Security
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.
CVE Vulnerability Alerts
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.
Cybersecurity
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.
Application Security
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
Application Security
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
Cybersecurity
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Application Security
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Cybersecurity
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
Cybersecurity
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
Cybersecurity
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Cybersecurity
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Cybersecurity
Liechtenstein Register Breach Exposes Data of 31,000 People
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
Cybersecurity
UKGI Left Officials’ Contact Details Exposed for 40 Hours
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
CVE Vulnerability Alerts
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
Application Security
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Application Security
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Cybersecurity
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Liechtenstein Register Breach Exposes Data of 31,000 People
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
UKGI Left Officials’ Contact Details Exposed for 40 Hours
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
Microsoft ties CaptiveCrunch hotel Wi-Fi attacks to Storm-2945, a Midnight Blizzard sub-cluster pushing fake updates that steal Microsoft 365 credentials.
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
Cyberattacks on US water and wastewater systems have spread to at least seven states, as investigators examine possible Iranian involvement in the campaign.