LIVE · cybersecurity feed
Live wire
CVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide Probes

News Archive

1926 stories · page 42 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

patchcritical

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

Something shifted in security operations over the last two years: AI stopped being a pilot program and became the plan. And if you survey 500 security professionals on whether that's going well – as Omdia did, commissioned by Rapid7 – you get a remarkable level of consensus: 97% report positive outcomes, 98% say AI reduces alert fatigue, and 95% say it's helping address staffing shortages. Those n

breach

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek.

security

Walmart Leaders Transform Security Operations Without Going Bananas

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.

vulnerability

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.

vulnerability

NIST Seeks Public Input on AI-Ready NVD Modernization

The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research

vulnerabilitycritical

Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]

vulnerability

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.

security

This Coin-Sized Device Can Hack a Boeing 737

Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.

security

Help shape the future of resilient private 5G

The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G

malware

Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attackers pose as recruiters and lure targets with job opportunities at well-known companies. One of the decoy documents uncov

aihigh

API Flaw Exposes AI Reasoning and Secrets

A vulnerability in the API reasoning services of OpenAI, Anthropic, and Google allowed researchers to extract sensitive information from session logs. The flaw involved encrypted reasoning objects that could be replayed across different sessions, potentially exposing API keys and passwords.

security

Ceva Logistics Operations Disrupted by Cyberattack

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek.

security

Signal adds new security feature to thwart man-in-the-middle attacks

​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]

zero-day

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]

ai

‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware

Experts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.

phishing

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) Chrome revokes notification permissions for websites users have not recently interacted with and for sites that Google Safe Br

patch

Weekly Update 516: Live From Vietnam

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to

breach

Ivanti EPM Update Patches Remotely Exploitable Flaws

The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.

healthcare

Post-quantum migration gets harder when every user holds a key

In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assumptions in IPsec, SSH, TLS and libp2p, why migrating user keys makes blockchains hard to upgrade, and what a silent quan

vulnerability

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery, vulnerability identification, report. No human sits in the loop. The agent drives Claude Code or Codex, runs the tools,

CVE-2026-20349

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.

phishing

Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found. Researchers discovered the scam project on May 16 and described it as an example of how social engineering, phishing, and financial fraud can be combined into a s

ai

AI deployments are stretching enterprise security to its limits

CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey. Key aspects of AI deployments contributing most to attack surface chang

security

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]