Cyber Security
ShinyHunters Claims 2.2 Million Kodak Records, Sets Leak Deadline
CISA Adds Joomla JCE CVE-2026-48907 to KEV Amid Active Scans
DragonForce’s Backdoor.Turn Routes C2 via Microsoft Teams TURN
iRhythm Confirms PHI Exfiltration via Social Engineering
Rokarolla Android Trojan Hits 217 Banking and Crypto Apps
Steam Workshop Wallpaper Packages Drop DarkKomet and Lumma
GhostTree NTFS Junctions Paralyze Windows Defender Scans
CVE-2026-2473: Vertex AI SDK Pickle Attack Enables Cross-Tenant RCE
Endpoint Security Solutions: How to Protect Every Enterprise Device
UNC6508 Abused Google Workspace Rules in Medical-Military Espionage
Three FortiSandbox CVEs Chained for Unauthenticated Root Execution
Cisco CVE-2026-20262 Added to CISA KEV; Eighth Exploited SD-WAN Flaw
LiteSpeed cPanel CVE-2026-54420 Escalates to Root on Shared Hosts
APT37 Deploys NarwhalRAT via Fake Microsoft Security Alerts
DOJ Seizes CFAKE.com and SOCFAKE.com in First TAKE IT DOWN Act Case
The Quarry PhaaS: IRS Lures, ConnectWise RAT, 500+ Victims
ESET Finds WIN_DRV: Earth Lusca’s First Windows SprySOCKS Rootkit
Obsidian Finds CVSS 9.9 Attack Chain in LiteLLM AI Gateway
CVE-2026-48558 Exposes 14,000 SimpleHelp RMM Servers to Auth Bypass
ShinyHunters Claims 61M Sysco Salesforce Records in Unverified Breach
What Is Scareware? How Fake Security Warnings Lead to Real Malware
Lapsus$ Lists GitHub Internal Repos for Sale, Copilot Source Included
Nightspire Claims Blue Nile Medical and Silsbee Police as New Victims
Ukrainian Conti Developer Pleads Guilty to Ransomware Loader Coding
Awesome Motive CDN Compromised; Backdoor Served to OptinMonster Users
CVE-2026-42824: M365 Copilot SearchLeak Enables 1-Click Email Theft
Novo Nordisk Confirms Hack of Clinical Trial Biomarker Data
SearchJack: 23 Chrome Extensions Intercept 758,000 Users’ Searches
TheGentlemen Ransomware Posts 20 Victims Across 14 Countries
PromptSnatcher Extensions Stole AI Chats From 90,000 Users
Wayne County Cyberattack Cripples Government Services; Ransom Demand Fuels Investigation
News
Wayne County Cyberattack Cripples Government Services: Ransom Demand Fuels Investigation
Wayne County cyberattack crippled government services, with hackers demanding a ransom. The FBI and Michigan State Police are investigating.
Verizon Outage Leaves Hundreds of Thousands Without Service
News
Verizon Outage Leaves Hundreds of Thousands Without Service
A major Verizon outage left over 200,000 customers without cell service for over 10 hours. Verizon cited a "network issue" but offered no further details ...
Feldstein & Stewart Data Breach Letter Sent to 8,171 Individuals
News
Feldstein & Stewart Data Breach Letter Sent to 8,171 Individuals
Feldstein & Stewart sent a data breach letter to 8,171 individuals following a serious security incident that compromised sensitive consumer information.
CF Medical Announces Data Breach Stemming from FBCS Data Breach
News
CF Medical Announces Data Breach Stemming from FBCS Data Breach
CF Medical announced a data breach linked to FBCS data breach, exposing sensitive consumer information. Notifications have been sent to affected individuals.
Wells Fargo Announces Data Breach Cause by Unauthorized Access by Former Employee
News
Wells Fargo Announces Data Breach Cause by Unauthorized Access by Former Employee
Wells Fargo has reported a data breach due to unauthorized access by a former employee. Sensitive customer information was compromised, prompting immediate notifications.
New York Sports Club Data Breach: 19,836 Individuals Affected
News
New York Sports Club Data Breach: 19,836 Individuals Affected
The New York Sports Club data breach has affected 19,836 individuals, exposing sensitive employee information such as Social Security numbers and passport numbers.
Community Clinic of Maui Data Breach: LockBit Ransomware Attack Exposes Patient Data
News
Community Clinic of Maui Data Breach: LockBit Ransomware Attack Exposes Patient Data
The Community Clinic of Maui suffered a significant data breach after a LockBit ransomware attack in May, exposing sensitive patient information. The clinic is working ...
FCC Fines T-Mobile US $31.4 Million for Data Breaches
News
FCC Fines T-Mobile US $31.4 Million for Data Breaches
The FCC fined T-Mobile US $31.4 million for multiple data breaches, impacting millions of customers and mandating significant cybersecurity improvements.
Top 5 Dangerous Cyberattack Techniques in 2024
Blog
Top 5 Dangerous Cyberattack Techniques in 2024
SANS Institute reveals the top 5 dangerous cyberattack techniques for 2024. Learn how to protect your enterprise from these evolving threats.
AFP Cyberattack: Security Breach at French News Agency Exposes Critical Infrastructure Vulnerabilities
Cybersecurity
AFP Cyberattack: Security Breach at French News Agency Exposes Critical Infrastructure Vulnerabilities
The AFP cyberattack disrupted the French news agency's systems, highlighting the growing threat to media outlets and critical infrastructure. The perpetrators and motives remain unknown.
Critical Flaw in NVIDIA Container Toolkit Allows Full Host Takeover
News
Critical Flaw in NVIDIA Container Toolkit Allows Full Host Takeover
A critical flaw (CVE-2024-0132) in NVIDIA Container Toolkit allows container escape, granting full host access and enabling attackers to execute commands and exfiltrate data.
UMC Hospital Lubbock Still Crippled by Devastating Ransomware Attack
News
UMC Hospital Lubbock Still Crippled by Devastating Ransomware Attack
UMC hospital in Lubbock faces a crippling ransomware attack, diverting ambulances and impacting patient care. The emergency room remains open, but the IT outage persists. ...
What is DNS SpoofingDNS Cache Poisoning and How Can It Compromise Your Network
Blog
What is DNS Spoofing/DNS Cache Poisoning and How Can It Compromise Your Network?
DNS spoofing, also known as DNS cache poisoning, is a malicious technique that exploits vulnerabilities in the DNS system to redirect users to fraudulent websites, ...
This Week In Cybersecurity: 23rd September to 27th September
Cybersecurity
This Week In Cybersecurity: 23rd September to 27th September
Harvey Nichols Data Breach: High-End Retailer Confirms Customer Data Exposure in Cyberattack Harvey Nichols has confirmed a data breach affecting ...
Meta Fined €91 Million: DPC Concludes Inquiry into Data Breach
News
Meta Fined €91 Million: DPC Concludes Inquiry into Data Breach
Meta Platforms Ireland Limited has been fined €91 million by the Data Protection Commission for failing to protect user passwords adequately, highlighting the importance of ...
MC2 Data Leak: Over 100 Million Americans Exposed in Massive Data Breach
News
MC2 Data Leak: Over 100 Million Americans Exposed in Massive Data Breach
The MC2 Data breach has exposed the sensitive personal information of over 100 million Americans, representing nearly a third of the US population.
FBI and Homeland Security Investigate Critical Water Facility Cyberattack in Kansas
News
FBI and Homeland Security Investigate Critical Water Facility Cyberattack in Kansas
FBI and Homeland Security investigate a Kansas water facility cyberattack, forcing manual operations but ensuring uninterrupted service. The incident highlights critical infrastructure vulnerabilities.
AutoCanada Ransomware Attack: Employee Data Compromised
News
AutoCanada Ransomware Attack: Employee Data Compromised
AutoCanada's August ransomware attack, claimed by Hunters International, may have exposed employee data including payroll, addresses, and social security numbers.
US Capitol Dark Web Cyber Attack: Thousands of Staffers' Data Leaked
News
US Capitol Dark Web Cyber Attack: Thousands of Staffers’ Data Leaked
A massive Dark Web Cyber Attack on the US Capitol has exposed personal information of over 3,000 congressional staffers.
MoneyGram Cyberattack: Outage Enters Day Three, Ransomware Suspected
News
MoneyGram Cyberattack: Outage Enters Day Three, Ransomware Suspected
MoneyGram, a leading global money transfer company, is facing a major outage that has disrupted its systems and payment services for three days. The company ...
Application Security
Mastra AI npm Supply Chain Attack Hits 1.1M Weekly Downloads
Cybersecurity
DragonForce’s Backdoor.Turn Routes C2 via Microsoft Teams TURN
Cybersecurity
Rokarolla Android Trojan Hits 217 Banking and Crypto Apps

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
iRhythm Confirms PHI Exfiltration via Social Engineering
Application Security
Obsidian Finds CVSS 9.9 Attack Chain in LiteLLM AI Gateway
Application Security
PromptSnatcher Extensions Stole AI Chats From 90,000 Users
Cybersecurity
Anthropic Releases Guardrail-Free Mythos 5 to Security Researchers
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

Podcasts

Sorry, we couldn't find any posts. Please try a different search.

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Elon Musk Claims ‘Massive Cyberattack’ on X Originated from Ukraine
Elon Musk confirmed a massive cyberattack on X, originating from the Ukraine area, causing widespread service disruptions and highlighting the vulnerability of major tech platforms.
New York Sues Allstate and National General Over Data Breaches
New York sues Allstate and National General for failing to protect consumer data, resulting in two major data breaches exposing thousands of driver's license numbers.
Cl0p Ransomware Published Rackspace Files on Leak Site
Cl0p ransomware publishes Rackspace files after ignored demands, exposing hundreds of Cleo victims. This data breach highlights the ongoing threat to enterprise and cloud security.
WordPress Vulnerability Expolited to Hack Moroccan Data Protection Authority Website
Morocco's data protection authority website suffered a WordPress plugin vulnerability exploit, resulting in reputational damage despite no sensitive data loss.
Japanese telco NTT Communications hacked hackers accessed details of almost 18,000 organizations
panese telecommunications giant NTT Communications Corporation (NTT Com) has disclosed a data breach affecting information from nearly 18,000 corporate clients. The breach was identified on ...
NBA and NASCAR Accounts on X Hacked to Promote Cryptocurrency Scams
The official NBA and NASCAR accounts on X were hacked to promote fake cryptocurrencies, raising serious concerns about cybersecurity and user safety on social media.
$5 Million Stolen from 1inch Due to Smart Contract Flaw
On March 5, 2025, 1inch confirmed a $5 million theft due to a smart contract flaw, affecting only resolver funds, not end-user assets.
US Cities Warn of Parking Phishing Texts Used to Steal Personal Data
US cities warn residents about a new wave of phishing texts claiming unpaid parking fees, threatening fines and attempting to steal personal information.
Chicago Public Schools Data Breach Exposes Hundreds of Thousands of Student Records
Hundreds of thousands of Chicago Public School students' data was exposed in a recent data breach, affecting names, birthdates, and student IDs. The FBI and ...
Bank of America Issues Warning on Data Breach: Millions of Accounts at Risk
Bank of America has announced a massive data breach affecting millions, with customers' sensitive information potentially compromised due to a vendor's mishandling of documents.
Data Breach Settlement: Rite Aid Agrees to Pay $6.8 Million to Affected Customers
Rite Aid has agreed to a $6.8 million settlement following a data breach affecting over 2 million customers, emphasizing the need for robust cybersecurity measures.
New Chirp Tool Using Audio Tones for Data Transit Between Devices
The new Chirp tool allows data transfer between devices using audio tones, offering a unique and engaging way to communicate.
1 Million Devices Hit: Inside the Massive Malvertising Campaign
A massive malvertising campaign has compromised one million devices worldwide, using malicious ads on illegal streaming websites to distribute malware. Dubbed Storm-0408, this cybercrime operation ...
Inside the $635K Taylor Swift Ticket Heist: Cybercrime, Loopholes, and Insider Threats
A cybercrime operation involving the theft and resale of $635,000 worth of concert tickets—primarily for Taylor Swift’s Eras Tour—has been uncovered. New York prosecutors revealed ...
Akira Ransomware Uses Webcam to Bypass EDR
The Akira ransomware gang has found a way to bypass EDR by exploiting unsecured webcams, demonstrating a new level of sophistication in cyberattacks.
Microsoft Reports Malvertising Campaign Impacted 1 Million PCs
Microsoft reports a large malvertising campaign has impacted nearly one million PCs, using malicious ads on streaming sites to deploy malware.
Taylor Swift Ticket Scam: Cybercrime Crew Steals $635,000
A cybercrime crew stole $635,000 worth of concert tickets, primarily for Taylor Swift's Eras Tour, exploiting a StubHub vendor loophole. Two employees were arrested and ...
Scott County Breach: Email Account Compromises Patient Data
The Scott County breach involved unauthorized access to email accounts, compromising protected health information for thousands of individuals across Iowa.
Silk Typhoon Strikes: From Direct Breaches to Stealthy Supply Chain Attacks
In this episode, we take an in-depth look at Silk Typhoon, the Chinese state-sponsored cyber espionage group that’s radically shifting its tactics. Moving away from ...
12,000 API Keys and Passwords Found in AI Training Datasets
Nearly 12,000 API keys and passwords were discovered in the Common Crawl dataset used for training AI models, highlighting significant security risks for enterprises. Many ...