LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!

News Archive

1920 stories · page 75 of 80

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ransomwarehigh

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Researchers have demonstrated a novel ransomware technique that operates entirely within a web browser, bypassing the need for native installations or exploits. By leveraging the File System Access API in Chrome, specifically on Android, malicious websites can trick users into granting access to sensitive photo directories. This method, inspired by AI-generated concepts, uses social engineering tactics like fake image-enhancement tools to prompt users for permissions, enabling the browser-based ransomware to potentially encrypt or modify files.

security

Martin Lee: Running through the Arctic (and the threat landscape)

Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry.

screenconnecthigh

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

Threat actors are distributing malicious installer archives that masquerade as popular freeware, such as OBS Studio and Bandicam. These installers contain a legitimate Microsoft binary alongside a rogue DLL that enables DLL sideloading. This process deploys the ScreenConnect remote access tool, which attackers use to maintain control over compromised systems and potentially execute further payloads like AsyncRAT.

phishing

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoi

ai

OpenClaw: risks for the users and how to mitigate them

OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

phishing

Phishing Attack Targets MetaMask Users with Fake Credentials

This morning, an interesting phishing email hit my mailbox. It targets Metamask[1], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It's pretty popular, so a

aihigh

AI Hallucinations Create Phantom Domains for Supply Chain Attacks

Artificial intelligence models can generate domain names that do not actually exist, a phenomenon known as "phantom squatting." Attackers are leveraging this AI hallucination to create malicious domains that mimic legitimate ones, thereby posing a significant threat to software supply chains. This tactic allows them to potentially intercept or manipulate software development processes.

securitycritical

China-Linked Group Targets Southeast Asia Critical Systems

The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.

iranhigh

Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool

A threat group linked to Iran, known as TAG-182, is actively distributing a surveillance tool called MarkiRAT. This malware is being spread through fake applications disguised as VPNs and download tools, primarily targeting Iranian citizens both within and outside the country. The operations appear to be conducted via social media platforms and are likely part of Iran's intensified cyber surveillance efforts.

ai

Fake Bug Report Hijacks AI Coding Agents at Scale

"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.

security

Scammers race to cash in on Venezuelan earthquake disaster

Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.

breach

Attackers Seize Exposed AI Endpoints to Power Offensive Ops

Threat actors don't need any special authentication to reach a target endpoint — they just need to know where it is.

ai

Why Identity Security Is Your Cyber Career Entry Point

In this "Heard it From a CISO" video, Silverfort CISO John Paul Cunningham explains that AI in cybersecurity workflows is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into this essential f

quantum computinghigh

Accelerating the quantum-safe timeline

Microsoft is accelerating its timeline for transitioning to post-quantum cryptography (PQC) due to advancements in quantum research and government guidance. The company aims to have its products and services ready for PQC by 2029, encouraging organizations to begin their transition sooner to mitigate risks and costs associated with this multi-year engineering effort.

phishing

Phishers Gain Persistence at EU, Asia Hospitality Orgs

Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.

ai security

​​What’s new in Microsoft Security: June 2026

Microsoft is enhancing its security offerings with a focus on AI and agent protection. New features include 'Codename MDASH,' an AI-powered system for discovering and remediating complex software vulnerabilities across environments. Additionally, Microsoft Defender now extends endpoint protection to local AI agents, detecting and blocking threats like prompt injection attempts targeting tools such as GitHub Copilot CLI and Claude Code.

patch

Weekly Update 510: Live From Mallorca with Scott Helme

How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and to make it

ai

AI-Generated Workflows Are a Silent Security Disaster

Teams are dealing with a truly dangerous problem — automation that works, but that no one understands.

ai

The Realities of AI Video Surveillance

The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mass spying in the way

malware

USB drives carrying China-linked malware infected Japanese military networks for nearly a year

Read more in my article on the Hot for Security blog.

patch

Apple Releases June Software Updates

Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.

nation-state

NIST Enrichment Reductions Impact CVE Coverage, Accuracy

The National Institute of Standards and Technology (NIST) scaled back the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers.

CVE-2026-48558critical

'Djinn' Stealer Targets Cloud, AI Credentials

The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.

vulnerabilitycritical

Vulnerabilities Expose Private Data in Indian Government Systems

One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.