LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1920 stories · page 66 of 80

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

opensslhigh

HollowByte DDoS flaw bloats OpenSSL server memory

A vulnerability named HollowByte has been discovered that enables unauthenticated attackers to cause a denial-of-service on OpenSSL servers. The attack requires only a small, 11-byte malicious payload to trigger the condition, which reportedly causes server memory to bloat.

cyberattackhigh

Cyberattack Disrupts Operations at Japanese Food Giant Nichirei

Nichirei, a major Japanese food company, has confirmed that a cyberattack on July 13th caused system outages, disrupting logistics and shipments. The company has established an emergency response team and is gradually restoring operations while withholding specific details to prevent further damage. The incident has impacted various businesses that rely on Nichirei's services, including restaurant chains and retailers.

botnethigh

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials

A newly identified botnet written in Go, dubbed NadMesh, is actively scanning for and exploiting exposed AI services. The botnet specifically targets cloud environments, seeking to steal AWS keys and Kubernetes tokens from vulnerable AI platforms. Researchers have observed it scanning for services like ComfyUI and Ollama, which are often deployed without adequate security measures.

ai

Blind Trust in AI Creates Cybersecurity Risks

Allowing AI models to both interpret and execute commands without human oversight introduces significant cybersecurity vulnerabilities. This lack of critical review can lead to unintended consequences and security breaches.

apthigh

Chinese APT Group Linked to DigiCert Breach and Code Signing Certificate Theft

Researchers have linked a Chinese cybercrime group, known as GoldenEyeDog and CylindricalCanine, to a security incident at DigiCert that resulted in the theft of code-signing certificates. This group has previously targeted the gambling and gaming industries.

phishing

Attackers Use Text Salting to Evade AI-Powered Spam Filters

Cybersecurity firm Barracuda reports that attackers are increasingly using a technique called 'text salting' to bypass AI-driven email filters. This method involves embedding harmless-looking words within malicious emails to confuse machine-learning and LLM-based security tools. Barracuda has observed over a million phishing attacks employing this tactic since April.

ai

Microsoft Discusses AI and Supply Chain Threats at Black Hat

Microsoft Security will present at Black Hat USA 2026 on how threat actors are targeting trusted systems, including software, services, and AI, to scale their attacks. The company will share insights into identifying these threats earlier and how threat intelligence, response, and security operations can collaborate across various systems. Sessions will cover the increasing ease of offensive capabilities and deep dives into hunting supply chain attacks within software ecosystems and developer workflows.

ransomwarehigh

Government Agencies Face Daily Ransomware Attacks, Study Warns

A recent study indicates that government agencies are frequently targeted by ransomware attacks. Attackers exploit the critical nature of public services, knowing that disruptions can be particularly damaging and may increase the likelihood of ransom payments.

data breach

Ernst & Young Reports Data Breach After Support System Hack

Ernst & Young has alerted its clients to a data breach resulting from a security incident involving a third-party support ticket system. The compromised system was utilized by the company's IT staff, leading to unauthorized access to sensitive information.

data breachhigh

23andMe Settles Data Breach Lawsuit for $18 Million

Genetic testing company 23andMe has reached an $18 million settlement with 42 state attorneys general following a significant data breach in 2023. The agreement includes mandates for the company to implement stricter data security measures to prevent future incidents.

espionage

Iran Tracks US Military Phones, macOS Malware, Data Breaches

Reports indicate Iran is tracking US military personnel's mobile phones, and new macOS malware dubbed CrashStealer has emerged. Additionally, vulnerabilities in OpenClaw AI agents, a ransomware attack on naval defense firm TKMS, and a data breach at Lidl are highlighted.

scattered spiderhigh

Two Scattered Spider members sentenced to 66 months for London transport cyberattack

Two individuals, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in prison in the UK for their roles in a cyberattack that disrupted Transport for London's operations. The pair were identified as leading members of the Scattered Spider hacking group. Authorities linked them to significant cryptocurrency transactions and numerous cyberattacks, including extortion of US organizations and an attack on the federal court system.

fraud

Cybercriminals Seek Clean Residential Proxies for Fraud

Fraudsters are finding that traditional residential proxies are becoming less effective for carding operations. To bypass advanced fraud detection systems, criminals are now combining these proxies with other identity information, such as browser fingerprints and device profiles.

phishinghigh

Phishing Emails Use Fake Font Files to Deliver Windows Malware

Threat actors are distributing malware through phishing emails that use specially crafted font files. These malicious files, when opened, can execute arbitrary code on a victim's Windows system, leading to malware infection. The emails often masquerade as legitimate business documents to trick recipients into opening the dangerous attachments.

malwarehigh

North Korean Hackers Use SVG Images to Hide Malware in Fake Coding Tests

North Korean threat actors, associated with the Contagious Interview campaign, are using steganography within SVG image files to hide malware. This technique is employed in a campaign that uses fake job postings and coding challenges to deliver malicious payloads, including credential and crypto wallet stealers.

cybersecurityhigh

Dairy producer Fairlife halts US production due to cyber incident

Fairlife, a major dairy company with over $1 billion in retail sales in 2022, has suspended its United States production operations. The company has facilities in Michigan, New York, and Arizona. The halt is reportedly due to a cyber incident impacting its systems.

CVE-2026-28739high

Multiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM

Researchers have disclosed several vulnerabilities affecting WolfSSL, GeoVision, and VTK-DICOM. The issues include improper input validation and integer underflow in WolfSSL, and a range of problems in GeoVision such as memory corruption, OS command injection, buffer overflows, and privilege escalation. These vulnerabilities have been addressed by the respective vendors.

cybersecurity

Tennis Analogy Highlights Cybersecurity's Imperfect Nature

A cybersecurity professional uses a tennis analogy to challenge the common notion that defenders must be perfect while attackers only need one success. By referencing Roger Federer's career statistics, the author illustrates that winning a match, much like cybersecurity, doesn't always equate to winning every single point. The key lies in winning the crucial points and understanding the strategic nuances of the game.

helixhigh

New Helix Group Targets SharePoint Data via Vishing and MFA Abuse

A newly identified cybercriminal group, known as Helix, is employing sophisticated identity-based attacks to exfiltrate data from SharePoint environments. Their methods include voice phishing, device code phishing, and the abuse of multi-factor authentication systems.

microsoft

AI to Drive More Windows Security Updates, Microsoft Says

Microsoft anticipates a rise in security updates for Windows due to its growing use of artificial intelligence. The company is leveraging AI to proactively identify vulnerabilities within its software, aiming to enhance overall system security.

phishinghigh

Forg365 Phishing Platform Leverages AI for Microsoft 365 Account Theft

A new phishing-as-a-service operation, dubbed Forg365, is targeting Microsoft 365 accounts. This platform employs a combination of adversary-in-the-middle techniques and device code methods, enhanced by AI-generated lures to trick users into compromising their accounts.

it security

Summer Staffing Shortages Expose IT Security Risks

Reduced IT staffing during summer vacation periods can create significant security vulnerabilities. Organizations are advised to leverage AI-driven automation to maintain consistent security operations and minimize reliance on manual processes, ensuring protection remains robust even with fewer personnel.

microsoft

Microsoft to Retire OWA Light Client in Exchange Server

Microsoft is planning to remove Outlook Web Access (OWA) Light, a simplified version of its web-based email client, in an upcoming Exchange Server update. This move will likely encourage users to adopt the full Outlook Web App for a more feature-rich experience.

aihigh

AI Coding Tools Vulnerable to Decades-Old Hacking Technique

Researchers have uncovered a vulnerability in AI coding assistants that allows them to be tricked into executing malicious code. This attack, named GhostApproval, leverages a long-standing technique to compromise a developer's machine through the AI tool. The exploit highlights potential security risks associated with the integration of AI into software development workflows.