News Archive
1920 stories · page 69 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's advanced AI model, Mythos, to proactively scan government code for security vulnerabilities. The goal is to identify and fix flaws before malicious actors, such as foreign intelligence agencies or cybercriminals, can exploit them. Initial audits using the AI have allegedly uncovered a significant number of bugs, though details on the scope and severity remain undisclosed.

CISA orders feds to patch max severity ColdFusion flaw by Friday
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a maximum-severity Adobe ColdFusion vulnerability. This flaw is currently being actively exploited and requires patching by Friday.

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Nebula Security has revealed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present for 15 years. This flaw allows any logged-in user to achieve root privileges and container escape on unpatched systems, as it is included by default in most Linux distributions.

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.

The Threat Isn’t the Frontier Model
The article argues that the primary AI security threat is not advanced frontier models, but rather the increasing accessibility of powerful open-source AI models that can be run on modest hardware. Adversaries are expected to leverage these models for autonomous attacks as quantization reduces their resource requirements. CISOs are urged to proactively build and test defensive AI agents now to counter this emerging threat, focusing on areas like Continuous Threat Exposure Management (CTEM), Breach and Attack Simulation (BAS), and Security Operations.

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

Accenture confirms breach after hacker offers stolen data for sale
Accenture has verified a data breach following claims by a threat actor who offered stolen information for sale. The compromised data reportedly includes 35 GB of source code and other sensitive material.

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Researchers have uncovered a sophisticated campaign distributing the Vidar stealer and XMRig cryptocurrency miner, primarily targeting users seeking cracked software. Attackers use malvertising to lure victims into downloading password-protected archives containing malicious loaders. These loaders are signed with a fake certificate and employ techniques like file-size inflation and AMSI bypass to evade detection before dropping the final payloads.

Spain arrests suspected hacker linked to Russian hacktivist campaign
Spanish police, with assistance from the FBI, have arrested an individual suspected of supporting the pro-Russian hacktivist group Cyber Army of Russia Reborn. The arrest, which occurred in March but was announced recently, is part of a broader international effort to combat cybercrime. The suspect allegedly provided logistical support to another hacker and participated in activities aimed at spreading pro-Russian narratives.

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese state-sponsored hackers, identified as UAT-7810, have developed new malware named LONGLEASH. It is being used to expand their ORB network by compromising internet-facing devices, specifically targeting unpatched Ruckus routers.

OMB M-26-14: Why federal agencies must fix asset visibility first
The U.S. Office of Management and Budget (OMB) has issued Memorandum M-26-14, a new directive for federal agencies focused on improving logging and network visibility. This memo replaces previous mandates with a five-level maturity model for logging, where progress is directly tied to an agency's ability to discover and inventory its IT, OT, and IoT assets. Achieving higher maturity levels requires progressively higher percentages of asset capture, making comprehensive asset visibility the foundational step for compliance.

Uncommon NIMLOC DNS Record Type Observed
The SANS Internet Storm Center has published an entry discussing the uncommon NIMLOC DNS record type, which has been observed appearing in network logs.

SharpHound Recon Attack – How AI enhanced the threat hunt
Researchers integrated an AI-driven security agent with full packet capture technology at Cisco Live AMER 2026 to automate threat hunting and analysis. The system successfully identified a potential SharpHound reconnaissance attack, analyzed network traffic, and accurately determined it to be a benign near-miss, saving significant analyst time and demonstrating the AI's potential to boost SOC efficiency.

Machine Speed, Human Judgement: How AI Changed the SOC in 2026
The article provides an inside perspective on how artificial intelligence and automation are reshaping security operations centers (SOCs). It highlights the integration of AI, automated processes, and agent-based workflows as key drivers of change in modern security.

Cisco Live Event SOC Educates Attendees on Security Operations
The Cisco Event SOC at Cisco Live AMER 2026 served a dual purpose of providing security operations during the event and educating attendees. Through guided tours, dedicated speaker sessions, and interactions at the World of Solutions, the SOC shared insights into its live operations.

What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
A product manager shared insights gained from working at the Cisco Live Security Operations Center. The experience highlighted the effective use of artificial intelligence, Splunk Enterprise Security, and Extended Detection and Response (XDR) technologies for accelerating threat investigations and improving the development of security detection and response tools.

How the Reddit and Discord false report scam steals accounts
Scammers are targeting users on platforms like Reddit and Discord by initiating conversations under the guise of a mistaken account report. They aim to trick victims into revealing login credentials or verification codes, or into changing their account's linked email address. The ultimate goal is to gain unauthorized access to accounts, lock users out, or extort payment by threatening account deletion or misuse.

County Government Reportedly Paid $1 Million to Cyber Extortion Group
A small county government in Ohio reportedly paid a cyber extortion group one million dollars. The payment was made to prevent the public release of data stolen during a cyberattack.

Hidden backdoor in Tenda router firmware grants admin access
A hidden backdoor has been discovered in multiple versions of Tenda router firmware. The hardcoded authentication backdoor allows unauthorized administrative access to the router web management panel.

Critical Gitea Flaw Under Active Exploitation, Researchers Warn
A critical vulnerability in Gitea, tracked as CVE-2026-20896, is being actively exploited. The flaw lets attackers bypass authentication with a single HTTP header to access repositories and secrets.

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Malware-as-a-Service offering called RedWing packages Android bank fraud tools and is rented via Telegram. It provides ready-made malware capable of taking over phones and stealing banking credentials and one-time passcodes.