LIVE · cybersecurity feed
Live wire
CVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide Probes

News Archive

1926 stories · page 37 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

breach

Hackers breach govt webmail while running parallel crypto fraud

The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]

security

Curiouser and Curiouser

In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.

CVE-2026-71362critical

Critical Adobe Commerce Flaw Exploited After Disclosure

Attackers are actively exploiting a critical vulnerability in Adobe Commerce, identified as CVE-2026-71362, shortly after its public disclosure. This flaw allows unauthenticated attackers to hijack customer accounts and access sensitive data by switching user sessions. Adobe has released an isolated patch to address this and other vulnerabilities.

vulnerability

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]

ai

AI 'watermark removers' flood the web. Almost none can prove they work.

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]

CVE-2026-20349critical

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by specific deadlines. The vulnerabilities affect Cisco Secure Firewall, Microsoft Windows, and Metabase, with the Metabase flaw being a critical SQL injection that was actively exploited.

CVE-2026-20349

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software

aicritical

Why API Discovery Is Critical for Modern AppSec Programs

Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet. API discovery must pull from gateways, cloud, specs, traffic paths, scanners, and external exposure signals. OWASP […]

ai

AI’s ‘middle class’ has gotten dramatically better at hacking

As frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models. The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop.

security

Flock tightens privacy controls amid scandals over officer abuse

All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.

CVE-2026-59310critical

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

malware

New Mirai variant adds stealth capabilities to notorious botnet code

Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.

breach

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities

CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data

breach

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]

security

Trump wants to grant private cyber firms a license to hack back

Contractors could surveil and disrupt foreign criminal networks, provided they follow strict rules and put up $1M

cloud

Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone

Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028

ransomware

The backup Microsoft never promised you

SPONSORED FEATURE: Your M365 and Azure data might not be as safe as you think from ransomware; time for a reality check

security

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.

nation-state

White House authorizes private US companies to hack foreign criminal networks

President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government. The post White House authorizes private US companies to hack foreign criminal networks appeared first on Help Net Security.

aihigh

Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

Researchers at Arizona State University have demonstrated the significant impact of AI on vulnerability discovery, using advanced models like Anthropic's Claude Mythos to find hundreds of flaws in the Linux kernel. The team found that AI models, especially when enhanced with workflows and trained on past vulnerabilities, can discover vulnerabilities at a rate that outpaces human reporting capabilities. This rapid discovery raises concerns about responsible disclosure and the ability of organizations to patch systems effectively, potentially leading to increased cybercrime or system instability.

CVE-2026-71362

Adobe Commerce Bug Targeted Immediately After Disclosure

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.

ai

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]

vulnerabilitycritical

vCenter Flaw Exploited Just Five Days After Disclosure

Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it

ai

DataGrout helps enterprises control AI usage, governance and LLM costs

SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equipping IT and FinOps leadership with a policy-driven, auditable LLM payload and cost monitoring system to track company-w