News Archive
1929 stories · page 30 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Comcast turns your Xfinity WiFi into a home motion detector
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others. The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.

OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue
The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.

CISOs Break Their Silence in 'Declassified' Docuseries
A new docuseries titled 'Declassified' offers an unprecedented look into the high-pressure world of Chief Information Security Officers (CISOs). The series features candid accounts from CISOs detailing the immense stress, burnout, and personal toll that comes with managing an organization's cybersecurity defenses, including instances of significant financial loss and career disruption.

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing [

More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

Hackers Expose Data of 1.2 Million Heights Finance Customers
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance […]
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -

Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer, a macOS information stealer, has been observed using rapidly changing infrastructure for its operations. Microsoft Defender Experts identified persistent behavioral patterns, such as specific request characteristics and upload methods, that allow for tracking the malware's activity even as its command-and-control domains rotate. These durable pivots enable defenders to investigate payload delivery, data collection, staging, and exfiltration.

Project noRecognition: Teaching AI to Fool Surveillance Cameras
Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly […

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A new threat actor, operating under the name "Ransom Busters," is contacting ransomware victims directly, claiming to have infiltrated ransomware groups' servers and offering to delete stolen data for a fee between $20,000 and $60,000. Security researchers believe this is likely a ransomware affiliate attempting to extort victims further, rather than a legitimate recovery service, and warn that payments offer no guarantee of data deletion.

Berlin cuts two state ministries off government network after security breach
The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.

University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks

BGP Role model: tracking the adoption of RFC 9234
RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. The post Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks appeared first on SecurityWeek.

Enterprise Software Has 4.31x More Critical Vulnerabilities
A recent analysis indicates that enterprise software applications are now exhibiting a 4.31 times higher rate of critical and high-severity vulnerabilities. This trend coincides with an overall acceleration in the development of enterprise software.
Apple plugs image-processing hole ripe for spyware abuse
Patch batch spans current kit, older iGadgets, Macs, and Vision Pro

Meta Ran Ads for an App That Promised to Nudify Female Politicians
One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

Hackers target Ukrainian agency managing assets seized from sanctioned Russians
The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.