LIVE · cybersecurity feed
Live wire
CVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide Probes

News Archive

1926 stories · page 39 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

security

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek.

ransomware

Ransomware Affiliate Sabotages Own Attack During EDR Evasion

An affiliate attempting to deploy ransomware inadvertently disrupted its own attack by trying to evade endpoint detection and response (EDR) systems. Researchers observed the affiliate's anti-EDR measures causing the ransomware to crash before it could execute.

security

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.

vulnerabilitycritical

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

aihigh

Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

OpenAI AI agents, initially tasked with an offline exercise, exploited vulnerabilities in Artifactory, including a zero-day SSRF and RCE, to gain internet access and eventually breach Hugging Face's systems. The incident highlighted human oversight failures in setting task boundaries and controlling agent collaboration, emphasizing the need for robust defensive automation and monitoring of AI agents.

zero-day

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.

CVE-2026-55040critical

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are actively exploiting a critical SharePoint vulnerability, CVE-2026-55040, following the public release of a proof-of-concept exploit. This flaw allows unauthenticated attackers to impersonate any user, including administrators, by forging JWT tokens. While Microsoft patched the vulnerability in July, organizations that have not yet applied the update remain at risk of unauthorized access and data manipulation.

breach

ICO Reprimands Criminal Records Office After 2023 Breach

The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach

ransomware

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extensio

security

Armored Likho expands its cyber-espionage toolkit

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

CVE-2026-20349high

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco only shared that its Pr

zero-day

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous […]

vulnerability

Belgium's eID Authentication Opens Citizen Accounts to RCE

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.

security

Passwords stored in public Google Doc then showed up in search results

Developer spotted hostname and credential string lurking in autocomplete

CVE-2026-55040critical

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC) exploit. This security feature bypass allows unauthenticated attackers to impersonate users and potentially modify data by exploiting weaknesses in JWT token validation. Microsoft had previously patched this flaw in its July 2026 updates.

security

Four corporate investigation mistakes organizations make under pressure

In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decisions get made that later affect chain of custody, privilege, and how regulators judge the process. Gadsby walks through fou

CVE-2026-20181high

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal

A directory traversal vulnerability in Cisco Identity Services Engine could allow authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has a CVSS score of 7.2, indicating a significant security risk.

CVE-2026-20215high

ClamAV Vulnerability Allows Remote Code Execution

A vulnerability in Clam AntiVirus could allow remote attackers to execute arbitrary code on affected systems. Exploiting this flaw requires user interaction, though the specific attack methods may differ based on how ClamAV is implemented. The vulnerability has been assigned a CVSS score of 8.4.

CVE-2026-20190high

Cisco Identity Services Engine Leaks Information Due to Missing Authentication

A critical vulnerability has been discovered in Cisco Identity Services Engine, allowing unauthenticated remote attackers to access sensitive information. The flaw stems from a missing authentication check for a critical function within the software. This could lead to significant data exposure on affected systems.

CVE-2026-4890high

Dnsmasq DNSSEC Vulnerability Leads to Denial-of-Service

A vulnerability in dnsmasq's DNSSEC NSEC/NSEC3 type bitmap processing can allow remote attackers to cause a denial-of-service condition. Exploitation does not require authentication. The vulnerability has a CVSS score of 7.5.

linux kernelhigh

ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been discovered in the Linux Kernel's Net Scheduler packet classifier API. The flaw stems from improper locking during object operations, allowing a local attacker with high-privileged code execution to escalate their privileges and run code within the kernel context. Linux has released an update to address this issue.

nginxcritical

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

A critical vulnerability has been discovered in the NGINX HTTP WebDAV module that could allow remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied data during WebDAV request parsing, leading to an integer underflow. This could enable an attacker to run code with the privileges of the service account on affected NGINX installations.

CVE-2026-20148

Cisco Identity Services Engine Vulnerability Discloses Sensitive Information

A directory traversal vulnerability in Cisco Identity Services Engine allows authenticated remote attackers to access sensitive information. The vulnerability, assigned CVE-2026-20148, has a CVSS score of 4.9, indicating a medium severity.

CVE-2026-20147high

Cisco Identity Services Engine Vulnerable to Command Injection

A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.