News Archive
1926 stories · page 41 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]

Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.

“Zoomsday” flaws could let one Zoom participant attack another
Update Zoom now to protect against critical vulnerabilities that could allow an attacker in the same meeting to run malicious code on your device.

Uber Freight Investigates Data Breach After Extortion Group Claims Attack
Uber Freight is investigating a data security incident after the extortion group Helix claimed to have stolen nearly one million files. Helix listed Uber Freight on its data leak site, alleging access to mailboxes, OneDrive accounts, and other repositories. The company stated that the incident has been contained and remediated, with no disruption to its business operations, and that federal law enforcement has been engaged.

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call

Linux Kernel Process Accounting, (Wed, Aug 12th)
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26;#;xa0;and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux&#;x26;#;39;s kernel process accounting feature, and I think he

FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]

737 Chrome Extensions Caught Routing User Traffic Through Proxies
Researchers discovered 737 Chrome extensions, primarily targeting Russian-speaking users, that were secretly routing browser traffic through proxy servers. These extensions, which accumulated over 75,000 installations, were designed to bypass blocked services while potentially intercepting user data. Many of these extensions also impersonated legitimate services.

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. [...]

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals aro

Patch Tuesday: Update now to fix 421 flaws, including three zero-days
Microsoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.

Signal’s new security feature checks if your encrypted chats were tampered with
Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end encrypted session,” Signal engi

ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5
ScienceLogic has launched Skylar AI 2.5, a new version of its AI platform designed to enhance IT operations. This release offers flexible deployment options, including sovereign cloud, on-premises, and secure cloud environments, to meet stringent security, sovereignty, and compliance needs. It also introduces improvements in AI accuracy, operational guidance, enterprise integrations, and governance.

Exposed: Woeful security at UK criminal records office that led to sensitive data leak
Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026 highlighted the rapid advancement of AI and its increasing role in cybersecurity, while also raising critical questions about accountability. Discussions focused on the challenges of regulating AI due to its swift evolution and the difficulty in assigning responsibility when AI-driven incidents occur. Experts emphasized the need for human oversight, robust governance, and a collaborative approach to ensure AI is developed and deployed safely and responsibly.

Deloitte strengthens AI governance to support trusted enterprise adoption
Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across the AI lifecycle, combining advisory and assurance services across governance frameworks and AI-enabled transformation to he

Mindgard Raises $30 Million to Protect AI Systems
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek.

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

WhatsApp Unveils New Scam Alert Feature
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.

Akira ransomware scum blocked victim's security tools – and broke their own encryptor
Gives a whole new meaning to Safe Mode

Three intrusions at UK criminal records office went undetected for two years
Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.