Cyber Security
Cybersecurity
NIST Alters Approach to Vulnerability Assessments, Ceasing Severity Scores for Lower-Priority Issues
Mitchell Langley
April 21, 2026
NIST plans to halt severity scoring for lower-priority vulnerabilities due to high submission volumes.
News
Phishing Scams Are Now Exploiting Apple’s Trusted Email Servers
Gabby Lee
April 20, 2026
Apple account change alerts misused for phishing, mimicking legitimate iPhone purchase notices.
Cybersecurity
Hackers Target Trucking and Logistics Firms in Organized Crime-Linked Cyber Campaign
Andrew Doyle
April 20, 2026
Hackers linked to organized crime infiltrate logistics companies, posing rising threats of cargo theft and payment diversion.
CVE Vulnerability Alerts
Critical Nginx-UI Vulnerability Lets Attackers Seize Full Server Control
Mitchell Langley
April 16, 2026
Nginx servers vulnerable to attacks via a flaw (CVE-2026-33032) that allows authentication bypass.
Application Security
Digitally Signed Adware Disables Antivirus Across Multiple Sectors
Andrew Doyle
April 16, 2026
A system-level adware attack compromises antivirus protection on thousands of endpoints across various sectors.
Application Security
Cybercriminals Are Weaponizing n8n to Launch Phishing Attacks
Mitchell Langley
April 16, 2026
Threat actors are exploiting n8n, an AI workflow platform, to launch advanced phishing attacks.
Cybersecurity
Microsoft Awards $2.3 Million to Researchers in Zero Day Quest Hacking Contest
Andrew Doyle
April 16, 2026
Microsoft awarded $2.3 million to researchers during this year's Zero Day Quest for discovering vulnerabilities.
Cybersecurity
Sweden Points to Pro-Russian Group in Cyberattack on Energy Infrastructure
Gabby Lee
April 16, 2026
Swedish authorities attribute a cyberattack on a heating plant to a pro-Russian group, laying bare vulnerabilities in national energy infrastructure.
Cybersecurity
Autovista Battles Ransomware Attack Across Europe and Australia
Gabby Lee
April 16, 2026
Autovista enlists external support to tackle a ransomware attack impacting its systems in Europe and Australia.
Cybersecurity
CISA Expands Known Exploited Vulnerabilities Catalog with Microsoft and Apple Flaws
Mitchell Langley
April 16, 2026
CISA adds critical vulnerabilities in Microsoft SharePoint, Office Excel, Apple, Laravel, and Craft CMS to exploited vulnerabilities list.
Cybersecurity
A ‘By Design’ Flaw in Anthropic’s MCP Could Enable Widespread AI Supply Chain Attacks
Mitchell Langley
April 16, 2026
A newly discovered flaw in Anthropic's Model Context Protocol allows unsanitized command execution, endangering AI environments.
Cybersecurity
Capsule Security Secures $7 Million to Protect AI Agents at Runtime
Gabby Lee
April 16, 2026
Capsule Security emerges from stealth with $7 million funding to secure AI agents.
Cybersecurity
France’s Rising Kidnapping Cases Amid Crypto Extortion Schemes
Mitchell Langley
April 16, 2026
French mother and child rescued after 20-hour kidnap, exposing extortion threats tied to crypto wealth.
Application Security
Over 100 Malicious Chrome Extensions Are Stealing User Data and Creating Backdoors
Gabby Lee
April 16, 2026
Over 100 Chrome extensions are stealing user data and creating backdoor vulnerabilities, posing significant threats to cybersecurity.
Cybersecurity
Modern Trucking’s Cybersecurity Imperative: Industry Leaders Address Digital Threats
Andrew Doyle
April 16, 2026
Trucks transformed into digital networks face cybersecurity risks.
Application Security
Microsoft Releases Windows 10 KB5082200 to Fix April 2026 Patch Tuesday Zero-Days
Mitchell Langley
April 15, 2026
Microsoft addresses critical Windows 10 vulnerabilities with its April 2026 security patches.
Application Security
Fake Ledger Live App on macOS Drains $9.5 Million From Victims
Gabby Lee
April 15, 2026
Fake Ledger Live app drains $9.5 million from 50 victims via Apple's App Store. Investigating infiltration tactics.
Cybersecurity
Basic-Fit Data Breach Exposes Personal Information of One Million Members
Gabby Lee
April 15, 2026
A data breach at Basic-Fit has exposed sensitive data of one million members, including names, birth dates, and bank details.
Cybersecurity
McGraw-Hill Data Breach: Salesforce Misconfiguration Exploited by Hackers
Andrew Doyle
April 15, 2026
McGraw-Hill's data breach involved a Salesforce misconfiguration, exposing sensitive information.
Application Security
Critical Security Flaws in Composer Put PHP Applications at Risk
Andrew Doyle
April 15, 2026
Two severe security vulnerabilities identified in PHP's Composer might allow arbitrary command execution.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Andrew Doyle
September 11, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
TOP CYBERSECURITY HEADLINES
Application Security
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
This Week’s Security Spotlight
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Mitchell Langley
September 8, 2026
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Critical Nginx-UI Vulnerability Lets Attackers Seize Full Server Control
April 16, 2026
Nginx servers vulnerable to attacks via a flaw (CVE-2026-33032) that allows authentication bypass.
Digitally Signed Adware Disables Antivirus Across Multiple Sectors
April 16, 2026
A system-level adware attack compromises antivirus protection on thousands of endpoints across various sectors.
Cybercriminals Are Weaponizing n8n to Launch Phishing Attacks
April 16, 2026
Threat actors are exploiting n8n, an AI workflow platform, to launch advanced phishing attacks.
Microsoft Awards $2.3 Million to Researchers in Zero Day Quest Hacking Contest
April 16, 2026
Microsoft awarded $2.3 million to researchers during this year's Zero Day Quest for discovering vulnerabilities.
Sweden Points to Pro-Russian Group in Cyberattack on Energy Infrastructure
April 16, 2026
Swedish authorities attribute a cyberattack on a heating plant to a pro-Russian group, laying bare vulnerabilities in national energy infrastructure.
Autovista Battles Ransomware Attack Across Europe and Australia
April 16, 2026
Autovista enlists external support to tackle a ransomware attack impacting its systems in Europe and Australia.
CISA Expands Known Exploited Vulnerabilities Catalog with Microsoft and Apple Flaws
April 16, 2026
CISA adds critical vulnerabilities in Microsoft SharePoint, Office Excel, Apple, Laravel, and Craft CMS to exploited vulnerabilities list.
A ‘By Design’ Flaw in Anthropic’s MCP Could Enable Widespread AI Supply Chain Attacks
April 16, 2026
A newly discovered flaw in Anthropic's Model Context Protocol allows unsanitized command execution, endangering AI environments.
Capsule Security Secures $7 Million to Protect AI Agents at Runtime
April 16, 2026
Capsule Security emerges from stealth with $7 million funding to secure AI agents.
France’s Rising Kidnapping Cases Amid Crypto Extortion Schemes
April 16, 2026
French mother and child rescued after 20-hour kidnap, exposing extortion threats tied to crypto wealth.
Over 100 Malicious Chrome Extensions Are Stealing User Data and Creating Backdoors
April 16, 2026
Over 100 Chrome extensions are stealing user data and creating backdoor vulnerabilities, posing significant threats to cybersecurity.
Modern Trucking’s Cybersecurity Imperative: Industry Leaders Address Digital Threats
April 16, 2026
Trucks transformed into digital networks face cybersecurity risks.
Microsoft Releases Windows 10 KB5082200 to Fix April 2026 Patch Tuesday Zero-Days
April 15, 2026
Microsoft addresses critical Windows 10 vulnerabilities with its April 2026 security patches.
Fake Ledger Live App on macOS Drains $9.5 Million From Victims
April 15, 2026
Fake Ledger Live app drains $9.5 million from 50 victims via Apple's App Store. Investigating infiltration tactics.
Basic-Fit Data Breach Exposes Personal Information of One Million Members
April 15, 2026
A data breach at Basic-Fit has exposed sensitive data of one million members, including names, birth dates, and bank details.
McGraw-Hill Data Breach: Salesforce Misconfiguration Exploited by Hackers
April 15, 2026
McGraw-Hill's data breach involved a Salesforce misconfiguration, exposing sensitive information.
Critical Security Flaws in Composer Put PHP Applications at Risk
April 15, 2026
Two severe security vulnerabilities identified in PHP's Composer might allow arbitrary command execution.
Adobe’s ColdFusion Vulnerabilities Pose a Major Threat Amid Broader Security Concerns
April 15, 2026
Adobe patches 55 vulnerabilities across 11 products, with ColdFusion flaws deemed highly exploitable.
Microsoft Rolls Out Fast-Track Account Recovery for Windows Hardware Program Suspensions
April 15, 2026
Microsoft introduces a fast-track process for developers facing sudden account suspensions in the Windows Hardware Program.
Cyberwarfare Within the Underground: Ransomware Gangs Clash
April 15, 2026
Rival ransomware gangs in a conflict as 0APT warns of exposing Krybit affiliates.





































