LIVE · cybersecurity feed
Live wire

News Archive

561 stories · page 12 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

copyright infringement

OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

Adult content creators are inadvertently causing hacked government and university websites to disappear from search results. This occurs when creators issue copyright takedown requests, often under the Digital Millennium Copyright Act (DMCA), to remove pirated content from search engines. Scammers have been exploiting insecure government and educational domains to host malicious pages, using the names of adult creators to lure victims. Consequently, DMCA requests aimed at protecting creators' content are leading to the removal of these compromised, but legitimate, government and educational web pages from search results.

cisahigh

CISA orders feds to prioritize patching Langflow auth bypass flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to prioritize patching a critical authentication bypass vulnerability within the Langflow AI agent framework. This directive comes as the flaw is reportedly being actively exploited.

china

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor, UAT-7810, is reportedly enhancing its custom malware to broaden its Operational Relay Box (ORB) network. This expansion involves compromising internet-facing networking devices, according to Cisco Talos.

vulnerability managementhigh

Found fast, fixed slow: The gap the AI clearinghouse must close

A new AI cybersecurity clearinghouse, mandated by a recent executive order, faces the critical challenge of moving beyond rapid vulnerability discovery to effective remediation. While AI can quickly identify software flaws, the process of validating, prioritizing, and patching these issues remains a significant bottleneck, particularly for open-source software. The clearinghouse must focus on building infrastructure for triage, incentivizing maintainer and user collaboration, and leveraging Software Bills of Materials (SBOMs) to ensure vulnerabilities are actually fixed.

CVE-2026-48282critical

U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog

The U.S. CISA has added several vulnerabilities to its catalog of actively exploited flaws. These include a critical path traversal vulnerability in Adobe ColdFusion that allows for unauthenticated code execution, and multiple issues affecting Joomlack Page Builder and JoomShaper SP Page Builder that can lead to unauthorized access and malicious file uploads. Organizations are urged to update affected software immediately.

ubiquiticritical

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti has issued updates to address seven critical vulnerabilities within its UniFi OS. Among these patched flaws is a command injection vulnerability rated at maximum severity.

cybersecurity

NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense

The UK's National Cyber Security Centre is seeking AI partners to develop a national-scale "Cyber Shield." This initiative aims to enhance the country's cyber defenses by leveraging artificial intelligence.

memory

Understanding Program Memory Stack with Stack Simulator

An explanation of the program memory stack, detailing how local variables and return addresses are managed. It uses a stack-of-plates analogy to make the concept easy to follow.

estonia

State IDs for AI Agents: Will Estonia Set a Precedent?

Estonia is exploring methods to facilitate the use of AI agents by its citizens for governmental services. This initiative brings forth important questions regarding digital identity and authentication for AI entities.

aihigh

CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's advanced AI model, Mythos, to proactively scan government code for security vulnerabilities. The goal is to identify and fix flaws before malicious actors, such as foreign intelligence agencies or cybercriminals, can exploit them. Initial audits using the AI have allegedly uncovered a significant number of bugs, though details on the scope and severity remain undisclosed.

cisacritical

CISA orders feds to patch max severity ColdFusion flaw by Friday

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a maximum-severity Adobe ColdFusion vulnerability. This flaw is currently being actively exploited and requires patching by Friday.

CVE-2026-43499critical

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Nebula Security has revealed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present for 15 years. This flaw allows any logged-in user to achieve root privileges and container escape on unpatched systems, as it is included by default in most Linux distributions.

CVE-2026-48282high

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.

banking trojanhigh

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

aihigh

The Threat Isn’t the Frontier Model

The article argues that the primary AI security threat is not advanced frontier models, but rather the increasing accessibility of powerful open-source AI models that can be run on modest hardware. Adversaries are expected to leverage these models for autonomous attacks as quantization reduces their resource requirements. CISOs are urged to proactively build and test defensive AI agents now to counter this emerging threat, focusing on areas like Continuous Threat Exposure Management (CTEM), Breach and Attack Simulation (BAS), and Security Operations.

accenture

Accenture confirms breach after hacker offers stolen data for sale

Accenture has verified a data breach following claims by a threat actor who offered stolen information for sale. The compromised data reportedly includes 35 GB of source code and other sensitive material.

vidar stealerhigh

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

Researchers have uncovered a sophisticated campaign distributing the Vidar stealer and XMRig cryptocurrency miner, primarily targeting users seeking cracked software. Attackers use malvertising to lure victims into downloading password-protected archives containing malicious loaders. These loaders are signed with a fake certificate and employ techniques like file-size inflation and AMSI bypass to evade detection before dropping the final payloads.

hacktivism

Spain arrests suspected hacker linked to Russian hacktivist campaign

Spanish police, with assistance from the FBI, have arrested an individual suspected of supporting the pro-Russian hacktivist group Cyber Army of Russia Reborn. The arrest, which occurred in March but was announced recently, is part of a broader international effort to combat cybercrime. The suspect allegedly provided logistical support to another hacker and participated in activities aimed at spreading pro-Russian narratives.

CVE-2026-20896critical

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets

A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.

phishing

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

googlehigh

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

malwarehigh

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese state-sponsored hackers, identified as UAT-7810, have developed new malware named LONGLEASH. It is being used to expand their ORB network by compromising internet-facing devices, specifically targeting unpatched Ruckus routers.

federal governmenthigh

OMB M-26-14: Why federal agencies must fix asset visibility first

The U.S. Office of Management and Budget (OMB) has issued Memorandum M-26-14, a new directive for federal agencies focused on improving logging and network visibility. This memo replaces previous mandates with a five-level maturity model for logging, where progress is directly tied to an agency's ability to discover and inventory its IT, OT, and IoT assets. Achieving higher maturity levels requires progressively higher percentages of asset capture, making comprehensive asset visibility the foundational step for compliance.

dns

Uncommon NIMLOC DNS Record Type Observed

The SANS Internet Storm Center has published an entry discussing the uncommon NIMLOC DNS record type, which has been observed appearing in network logs.