LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1923 stories · page 50 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ai

'Asimov was right' about rules for robots, says ex-US Cyber Director

Humans will get the AI models they deserve

vulnerability

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.

security

Google Links Redact Extortion Group to BlackFile Rebrand

BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns

security

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and

security

Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)

Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek.

vulnerabilitycritical

Microsoft, Apple Release Fresh Security Updates

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.

patch

OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens

OpenAI has updated GPT-5.6 Sol, the model behind ChatGPT for Plus and Pro subscribers, and pushed a new model, GPT-5.6 Luna, out to everyone using the free tier. The company is also removing the rate limit on text conversations for free users, allowing them to keep chats going without waiting for the limit to reset. For Plus and Pro accounts, GPT-5.6 Sol now handles both quick replies and longer r

malwarehigh

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Researchers have discovered a method for malware to abuse Windows Hello for Business keys, enabling persistent access to Microsoft Entra ID. The technique allows malicious code running within a user's active session to silently authenticate using the victim's Hello for Business key, bypassing biometric or PIN prompts on TPM-backed systems. This can lead to the attacker registering their own device, obtaining a Primary Refresh Token, and potentially adding further authentication methods, even satisfying phishing-resistant authentication requirements.

ransomware

Ransomware Surges in July After Q2 Lull

Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech

CVE-2026-12537critical

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Researchers discovered vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged attackers to execute code on CI runners. The flaws, which have been patched and assigned CVEs, involved issues with command validation and container launching. A separate finding related to OpenAI's Codex also allowed for the hijacking of agent runs, though OpenAI considers its sandbox to have behaved as documented.

security

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:

breach

3.8 Million Impacted by Unlimited Technology Systems Data Breach

Hackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek.

aicritical

Keepit AI Truth Cloud protects the data behind enterprise AI

Keepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as the sovereign source of truth that enterprise AI can safely build on: data that is verifiable, governed, immutable, and proven. From backup to trusted enterprise o

vulnerabilitycritical

Critical Vulnerabilities Patched With Chrome 151 Update

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek.

deepfakehigh

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Scammers are leveraging AI-generated deepfakes to impersonate OnlyFans creators, tricking fans into sending money through platforms like Cash App. This scam not only defrauds fans but also harms creators, who face accusations from angry followers and even threats. While legal measures are being introduced, the global nature of hosting and enforcement challenges hinder effective control.

threat actorhigh

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Researchers have linked the threat actor known as TeamPCP to cybercriminal activities dating back to 2020, predating their known supply chain attacks. The group has a history of exploiting vulnerabilities in internet-facing infrastructure, including Redis servers and AI platforms, for various malicious purposes like cryptocurrency mining and botnet creation. Their operations have evolved to include sophisticated supply chain compromises, weaponizing open-source libraries and leveraging cloud infrastructure for widespread attacks.

zero-day

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs were reported as exploited zero-days and only one as publicly disclosed, but we’ll get back to that later in this artic

phishing

What the first year of EU AI Act transparency enforcement could look like

In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts as interacting with a person, and how security teams should handle simulated phishing that uses cloned

security

US fuel gauge exposure fell by more than half in three months

Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous year’s floor, and the decline holds up against checks for address churn and port hopping. Exposure figures rarely move this way, and almost never t

vmwarehigh

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

CrowdStrike researchers have identified 21 novel methods for obfuscating shell commands on VMware ESX hypervisors. These techniques, ranging from simple encoding to complex cryptographic ciphers and invisible Unicode characters, evade traditional log-based detection by exploiting the parsing stage of command execution. CrowdStrike has developed detection patterns to identify these obfuscated commands at scale, enhancing security for ESX environments frequently targeted by ransomware.

ai

ShieldFont Fights AI Scraping With Deceptive Text

A new web font called ShieldFont has been developed to combat AI-driven web scraping. It displays one version of text to human users while serving a different, altered text to automated crawlers that inspect the page's source code. This technique aims to confuse AI models trained on scraped data by providing them with inaccurate information.

security

China launches mysterious probe into security of Palo Alto Networks' products

Beijing’s not saying why, which is just what happened when it investigated Micron

aihigh

AI-generated phishing texts bypass human intuition

AI can craft highly convincing spear-phishing text messages that are difficult for even experienced individuals to distinguish from legitimate communications. A demonstration showed that personalized AI-generated texts, mimicking official alerts, could easily deceive recipients, highlighting the limitations of relying on gut feelings to identify threats.

security

ISC Stormcast For Friday, August 7th, 2026 (Fri, Aug 7th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.