LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1920 stories · page 67 of 80

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

chromecritical

Chrome 150 Update Fixes 27 Security Flaws

Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

funding

8Layers Secures $2.9 Million for Identity Security Platform

Spanish startup 8Layers has successfully raised $2.9 million in an extended pre-seed funding round. This capital infusion comes just two months after the company launched its digital identity protection platform, signaling strong investor confidence in its market potential.

aihigh

AI Coding Agents Can Be Tricked Into Executing Malicious Code

Researchers have demonstrated a vulnerability in AI coding agents, such as Anthropic's Claude Code and OpenAI's Codex, where they can be manipulated into executing malicious code instead of identifying security flaws. This 'Friendly Fire' attack exploits the autonomous mode of these agents, potentially leading them to run harmful code on the user's system.

CVE-2026-11405critical

Tenda Firmware Vulnerability Allows Unauthenticated Admin Access

A critical backdoor vulnerability has been discovered in Tenda device firmware, identified as CVE-2026-11405. This flaw enables unauthenticated attackers to gain administrative control over affected devices by accessing their web management interface. The vulnerability remains unpatched, posing a significant risk to users.

malwarehigh

Fake 7-Zip Installers Hijack Devices for Proxy Network

A threat group known as Lurking Lizard has established a large-scale residential proxy network using over 230 fake domains. This operation, active since at least August 2022, leverages compromised devices, including those infected via fake 7-Zip installers, to route traffic for malicious purposes.

honeypot

Honeypot Researcher Finds Bot's Plea for Help

A honeypot researcher discovered a peculiar scanning bot that uses a URL path as a plea for help, seemingly from someone in Belarus. The bot, which scans for open ports and sends basic HTTP requests, appears to be intentionally limited and not malicious. The author claims the bot's purpose is to draw attention to their situation.

vulnerability managementhigh

When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed First

The increasing speed at which AI models discover software vulnerabilities, particularly in open-source components, is outpacing the ability of organizations to patch them. This necessitates a shift in risk prioritization, focusing on exploitability rather than just severity scores. An industry coalition called Athena aims to accelerate the defense of open-source software, while tools like those from Qualys help organizations identify which discovered vulnerabilities are actively being exploited and require immediate attention.

CVE-2026-50746critical

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation

Ubiquiti has released security updates to address seven vulnerabilities in its UniFi OS, including several critical flaws. One critical vulnerability, CVE-2026-50746, allows for command injection in the UniFi Connect Application, impacting systems that manage building infrastructure like smart lighting and EV chargers. Other patched issues include SQL injection, improper input validation, and SSRF vulnerabilities across various UniFi applications, potentially leading to privilege escalation.

predator spywarehigh

Greek victims sue Intellexa over Predator spyware

Victims in Greece have filed a lawsuit against Intellexa, the company behind the Predator spyware. The spyware's use was revealed in 2022, with evidence found on numerous phones. This revelation previously resulted in the resignations of the head of Greece's intelligence service and the prime minister's chief of staff.

cash app

Cash App Owner to Pay $45 Million Over Lax Security Claims

Block, Inc., the owner of Cash App, has agreed to pay $45 million to settle allegations that it misrepresented the security protections offered to its users. State attorneys general stated that the company incorrectly claimed Cash App provided the same level of security as traditional banks.

data breachhigh

Accenture Confirms Security Incident After Hacker Claims 35GB Source-Code Theft

Accenture has acknowledged a security incident after a threat actor advertised what they claim is stolen internal data. The attacker, using the alias "888", says they took more than 35GB of source code and cloud credentials from the consulting giant and are offering it for sale. Accenture says it has addressed the source of the issue and that its operations were not disrupted.

CVE-2026-24858high

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices

A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

ai

AI Coding Tools Trigger Endpoint Security Rules

Researchers have observed that AI coding assistants are inadvertently triggering endpoint security software designed to detect malicious activity. These tools, including Cursor, Claude Code, and OpenAI Codex, are setting off behavioral detection rules due to actions like credential harvesting and system reconnaissance, which mimic attacker behavior. The AI agents themselves are not malicious, but their operations resemble those of human intruders.

ai

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

Microsoft has developed an internal AI system to proactively evaluate and strengthen its cloud infrastructure. This system operates at AI speed to match the scale and complexity of Microsoft's hyper-scale environments, ensuring security controls are robust and effective. While not a customer-facing product, the insights gained will inform future product improvements.

data breach

Accenture Confirms Data Breach Following Source Code Theft Claim

Accenture has confirmed a data breach occurred, which involved the alleged theft of source code. The company stated that the incident has been contained and remediated, with no impact on its operations or service delivery.

apthigh

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

A China-linked advanced persistent threat (APT) group, identified as LapDogs, has reportedly enhanced its malicious toolkit. Security researchers have observed the deployment of three new backdoors: LongLeash, DogLeash, and JarLeash, which are designed to compromise small office/home office (SOHO) routers.

androidhigh

RedWing Android Spyware Sold as a Service on Telegram

A new Android spyware called RedWing is being offered as a service on Telegram, allowing less sophisticated attackers to compromise phones and steal banking information. Researchers have identified it as a polished malware-as-a-service operation with extensive documentation and a subscription model, potentially linked to Russian threat actors. RedWing employs fake login overlays, SMS interception, call forwarding, and even screen control to harvest credentials and conduct further malicious activities.

aihigh

HalluSquatting Attack Exploits AI Coding Assistants to Deliver Malware

A new attack technique called HalluSquatting leverages the tendency of AI coding assistants to invent non-existent project names. Attackers can register these fabricated names and trick the AI into recommending them, thereby leading users to unknowingly install malicious software like botnet malware.

aihigh

Operationalizing Day Minus Seven: The Cloud-Native ROC

The article introduces the concept of a Risk Operations Center (ROC) as a necessary evolution for cybersecurity teams facing AI-driven threats. It argues that traditional risk management models are insufficient due to the speed at which AI can discover and exploit vulnerabilities, especially in cloud environments. A ROC, powered by platforms like Qualys Enterprise TruRisk Management (ETM), aims to unify disparate security findings, hyper-prioritize risks based on exploitability and business impact, and enable autonomous remediation to keep pace with attackers.

apt

China-Linked APT Expands Proxy Network With New Malware

A China-linked advanced persistent threat group, identified as UAT-7810, is reportedly expanding its network of proxy servers. This expansion is being facilitated by the deployment of new malware, according to research from Cisco Talos.

infostealerhigh

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Cybersecurity researchers have identified a new threat actor, dubbed Armored Likho, targeting government and energy sectors in Russia, Kazakhstan, and Brazil with a sophisticated phishing campaign. The operation utilizes a custom-built Python infostealer named BusySnake, designed to steal credentials, sensitive documents, and other high-value data. The attackers employ AI-generated payloads to obscure their activities and maintain persistence through various methods, including reverse SSH tunneling.

CVE-2026-55255critical

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)

CISA has issued a warning regarding a critical vulnerability (CVE-2026-55255) in the Langflow AI framework, which is being actively exploited by attackers. The flaw allows authenticated users to execute arbitrary flows belonging to other users, potentially leading to the theft of sensitive credentials and data exposure, especially in multi-tenant environments. US federal agencies have been mandated to patch this vulnerability by July 10th.

aihigh

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

CVE-2026-12958high

Bug in top AI coding agents shows that Unix-era security headaches never really die

A vulnerability dubbed "GhostApproval" has been discovered in at least six popular AI coding assistants, allowing them to access files outside their designated workspaces and potentially execute remote code. The flaw exploits symbolic links, a long-standing security issue, to trick agents into writing malicious content, such as SSH keys, to sensitive system files. While some vendors have patched the issue and assigned CVEs, others have downplayed the risk or are yet to release fixes.