News Archive
1920 stories · page 17 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

New Zealand to pursue social media ban for children under 16
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.

Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]

Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.

Bipartisan Senate bill aims to prepare energy sector for Q-Day
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.

The Cloudflare Blog – Brought to you by EmDash
We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience.

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.

TikTok reaches $400M settlement with US over COPPA violations
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.

Iran-linked cyberattack shut down a UK power plant
A suspected Iran-linked cyberattack recently disrupted a small-scale UK power plant, causing it to shut down for four days. While the government confirmed the incident, it emphasized that the wider energy system remained unaffected and highly resilient. This event follows a series of similar cyber intrusions targeting water utilities in the United States, which cybersecurity analysts also suspect are linked to Iran.

Fake GTA 6 Extended Look and demo sites deliver an infostealer
Cybercriminals are exploiting the hype surrounding the upcoming Grand Theft Auto VI release by distributing fake demo websites that deliver an information-stealing malware. These sites impersonate Rockstar Games and trick users into downloading a malicious executable disguised as a game installer. The malware, identified as belonging to the Vidar family, is designed to steal passwords, session cookies, and other sensitive data from browsers and applications, potentially bypassing two-factor authentication through the reuse of stolen session tokens.

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 has published a technical analysis of CVE-2026-63520, a critical remote code execution vulnerability in Microsoft SharePoint. The vulnerability allows an authenticated attacker to execute arbitrary code on a vulnerable server by uploading a malicious BDC model file. When combined with another vulnerability, CVE-2026-55040, it can lead to unauthenticated RCE.

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
The Trusted Computing Group (TCG) has released new guidance to help organizations verify if their hardware, specifically Trusted Platform Modules (TPMs), is genuinely quantum-safe. This new benchmark addresses concerns that some TPMs claiming quantum-safe compliance may not offer full security capabilities. The guidance introduces designations for 'TCG PQC-ready TPM' and 'TCG PQC-upgradable TPM' to clarify readiness for post-quantum cryptography.

NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions

ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

Tricky 'SynkLoader' Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access to your savings. Read more in my article on the Hot for Security blog.

Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users

Fake Microsoft security scans trick victims into uninstalling their antivirus
Scammers are operating fake Microsoft-branded websites that mimic security scans to trick users into uninstalling their antivirus software. These sites present fabricated security issues, falsely claim third-party antivirus is unsupported, and then guide victims toward a refund scam. The ultimate goal is to obtain personal information, banking details, and remote access to the victim's computer.

Your data doesn’t die when you do (Lock and Code S07E17)
This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.

ToxicPanda Banking Trojan Matures into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
This week's cybersecurity landscape features AI-powered attacks targeting industrial control systems, a critical vulnerability in GitLab being actively exploited, and the discovery of trojanized npm packages delivering a sophisticated Linux backdoor. Additionally, researchers revealed a method to exploit expired credit cards for contactless payments, and several other vulnerabilities across various software platforms were highlighted.

AliExpress caught using silent audio to fingerprint visitors’ browsers
Silent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.

24th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The […] The post 24th August – Threat

Microsoft Teams now lets admins block external bots from meetings
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]