News Archive
1923 stories · page 20 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

How an Emerging Industrial Protocol Family Could Put OT at Risk
New research highlights potential security risks associated with Time-Sensitive Networking (TSN) protocols used in industrial environments. Unprotected TSN implementations could be exploited by attackers to disrupt or manipulate critical physical processes, posing a significant threat to operational technology (OT) systems.

Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

Apollo discloses data breach from ongoing wave of attacks hitting financial sector
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researchers have identified 14 malicious npm packages disguised as calendar and streak utilities that deliver a sophisticated Linux backdoor known as RedC2 4.0. These packages, once imported, stealthily execute a Linux implant that communicates with a command-and-control server for post-exploitation activities. The RedC2 framework, marketed as a cross-platform toolkit, features AI-assisted capabilities for orchestrating complex intrusions using natural language commands.

Your Shredded Visa Card May Still Work at the Checkout
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

OWASP Flags Top AI Skill Risks in New Security Blueprint
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.

AI Is Learning to Write Genetic Code
This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the mode

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf

Former NSA Director Paul Nakasone Launches National Security Advisory Firm
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm appeared first on SecurityWeek.

U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised.

Hundreds of leaked AWS keys give full control over corporate accounts
Truffle Security has identified over 9,300 active AWS access keys exposed publicly between August 2022 and August 2026. Of these, 817 keys were linked to companies, with 526 being root keys and 242 granting full administrative privileges. This level of access allows attackers to potentially steal, delete, or manipulate cloud data and services, or deploy resource-intensive applications like cryptominers.

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
A new malware family targeting Android-based car head units has been discovered, exploiting built-in firmware updaters for distribution. This malware, attributed to the MoYu Group, aims to facilitate ad fraud and establish a proxy botnet. Researchers noted this is the first documented case of malware specifically designed for car head units with a tailored infection chain.

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.

Lawmakers seek watchdog review of federal hacking of Americans
Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.

Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.

Malware injected into popular Rust packages to steal developer credentials
Malicious actors have compromised several widely-used Rust packages, including arrayref, internment, and append-only-vec, by injecting malware into their build scripts. These poisoned packages, disguised as legitimate updates, were designed to steal developers' credentials. The attack leveraged a typosquatted dependency, proc-macro1, which fetched malware from a remote server during the compilation process. The compromised packages were quickly removed from the registry, but their popularity raises concerns about the potential impact on developers.

Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek.

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.

Zombie Card: An expired Visa credit card can be used for purchases
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.

Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]

Calling on Cyber Pros to Help Defend City Hall
Government agencies with smaller budgets need support — and here's how you can help.