Cyber Security
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
September Windows Server Updates Break Remote Desktop Services
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
cPanel Critical RCE Enables Full Server Takeover via Mail Account
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Microsoft Ships Record 974 Security Patches in September Batch
ShinyHunters Claims Breach of Florida DMV DAVID Database
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
LG Accused of Privacy Violations Over Smart TV Data Collection
Microsoft Adds Age-Awareness APIs to Windows 11
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Critical Vulnerability in Honeywell CCTVs Exposes Security Risks
CVE Vulnerability Alerts
Critical Vulnerability in Honeywell CCTVs Exposes Security Risks
CISA alerts to a critical flaw in Honeywell CCTVs enabling unauthorized access with potential for account hijacking and system compromise.
The UK Classifies Non-Consensual Intimate Images Alongside Serious Offenses
Cybersecurity
The UK Classifies Non-Consensual Intimate Images Alongside Serious Offenses
UK demands quick removal of non-consensual images, equating them with terror content.
Venice Security Raises $33M to Strengthen Its Privileged Access Management Platform
Cybersecurity
Venice Security Raises $33M to Strengthen Its Privileged Access Management Platform
Venice Security, formerly known as Valkyrie, has secured $33 million in funding to enhance its Privileged Access Management solutions.
Figure Data Breach Exposes Nearly 1 Million User Records
Cybersecurity
Figure Data Breach Exposes Nearly 1 Million User Records
Blockchain lender Figure confirms data breach with over 2GB of user information leaked by ShinyHunters.
Cybercriminals Exploit OAuth 2.0 Device Authorization Flow in Vishing Campaigns
News
Cybercriminals Exploit OAuth 2.0 Device Authorization Flow in Vishing Campaigns
Hackers target tech, manufacturing, and finance sectors using device code phishing and vishing in OAuth 2.0 abuse campaigns.
Texas Sues TP-Link Over Router Security Deception Tied to Chinese State-Backed Hackers
Cybersecurity
Texas Sues TP-Link Over Router Security Deception Tied to Chinese State-Backed Hackers
Texas accuses TP-Link of falsely advertising its routers' security, allowing Chinese state-backed hackers to exploit firmware vulnerabilities and acce...
DEF CON Bars Three Men Named in Epstein Documents
Cybersecurity
DEF CON Bars Three Men Named in Epstein Documents
DEF CON bans three men linked to Epstein files, raising important questions about ethics and attendee policies at major cybersecurity conferences.
Ivanti Zero-Day Exploitation Peaks as Cyber Threats Surge
Cybersecurity
Ivanti Zero-Day Exploitation Peaks as Cyber Threats Surge
Surge in Ivanti zero-day vulnerability exploits traced back to July 2025.
Nigerian Hacker Gets Eight-Year Prison Sentence for Tax Fraud
Cybersecurity
Nigerian Hacker Gets Eight-Year Prison Sentence for Tax Fraud
A Nigerian national has been sentenced to eight years in prison for hacking into tax preparation firms and submitting $8.1 million in fraudulent tax r...
Germany Warns of Phishing Threats via Signal Targeting High-profile Individuals
News
Germany Warns of Phishing Threats via Signal Targeting High-Profile Individuals
Germany's cyber authorities have alerted citizens about a sophisticated phishing attack using Signal. High-ranking officials, journalists, and politicians are prime targets. This advisory emphasizes the ...
Chinese Cyber Espionage Group Exploits Dell Security Vulnerability
Cybersecurity
Chinese Cyber Espionage Group Exploits Dell Security Vulnerability
Chinese state-backed hackers have been identified exploiting a Dell security flaw in a series of zero-day attacks since mid-2024. These attacks underline concerns regarding the ...
Cybercriminals Create Impersonated Oura MCP Server to Deploy StealC Info-Stealer
Cybersecurity
Cybercriminals Create Impersonated Oura MCP Server to Deploy StealC Info-Stealer
Cybercriminals replicated a legitimate Oura MCP server in a deceptive campaign to distribute StealC malware. STAR Labs discovered the SmartLoader operation, presenting crucial cybersecurity insights.
VulnCheck Secures $25 Million to Enhance Vulnerability Intelligence
Cybersecurity
VulnCheck Secures $25 Million to Enhance Vulnerability Intelligence
VulnCheck, a company specializing in vulnerability intelligence, has successfully raised $25 million in a Series B funding round. The investment, led by Sorenson Capital, demonstrates ...
Notepad++ Bolsters Security With New Double-lock Update System
Application Security
Notepad++ Bolsters Security With New Double-lock Update System
After a recent supply-chain attack, Notepad++ has revamped its update mechanism with a double-lock design. This new approach is intended to tighten security and prevent ...
AI Assistants as Covert C2 Tools Implications for Enterprise Security
Cybersecurity
AI Assistants as Covert C2 Tools: Implications for Enterprise Security
Cybersecurity experts have found methods to transform AI assistants with web capabilities into covert command-and-control (C2) tools. Such exploits could let attackers mask their activities ...
Unveiling the Extent of Leaked API Keys in Front-End Applications
Cybersecurity
Unveiling the Extent of Leaked API Keys in Front-End Applications
Intruder's comprehensive scan of JavaScript bundles across 5 million applications reveals a staggering number of exposed API keys, uncovering a critical security threat.
Microsoft Teams Service Outage Frustrates Users Worldwide
Application Security
Microsoft Teams Service Outage Frustrates Users Worldwide
Microsoft Teams has been experiencing an ongoing outage worldwide that has led to significant delays and access issues. Users are frustrated by these disruptions, with ...
Polish Authorities Detain Suspected Phobos Ransomware Operative
News
Polish Authorities Detain Suspected Phobos Ransomware Operative
Polish authorities have arrested a 47-year-old man suspected of participating in cybercrimes associated with the Phobos ransomware. During the operation, officers seized devices containing evidence ...
Millions of Eurail User Records at Stake as Hackers Threaten Sale
Cybersecurity
Millions of Eurail User Records at Stake as Hackers Threaten Sale
Hackers claim to have stolen millions of Eurail user records and are reportedly offering these for sale. Eurail is currently trying to gauge the breach's ...
Rise in API Exploitation Driven by Weak Security and Enhanced AI Capabilities
Cybersecurity
Rise in API Exploitation Driven by Weak Security and Enhanced AI Capabilities
New research details the growing misuse of APIs by attackers leveraging machine speed and AI capabilities. Enhanced API attacks increase exposure and amplify impact, indicating ...
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Figure Data Breach Exposes Nearly 1 Million User Records
Blockchain lender Figure confirms data breach with over 2GB of user information leaked by ShinyHunters.
Cybercriminals Exploit OAuth 2.0 Device Authorization Flow in Vishing Campaigns
Hackers target tech, manufacturing, and finance sectors using device code phishing and vishing in OAuth 2.0 abuse campaigns.
Texas Sues TP-Link Over Router Security Deception Tied to Chinese State-Backed Hackers
Texas accuses TP-Link of falsely advertising its routers' security, allowing Chinese state-backed hackers to exploit firmware vulnerabilities and acce...
DEF CON Bars Three Men Named in Epstein Documents
DEF CON bans three men linked to Epstein files, raising important questions about ethics and attendee policies at major cybersecurity conferences.
Ivanti Zero-Day Exploitation Peaks as Cyber Threats Surge
Surge in Ivanti zero-day vulnerability exploits traced back to July 2025.
Nigerian Hacker Gets Eight-Year Prison Sentence for Tax Fraud
A Nigerian national has been sentenced to eight years in prison for hacking into tax preparation firms and submitting $8.1 million in fraudulent tax r...
Germany Warns of Phishing Threats via Signal Targeting High-Profile Individuals
Germany's cyber authorities have alerted citizens about a sophisticated phishing attack using Signal. High-ranking officials, journalists, and politicians are prime targets. This advisory emphasizes the ...
Chinese Cyber Espionage Group Exploits Dell Security Vulnerability
Chinese state-backed hackers have been identified exploiting a Dell security flaw in a series of zero-day attacks since mid-2024. These attacks underline concerns regarding the ...
Cybercriminals Create Impersonated Oura MCP Server to Deploy StealC Info-Stealer
Cybercriminals replicated a legitimate Oura MCP server in a deceptive campaign to distribute StealC malware. STAR Labs discovered the SmartLoader operation, presenting crucial cybersecurity insights.
VulnCheck Secures $25 Million to Enhance Vulnerability Intelligence
VulnCheck, a company specializing in vulnerability intelligence, has successfully raised $25 million in a Series B funding round. The investment, led by Sorenson Capital, demonstrates ...
Notepad++ Bolsters Security With New Double-lock Update System
After a recent supply-chain attack, Notepad++ has revamped its update mechanism with a double-lock design. This new approach is intended to tighten security and prevent ...
AI Assistants as Covert C2 Tools: Implications for Enterprise Security
Cybersecurity experts have found methods to transform AI assistants with web capabilities into covert command-and-control (C2) tools. Such exploits could let attackers mask their activities ...
Unveiling the Extent of Leaked API Keys in Front-End Applications
Intruder's comprehensive scan of JavaScript bundles across 5 million applications reveals a staggering number of exposed API keys, uncovering a critical security threat.
Microsoft Teams Service Outage Frustrates Users Worldwide
Microsoft Teams has been experiencing an ongoing outage worldwide that has led to significant delays and access issues. Users are frustrated by these disruptions, with ...
Polish Authorities Detain Suspected Phobos Ransomware Operative
Polish authorities have arrested a 47-year-old man suspected of participating in cybercrimes associated with the Phobos ransomware. During the operation, officers seized devices containing evidence ...
Millions of Eurail User Records at Stake as Hackers Threaten Sale
Hackers claim to have stolen millions of Eurail user records and are reportedly offering these for sale. Eurail is currently trying to gauge the breach's ...
Rise in API Exploitation Driven by Weak Security and Enhanced AI Capabilities
New research details the growing misuse of APIs by attackers leveraging machine speed and AI capabilities. Enhanced API attacks increase exposure and amplify impact, indicating ...
Allegations of Data Violations by Lenovo: US Law Firm Raises Concerns
Lenovo is under scrutiny as a US law firm alleges the company breached DOJ guidelines concerning data transfers to foreign adversaries, specifically China. Lenovo has ...
New Android Malware Identified in Device Firmware Raising Alarms
Android malware known as Keenadu has been discovered within the firmware of various brands, enabling it to breach installed apps and seize control of affected ...
Italian University Struggles With Disruption After Cyberattack
Rome’s La Sapienza University, a key academic institution in Italy, has been grappling with severe disruptions following a significant cyberattack on February 2. This attack ...