News Archive
1920 stories · page 72 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

US Army websites defaced with pro-Kurdish sentiments, insults to Trump
Several U.S. Army websites experienced defacement through a 404 hijacking campaign, displaying messages critical of President Trump and Ambassador Tom Barrack, and advocating for Kurdish independence. The compromised subdomains, oil.army.mil and ai2c.army.mil, which are related to innovation and AI integration respectively, showed these messages on error pages. This technique exploits a website's error handling to display unauthorized content without breaching core pages.

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU

JadePuffer: The First Complete LLM-Driven Ransomware Attack
An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from

How to tell if an image is AI-generated
Scammers are increasingly using realistic AI-generated images to create fake scenarios for financial or personal information theft. Traditional methods of spotting AI images, like checking for inconsistencies in details, are becoming obsolete. Instead, users are advised to verify the image's origin through reverse image searches or official tools like Google's Gemini, and to be skeptical of emotionally charged or urgent requests that accompany the images.

5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management
A new report from Frost & Sullivan highlights the evolving landscape of Cloud Security Posture Management (CSPM), which is shifting from a compliance-focused tool to an integrated governance layer within Cloud Native Application Protection Platforms (CNAPPs). The market is projected to grow significantly, driven by the need for continuous risk-based prioritization, code-to-cloud visibility, and platform consolidation to manage multicloud complexity. Artificial intelligence is also playing an increasing role in enhancing CSPM capabilities.

The Shift Toward Business-Aligned Risk Management
Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek.

Sysdig clocks first documented case of agentic ransomware
Researchers have documented the first instance of agentic ransomware, where an artificial intelligence agent autonomously managed an entire extortion operation. The AI handled tasks ranging from initial reconnaissance and credential theft to encryption and ransom note delivery. While not every step was fully automated, the AI significantly reduced complexity and accelerated the attack's tempo, demonstrating a new level of sophistication in cybercrime.

Is Your AppSec Program Built to Close the OWASP Top 10 2025 Coverage Gap?
The OWASP Top 10 2025 list introduces new vulnerabilities, particularly in API security and modern authentication flows, which many current application security programs fail to adequately address. Traditional security scanners often miss critical areas like Broken Object Level Authorization (BOLA) and Server-Side Request Forgery (SSRF) due to limitations in handling complex authentication and multi-role testing. Organizations need to adapt their security strategies to cover these evolving threats and close coverage gaps before they lead to significant remediation efforts.

A Day With Your Vector Command Red Team Pod
Continuous red teaming involves a dedicated team of specialists who work daily against a client's environment to identify risks. This ongoing process simulates a real adversary's persistence and coordination, providing a dynamic view of an organization's security posture. By continuously monitoring changes and potential vulnerabilities, the team offers actionable insights that go beyond traditional periodic assessments.

RCS Uses NAPTR Records for DNS Resolution
Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol [1]. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
A new modular command-and-control framework, dubbed 'Cavern Manticore,' has been observed in the wild, attributed to an Iran-nexus threat actor targeting Israeli government and IT sectors. The framework utilizes a .NET foundation but employs diverse compilation formats to evade analysis. Attackers gain initial access by exploiting legitimate software deployment features, such as RMM tools, to infiltrate victim environments.

Ransomware Attacks Hit Financial, Defense, and Manufacturing Firms
Several organizations, including River Bank & Trust, Indra Group, and Nidec, have recently fallen victim to ransomware attacks. These incidents have led to potential data exfiltration and service disruptions. Additionally, a new AI-driven ransomware technique has been demonstrated that exploits browser APIs to encrypt user files.

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The mult

France to Stop Certifying Non-Quantum-Safe Encryption
France is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodie

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website
Attackers are exploiting a legitimate Microsoft authentication feature, the Device Authorization Grant, to conduct phishing attacks. This method bypasses traditional URL checking by directing users to input codes on trusted Microsoft domains. The attack leverages the protocol designed for input-constrained devices, tricking users into authorizing malicious access.

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, th

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Th

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd p

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred t