LIVE · cybersecurity feed
Live wire
CVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide Probes

News Archive

1926 stories · page 41 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

vulnerability

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]

CVE-2026-68820

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

vulnerabilityhigh

SharePoint Vulnerability Exploited Shortly After PoC Release

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.

vulnerabilitycritical

“Zoomsday” flaws could let one Zoom participant attack another

Update Zoom now to protect against critical vulnerabilities that could allow an attacker in the same meeting to run malicious code on your device.

data breachhigh

Uber Freight Investigates Data Breach After Extortion Group Claims Attack

Uber Freight is investigating a data security incident after the extortion group Helix claimed to have stolen nearly one million files. Helix listed Uber Freight on its data leak site, alleging access to mailboxes, OneDrive accounts, and other repositories. The company stated that the incident has been contained and remediated, with no disruption to its business operations, and that federal law enforcement has been engaged.

malware

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call

security

Linux Kernel Process Accounting, (Wed, Aug 12th)

A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26;#;xa0;and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux&#;x26;#;39;s kernel process accounting feature, and I think he

security

FBI: Hackers target online accounts to steal nude photos

The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]

chrome extensionshigh

737 Chrome Extensions Caught Routing User Traffic Through Proxies

Researchers discovered 737 Chrome extensions, primarily targeting Russian-speaking users, that were secretly routing browser traffic through proxy servers. These extensions, which accumulated over 75,000 installations, were designed to bypass blocked services while potentially intercepting user data. Many of these extensions also impersonated legitimate services.

security

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. [...]

ransomwarecritical

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

security

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals aro

vulnerabilitycritical

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.

security

Signal’s new security feature checks if your encrypted chats were tampered with

Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end encrypted session,” Signal engi

ai

ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5

ScienceLogic has launched Skylar AI 2.5, a new version of its AI platform designed to enhance IT operations. This release offers flexible deployment options, including sovereign cloud, on-premises, and secure cloud environments, to meet stringent security, sovereignty, and compliance needs. It also introduces improvements in AI accuracy, operational guidance, enterprise integrations, and governance.

breach

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated

malware

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

artificial intelligence

Black Hat USA 2026: AI is racing ahead of cybersecurity controls

Black Hat USA 2026 highlighted the rapid advancement of AI and its increasing role in cybersecurity, while also raising critical questions about accountability. Discussions focused on the challenges of regulating AI due to its swift evolution and the difficulty in assigning responsibility when AI-driven incidents occur. Experts emphasized the need for human oversight, robust governance, and a collaborative approach to ensure AI is developed and deployed safely and responsibly.

ai

Deloitte strengthens AI governance to support trusted enterprise adoption

Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across the AI lifecycle, combining advisory and assurance services across governance frameworks and AI-enabled transformation to he

ai

Mindgard Raises $30 Million to Protect AI Systems

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek.

ransomwarecritical

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

security

WhatsApp Unveils New Scam Alert Feature

Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.

ransomware

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Gives a whole new meaning to Safe Mode

breach

Three intrusions at UK criminal records office went undetected for two years

Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.