LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1923 stories · page 60 of 81

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

phishing

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.

malware

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]

breach

Australian energy provider Origin says data breach exposes client data

Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]

security

Rubio restricts visas for sextortionists, cyber scammers

The move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes. The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.

malware

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]

cdn

Introducing Cache Response Rules

Cloudflare has introduced Cache Response Rules, a new feature designed to optimize content caching by running after an origin server responds but before the content is cached. These rules allow users to modify response headers, such as stripping `Set-Cookie` or adjusting `Cache-Control` directives, which were previously difficult or impossible to manage without origin server changes. This aims to improve cache hit ratios, reduce origin load, and enhance performance by addressing common caching inefficiencies.

CVE-2025-66376high

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A sophisticated Russian espionage campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), has been actively exploiting a zero-day vulnerability in Zimbra Collaboration's webmail client since at least July 2025. This flaw allowed attackers to steal sensitive data, including emails, contact lists, browser-saved passwords, and two-factor authentication codes, by simply having a user view a specially crafted HTML email. The vulnerability, identified as CVE-2025-66376, was patched by Zimbra in November 2025, but the attackers continued to leverage it for months prior to the fix.

security

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark

MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.

patchcritical

Don’t swing at everything

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

vulnerability

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

phishing

International alert spotlights Russia-linked attacks on Zimbra webmail

A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.

phishing

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]

phishing

Year-long Russian attacks infect users as soon as they look at an email

Phishing for dummies

malware

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]

security

Millions of California-bought cars can be hijacked via Bluetooth

Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers

vulnerabilitycritical

Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations

International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite

security

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. [...]

vulnerability

Oracle drops 1,449 security patches like it's the new normal

Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads

securitycritical

Iran-linked crews are probing more flavors of US industrial kit

CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure

security

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. [...]

ai

Microsoft Copilot Deployments Delayed Over Security Concerns

CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data

ransomware

Swiss train maker tells ransomware crooks to get off at the next stop

Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform

security

How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist. Since no real victim monitors misuse, a

vulnerability

Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting

Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Flash architecture and designed specifically to find, validate, and patch software vulnerabilities. It […]