Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Cybersecurity
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Cybersecurity
Liechtenstein Register Breach Exposes Data of 31,000 People
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
Cybersecurity
UKGI Left Officials’ Contact Details Exposed for 40 Hours
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
CVE Vulnerability Alerts
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
Application Security
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Application Security
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Cybersecurity
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
Cybersecurity
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
Microsoft ties CaptiveCrunch hotel Wi-Fi attacks to Storm-2945, a Midnight Blizzard sub-cluster pushing fake updates that steal Microsoft 365 credentials.
CVE Vulnerability Alerts
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.
Cybersecurity
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
Cyberattacks on US water and wastewater systems have spread to at least seven states, as investigators examine possible Iranian involvement in the campaign.
Blog
Cloud Access Security Broker (CASB) Explained: Architecture and Uses
Learn what a cloud access security broker (CASB) is, how its architecture works, key use cases, and how CASB fits into modern multi-cloud security.
Cybersecurity
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals SSH, AWS, and Azure keys.
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
Application Security
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Cybersecurity
Silver Fox BYOVD Chain Deploys ValleyRAT at Japanese Manufacturer
Silver Fox used a new three-driver BYOVD attack chain and dual watchdog persistence to deliver ValleyRAT at a Japanese manufacturer through invoice lures.
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
South Korea's data regulator fined telecom giant KT KRW 53.979 billion after an 11-month breach exposed 16,647 subscribers' data through a rogue femtocell.
Cybersecurity
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
ShinyHunters claims it breached Brinks Home in a Microsoft Entra vishing attack and stole up to 4.9 million Salesforce records and 3.8 million support chats.
Cybersecurity
Teams Vishing Campaigns Hit North American Firms With Chaos Ransomware
Sophos tracked a Teams vishing campaign as STAC4749, where fake IT support calls led to Chaos ransomware encryption at North American firms in under 17 ...
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
Microsoft ties CaptiveCrunch hotel Wi-Fi attacks to Storm-2945, a Midnight Blizzard sub-cluster pushing fake updates that steal Microsoft 365 credentials.
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
Cyberattacks on US water and wastewater systems have spread to at least seven states, as investigators examine possible Iranian involvement in the campaign.
Cloud Access Security Broker (CASB) Explained: Architecture and Uses
Learn what a cloud access security broker (CASB) is, how its architecture works, key use cases, and how CASB fits into modern multi-cloud security.
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals SSH, AWS, and Azure keys.
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Silver Fox BYOVD Chain Deploys ValleyRAT at Japanese Manufacturer
Silver Fox used a new three-driver BYOVD attack chain and dual watchdog persistence to deliver ValleyRAT at a Japanese manufacturer through invoice lures.
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
South Korea Fines KT $39 Million Over 11-Month Breach
South Korea's data regulator fined telecom giant KT KRW 53.979 billion after an 11-month breach exposed 16,647 subscribers' data through a rogue femtocell.
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
ShinyHunters claims it breached Brinks Home in a Microsoft Entra vishing attack and stole up to 4.9 million Salesforce records and 3.8 million support chats.
Teams Vishing Campaigns Hit North American Firms With Chaos Ransomware
Sophos tracked a Teams vishing campaign as STAC4749, where fake IT support calls led to Chaos ransomware encryption at North American firms in under 17 ...
Analog Devices Discloses Breach as ExfilSquad Claims Link
Analog Devices said unauthorized parties exfiltrated files in a breach detected June 23, while extortion group ExfilSquad separately claimed a connection.
Copilot for Word Copy-Paste Attack Still Exploitable
Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite mitigations.
Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones
Bitsight found generic TV streaming sticks spoofing as phones and clicking ads on AI-generated sites in a Fengwo Group ad-fraud network worth $50,000 a day.