News Archive
1923 stories · page 23 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

Is Cyber missing the Marque?
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.

Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account for the popular Rust crate `arrayref`, injecting malware that executes during the compilation process on developers' systems. This supply-chain attack also affected two other crates, `append-only-vec` and `internment`, within a short timeframe. The malware, disguised as a dependency, attempts to steal credentials from browsers and establish persistence across various operating systems.

Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

N-able Bug Exposes Password Vault Master Keys
The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs
NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA […]

Senators press TikTok over withholding of safety features for some users
In a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users."

Cyber Policing Hindered by Funding and Officer Focus
Law enforcement struggles to keep up with the increasing speed and complexity of cybercrime. Experts suggest that officers do not require extensive technical training, but rather a focus on fundamental concepts. However, insufficient budgets and a lack of concentrated effort are significant barriers to effective cyber policing.

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
Follow the money

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
This week's cybersecurity landscape features several significant threats, including the abuse of legitimate signed drivers for kernel operations, a large-scale cyber espionage campaign by an Iran-based group targeting universities, and malware utilizing DLL sideloading. Additionally, advancements in AI safety are being explored by OpenAI and Google, while a new service, Kriminal AI, offers unfiltered AI responses, raising concerns about misuse. Apple is also modifying its App Tracking Transparency feature in Germany following regulatory scrutiny.

From all-or-nothing to task-based OAuth consent
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That

Researcher tricks Apple’s Find My into sharing location data with Linux
Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.

Hackers Target Zimbra Servers in Active Exploitation Campaign
Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.

ChatGPT for Teens tackles risky chats and homework shortcuts
OpenAI has launched ChatGPT for Teens, a version of its AI assistant tailored for users aged 13-17, incorporating enhanced safety features and parental controls. This move comes in response to lawsuits and concerns over teens misusing the platform for harmful activities, including self-harm and violence, and for academic dishonesty. While the new version includes features like 'Study Mode' to encourage critical thinking over direct answers and stricter content moderation, experts caution that tech-savvy teens may still find ways to bypass these safeguards.

Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has detailed a new attack called Cryptographic Context Injection that can trick xAI's Grok chatbot into sending user data, including name, location, subscription tier, and conversation history, to an attacker-controlled server. The attack exploits the chatbot's Python execution runtime by embedding encrypted instructions that Grok decrypts and executes, leading it to construct a URL containing the sensitive information. While Adversa AI has reported the vulnerability to xAI, there is currently no patch or CVE identifier, and no public statement from xAI regarding mitigation.

Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first on SecurityWeek.

JFrog Artifactory Flaws Enable Software Supply Chain Attacks
Two Artifactory flaws allowed attackers to poison package metadata across software repositories

Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Because apparently even ransomware gangs can't trust the people they do business with

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

Frequently asked questions about the active threat to Siemens S7 Series PLCs
A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future