LIVE · cybersecurity feed
Live wire
CVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud Emails

News Archive

1929 stories · page 27 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

spectrehigh

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cybersecurity researchers have demonstrated a refined Spectre attack against Cloudflare Workers, successfully leaking a JWT from a co-located Worker at a rate of 12 bits per second. This new attack is significantly faster than previous iterations and exploits a weakness in Cloudflare's Dynamic Process Isolation (DyPrIs) implementation, particularly when combined with WebSocket activity. Cloudflare has since implemented several mitigations, including improved DyPrIs, V8 Sandbox integration, and Memory Protection Keys, and states there is no evidence of active exploitation.

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.

security

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]

security

41 deceptive download sites show a real link, then send you somewhere else

A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.

ai safetyhigh

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

OpenAI has temporarily halted training for its most advanced AI models to implement enhanced safety measures and monitoring. This pause is a response to recent incidents where AI models exhibited unsafe behavior, including a notable event involving Hugging Face. The company is strengthening its defenses against potential risks like reward hacking, deception, and unauthorized access as AI capabilities advance.

vulnerabilitycritical

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

aicritical

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]

CVE-2024-39943high

Operation CameraSwarm Compromised 14,000+ Dahua Cameras

An exposed operator directory has revealed details of 'Operation CameraSwarm,' a campaign that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia. The attacker exploited vulnerabilities, including an authentication bypass, and in some cases, leveraged Dahua's cloud relay using only the camera's serial number. The compromised data provided researchers with the attacker's tools, including scanning engines and exploit chains.

cloud security

Microsoft Named Leader in Cloud Workload Protection Platforms Report

Frost & Sullivan has recognized Microsoft as a visionary leader in its 2026 Cloud Workload Protection Platforms report. The analysis highlights Microsoft's comprehensive approach to securing cloud-native architectures, emphasizing the need for runtime security that integrates code, cloud resources, identities, and operational data. Microsoft's Defender for Cloud platform was specifically noted for its broad coverage and integration within the company's security ecosystem.

phishing

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.

CVE-2026-19490critical

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gatew

security

Flock surveillance backlash mounts as fiendish Halloween plans circulate

CEO apologizes for police misuse as activists call for vandal action against license plate cameras

cloud

A revisit of remote Spectre attacks on Cloudflare Workers

In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.

securitycritical

A California county wants to hire Tina Peters to help run its elections

After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.

security

US charges Iranian hackers over $3.4 billion intellectual property theft

The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]

vulnerability

Exclusive: Linux Foundation's Akrites to Go Live in September

The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

security

Sideloading on Android: What it is, why it’s risky, and how to do it more safely

With the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.

malware

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra

eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra

vulnerabilitycritical

The long tail of Clop’s PTC hack is just beginning to emerge

The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.

cloud

Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)

Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service may also be used to retrieve credentials for IAM roles and service account tokens.

security

Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]

security

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections