LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1920 stories · page 71 of 80

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ai

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

The use of AI in software development introduces new challenges to supply chain security. Organizations must now consider the security implications of AI-generated code, in addition to traditional component analysis. This requires a reevaluation of existing security practices to adapt to AI's role in code creation.

ai

Claude Code’s hidden tracker was an “experiment,” says Anthropic

A researcher discovered a hidden tracking mechanism within Anthropic's Claude Code client that encoded user traffic data based on system time zones. Anthropic has since removed the feature, stating it was an experimental measure to prevent account abuse and protect against model distillation, potentially linked to recent US government export controls.

google

Google Is Suing Chinese Scammers Who Are Using Gemini

Google has filed a lawsuit against a Chinese criminal organization known as Outsider Enterprise. The group is accused of providing "phishing-as-a-service" through Telegram and allegedly leveraging Google's Gemini platform for their fraudulent operations.

industrial automation

Threat landscape for industrial automation systems. Q1 2026

In the first quarter of 2026, the overall percentage of industrial control systems (ICS) computers experiencing malware infections continued its downward trend, reaching a three-year low. However, certain regions and industries, particularly biometric systems and manufacturing, saw increases in specific threat categories like spyware and internet-based threats. While ransomware and malicious documents saw significant decreases, malicious scripts, phishing pages, and denylisted internet resources remained prevalent.

threat actor

UAT-7810 continues building ORB networks using new malware

The threat actor UAT-7810 is reportedly developing new custom malware. This malware is being utilized to establish ORB networks, indicating an evolution in their tools and ongoing malicious operations.

linuxcritical

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

A recently discovered 16-year-old vulnerability in the Linux kernel's KVM hypervisor, dubbed Januscape, allows attackers to break out of a virtual machine. This flaw affects both Intel and AMD systems and could enable unauthorized code execution on the underlying host system.

microsoft

Microsoft to enable Windows settings backup by default for orgs

Microsoft is making its Windows settings backup and restore feature the default for business organizations. This update will automatically apply to devices managed by Microsoft Entra that are upgraded to Windows 11 version 26H2.

ai

Scammers are using AI to sell impossible flowers

Scammers are leveraging AI image generation to create and market seeds for non-existent, fantastical plants. These listings, appearing on major e-commerce platforms like eBay, Amazon, and Etsy, depict flowers in impossible shapes and colors, enticing buyers with visually appealing AI-generated images. The scam aims to profit from the sale of these fake seeds, differing from previous brushing scams that used unsolicited seed packets to manipulate reviews.

funding

Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security

Keyfactor, a provider of machine identity and cryptographic security solutions, has announced a funding round valued at over $1 billion. The investment will support the advancement of its platform, with a focus on addressing future security challenges from artificial intelligence and post-quantum cryptography.

CVE-2024-42009high

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Researchers have identified a new cyberattack campaign targeting academic institutions in North America. The attackers, believed to be linked to China, are exploiting vulnerabilities within the Roundcube webmail system used by physics and engineering departments.

CVE-2024-42009high

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

A China-aligned espionage group has been observed targeting U.S. and Canadian universities, specifically in physics and engineering departments. The attackers exploited two vulnerabilities in the Roundcube email client (CVE-2024-42009 and CVE-2025-49113) to steal credentials and establish persistent access through webshells and backdoors. Proofpoint researchers identified the campaign, which appears to be ongoing, and noted that victims may not yet be aware of the compromise.

beyondtrustcritical

BeyondTrust warns of critical flaws in remote access software

BeyondTrust has alerted users to two critical vulnerabilities affecting its Remote Support and Privileged Remote Access software. These security weaknesses could potentially enable attackers to circumvent authentication mechanisms.

windows 11

Microsoft testing new Cloud Rebuild Windows 11 recovery feature

Microsoft is piloting a new Cloud Rebuild feature for Windows 11 through its Insider Preview program. This functionality aims to simplify the recovery process for users by allowing them to rebuild their operating system from the cloud. The feature is currently available to testers in the Experimental channel.

CVE-2026-11405high

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

CERT/CC has identified a hidden backdoor in multiple Tenda router firmware versions. This backdoor allows unauthorized administrative access to the devices' web interfaces.

CVE-2026-40138critical

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust has issued patches for critical vulnerabilities in its Remote Support and Privileged Remote Access software. These flaws could permit unauthenticated attackers to gain unauthorized control over affected systems.

ai securityhigh

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike has identified and cataloged 18 new prompt injection techniques, expanding their taxonomy to over 200 distinct methods. These new techniques, including Trigger-Activated Rule Addition and Algorithmic Payload Decomposition, highlight the evolving sophistication of attacks against AI systems. The company emphasizes the need for enhanced AI threat modeling, red teaming, detection engineering, and runtime visibility to combat these emerging threats.

infostealerhigh

'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks

A sophisticated information-stealing malware known as 'BusySnake' has been observed targeting critical infrastructure. Threat actors identified as 'Armored Likho' have successfully infiltrated government and electrical power organizations across Russia, Brazil, and Kazakhstan.

vulnerability

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).

cse

Canadian spy agency reports hacking three criminal groups in 2025

Canada's Communications Security Establishment (CSE) conducted offensive cyber operations against three distinct criminal organizations in 2025. The targets included a ransomware-as-a-service operation, an extremist group with international ties, and drug trafficking networks.

phishing

Phishing poses as big-brand job interview to steal Google accounts

A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]

malware

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]

security

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks

Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’

security

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations.

security

Vietnam arrests suspects behind HiAnime anime piracy service

​Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]