News Archive
1920 stories · page 15 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, […]

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

When the Algorithm Fires You: Uber Faces €825M Fine
Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two critical authentication bypass vulnerabilities (CVSS 9.8) in the miniOrange SAML 2.0 Single Sign On WordPress plugin have been actively exploited. These flaws allow unauthenticated attackers to forge SAML responses and gain administrative access. The vulnerabilities were particularly insidious because they affected paid editions of the plugin, which were not listed in public vulnerability databases and did not trigger automatic updates, leaving administrators unaware of their exposure.

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

You could've applied all 1,449 Oracle patches and still been hit by this attack
Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

The patch window is collapsing: Why security needs a new control plane
The traditional patch management window is shrinking, forcing organizations to adopt new security strategies. The gap between vulnerability discovery and remediation is becoming a critical attack surface. A new control plane is needed to manage security effectively in this rapidly evolving landscape.

Massive DDoS attack disrupts Norway’s government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]

Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
Hostnames can be used to mask IP addresses, a technique that can be leveraged in security exploits. For instance, attackers might use hostnames to obscure malicious requests targeting cloud metadata services, such as those vulnerable to Server Side Request Forgery (SSRF). A common defense against such attacks involves blocking or filtering requests containing specific IP addresses like 169.254.169.254.

Is Cyber Facing an Affordability Crisis?
The cybersecurity industry is facing an affordability crisis, with rising breach costs and significant defense spending leaving small businesses vulnerable. This exposure poses a threat to the security of broader supply chains.

Hospital operator Nutex Health says data stolen in cyberattack
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]

ZeroTokens Phishing Platform Steers Attacks in Real Time
ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands

Interpol targets Black Axe’s illicit financial web in latest international sting
The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents. The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.

Alice Secures $140M for AI Model Defense and Enterprise Security
Alice, formerly ActiveFence, has successfully raised $140 million in new funding, bringing its total investment to $280 million. The company plans to use these funds to enhance its defenses for AI models and bolster its enterprise security solutions.

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
A vulnerability in NVIDIA NemoClaw could allow a malicious webpage to hijack a local AI agent by modifying its chat template. This could lead to hidden instructions being injected into the AI model, affecting all future conversations. While fixes are available for macOS and Linux, Windows and WSL paths remain vulnerable.

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,

Citrix UniconOS dual boot turns Windows endpoints into their own recovery device
Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix UniconOS Release 7 2607, dual boot turns every compatible Windows endpoint into its own recovery device: an isolated, hardened Citrix UniconOS env

Fideo Lens reveals connections across identities, accounts and devices
Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships among identities, accounts, devices and behaviors. Starting with a single identity signal, investigators can use Fideo Lens to visualize and connect data associated with the identity and transform fragmented identity data into interactive investi

Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Segmentation limits attacker movement, contains AI-era threats, and strengthens cyber resilience with Zero Trust.

WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
When Android users get a call from a non-contact, they will see more information about the caller, including their country. The post WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update appeared first on SecurityWeek.

First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.

The County Prosecutors Who Became ICE Informants
Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.