News Archive
1923 stories · page 48 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

AI chat bots are sliding into League of Legends friend requests
Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

Friday Squid Blogging: Arctic Bobtail Squid Video
Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Meta ordered to pay $942 million over harm to children
A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.

Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

Ex-NSA Chief Urges Disconnecting Water Controllers from Internet
Following suspected cyberattacks on water systems across at least 12 US states, likely perpetrated by Iran, a former NSA chief has strongly advised that industrial control systems like programmable logic controllers (PLCs) should not be connected to the internet. He emphasized the need for higher cybersecurity standards to defend these critical infrastructure components, noting that Iranian actors have a history and capability for such attacks.

Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

Water utilities group partners with DEF CON offshoot for Water Watch Center
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A campaign involving nearly 800 malicious npm packages has been discovered, delivering a cross-platform Remote Access Trojan (RAT) and infostealer. These packages, some appearing to be AI-generated or typo-squatted, instruct developers to load them via `require()`, leading to the execution of a downloader. This downloader fetches platform-specific payloads from Cloudflare Workers or uses DNS TXT records for delivery, ultimately deploying malware that can interfere with security monitoring and establish persistence.

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
A new Go-based malware targeting macOS is being distributed through ClickFix-style attacks. This malware is capable of stealing browser passwords, Apple Keychain data, and cached credentials. Notably, it also includes a function to gradually drain cryptocurrency wallets, siphoning funds into attacker-controlled accounts across various cryptocurrencies like Bitcoin, Ethereum, and XRP.

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A sophisticated cybercrime group known as UNC6671 is employing vishing attacks, targeting employees' personal phones to steal SaaS data. The attackers impersonate IT support, tricking victims into fraudulent login portals that capture credentials and multi-factor authentication tokens. This allows them to gain access to cloud environments and applications like Microsoft 365 and Okta, deploying scripts for data exfiltration.

US cyber ambassador nominee Cassady confirmed in Senate
NTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.

More than half of AI-generated patches are broken
Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. The post More than half of AI-generated patches are broken appeared first on CyberScoop.

New Mexico judge orders Meta to pay $567 million in kids online safety case
The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.

Military device manufacturer discloses cyber incident to SEC
IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into […]

AI-Generated Patches Fail Half the Time
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

Ransomware attacks spike as world distracted by AI
What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?

Hackers Impersonate IT Support to Breach Leading Financial Companies
Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among

Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]

Beware cut-price AI services that read your every word
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

Irregular, firm behind AI hacking incidents, won't say if there were more
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
JetBrains TeamCity is affected by CVE-2026-63077, a critical vulnerability allowing unauthenticated remote code execution. An attacker can exploit the agent polling protocol to execute OS commands with the privileges of the TeamCity server process. While initially not known to be exploited, CISA has confirmed its use in the wild.

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Several cybersecurity incidents are highlighted, including a ban on Chinese data center technology, a supply chain attack on QuickFox VPN, and a phishing breach at IEH Corporation. Additionally, AI-generated content may be impacting Apple's bug bounty program, and a North Carolina port experienced an attack, alongside broader targeting of Wall Street.