News Archive
1923 stories · page 49 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
The U.S. Coast Guard is investigating a cyberattack that disrupted operations at North Carolina's three major port facilities. The breach caused delays in gate openings and necessitated a shift to manual processing as the ports authority worked to contain the intrusion. While normal operations have resumed, the nature of the attack and its full impact remain undisclosed.

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
Researchers have developed a new speculative execution attack called TONTOU, which can bypass existing Spectre defenses on both Intel and AMD processors. The attack exploits a timing window after security mitigations are applied, using precisely timed interrupts to re-poison the branch predictor. This allows attackers to divert control flow and leak sensitive kernel data, demonstrated by a successful exploit against AMD Zen 2 that bypassed KASLR and leaked password hashes.

Real emails, hijacked payments: Two H1 2026 attack chains
Two distinct attack chains observed in the first half of 2026 highlight sophisticated threat actor tactics. One campaign leveraged compromised corporate email accounts to deliver banking malware through a series of script executions and system modifications. The second campaign utilized a Rust-based clipboard hijacker to alter cryptocurrency transaction destinations, with command-and-control infrastructure details hidden within a blockchain smart contract.

Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder
NHS Tayside is investigating an alleged data breach involving the medical records of a nine-year-old girl who died earlier this week. The breach reportedly occurred at Ninewells Hospital, where staff may have accessed the child's file without authorization or clinical need. A man has been arrested and charged in connection with the girl's death.

Levi Strauss says hackers breached employee computers, accessed corporate data
Levi Strauss & Co. has reported a cybersecurity incident where hackers gained unauthorized access to corporate data by compromising three employee-issued computers through a social engineering attack. The company stated that the breach was contained quickly, business operations were not disrupted, and there is no evidence that consumer data was affected. The investigation into the incident is ongoing, and no attackers have been identified.

North Carolina Ports confirms cyberattack disrupting operations
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]

Unveiling good and bad behaviors on the Agentic Internet
Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot.

Introducing Radar Researcher: An AI tool for exploring Internet data in plain language
Cloudflare Radar Researcher is a new AI-powered tool that lets you explore global Internet trends and traffic data using plain language. Built entirely on Cloudflare's Developer Platform, it turns natural language queries into real, interactive charts.

Announcing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding
We are launching updated community programs, including Cloudflare Ambassadors and Community Engineers, backed by $1M in open-source funding. Learn how we are supporting maintainers and scaling our developer community.

Unifying Workers AI and AI Gateway into a single AI control plane
Cloudflare is unifying AI Gateway and Workers AI into a single control plane, giving developers observability, billing, and dynamic routing across both managed GPUs and external providers. Learn how unified bindings and model-first routing simplify building resilient AI applications.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

200 accounts compromised in Swiss government’s Microsoft SharePoint breach
Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform

French rugby club Stade Français restores systems after cyberattack, probes data leak
The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational.

Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove the cost of finding and exploiting a vuln

Growing Up The Hard Way
The open-source software ecosystem, once a free-wheeling environment, is facing a significant shift due to increasing security threats and regulatory pressures. Projects will need to demonstrate ongoing maintenance, accountability, and a clear path for security updates to be considered viable for enterprise use. This evolution will likely split the open-source landscape into a subset of

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to […]

Attacker phished way into US defense supplier's Microsoft 365 account
Intruder gained access to engineering files and potentially export-controlled technical data

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
An 18-year-old use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, has been patched. The flaw, present since 2008, could allow local users to gain root privileges and escape containerized environments. Researchers from Tencent successfully demonstrated root access and container escape on several Linux distributions.

Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.

Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

ICE Is Buying Access to Credit Card Records
Through data brokers, ICE is buying the information you provided to open a credit card.

Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of […]

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
An AI system named HTTP Terminator, developed by James Kettle, has discovered novel HTTP desynchronization techniques by analyzing 30,000 candidate vectors. The research uncovered vulnerabilities in various sectors, including finance and government, and introduced new methods like the 'dangling-byte' technique to improve response queue poisoning attacks. Additionally, a separate human-guided discovery led to a zero-day vulnerability in Apache Traffic Server, now patched and tracked as CVE-2026-63078.