LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1923 stories · page 55 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ai

Legit Security VibeGuard 2.0 brings endpoint security and real-time guardrails to AI coding agents

Legit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents, secures them and delivers a frictionless developer experience. Launched in Q4 2025, Legit VibeGuard was the solution designed to secure AI-generated code at the moment of creation and place guardrails on coding agents. This latest release changes the d

nation-state

EU begins enforcing AI Act, putting AI models under the microscope

Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell users when they’re interacting with AI and when content has been generated or altered by it. Under these rules, chatbots have to id

security

WhatsApp account takeover scam asks you to “vote for my friend”

Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.

malware

Digital executive protection is a strategic imperative for CEOs

In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor authentication, and traders acted on it before the news went public. He also covers a home network left open after an AV te

security

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

breach

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

ai

Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack

The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop.

security

“Adult TikTok” searches lead to scams

That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.

ai

The AI Act kicks into action, forces companies to be clear about AI chatbots

The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.

security

Californians can tell data brokers to DROP their information

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.

ai

New Tool Traces AI Videos Back to Their Source

Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

breach

Anthropic: AI Attacks Result of Security Gaps, Not Model Issues

Last month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.

malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

malware

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

vulnerability

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

ai

AI slop pollutes the CVE pipeline with fake vulns

With NIST still buried under its backlog, expect AI-generated bogus reports to continue

vulnerability

More on the OpenAI Agent’s Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or

CVE-2026-18577

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

security

Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure

A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…

breach

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]

ai

Is your SD-WAN ready for AI-powered operations?

AI is shifting enterprise traffic from human-initiated to machine-generated workflows. Discover why Cisco SD-WAN must evolve to provide the visibility, policy enforcement, and performance assurance needed to support AI operations at scale.

CVE-2026-66066critical

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “KindaRails2Shell” by the researchers who found it, the flaw lets an attacker sneak a booby-trapped file past a website’s image-uplo

security

HollowFrame Loader Uses Fake Python DLL to Evade Defender

New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions

security

Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks untrusted data across files in C#, JavaScript, and TypeScript, which turns up SQL injection, command injection, cross-site scripting, a