News Archive
561 stories · page 12 of 24Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
Adult content creators are inadvertently causing hacked government and university websites to disappear from search results. This occurs when creators issue copyright takedown requests, often under the Digital Millennium Copyright Act (DMCA), to remove pirated content from search engines. Scammers have been exploiting insecure government and educational domains to host malicious pages, using the names of adult creators to lure victims. Consequently, DMCA requests aimed at protecting creators' content are leading to the removal of these compromised, but legitimate, government and educational web pages from search results.

CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to prioritize patching a critical authentication bypass vulnerability within the Langflow AI agent framework. This directive comes as the flaw is reportedly being actively exploited.

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor, UAT-7810, is reportedly enhancing its custom malware to broaden its Operational Relay Box (ORB) network. This expansion involves compromising internet-facing networking devices, according to Cisco Talos.

Found fast, fixed slow: The gap the AI clearinghouse must close
A new AI cybersecurity clearinghouse, mandated by a recent executive order, faces the critical challenge of moving beyond rapid vulnerability discovery to effective remediation. While AI can quickly identify software flaws, the process of validating, prioritizing, and patching these issues remains a significant bottleneck, particularly for open-source software. The clearinghouse must focus on building infrastructure for triage, incentivizing maintainer and user collaboration, and leveraging Software Bills of Materials (SBOMs) to ensure vulnerabilities are actually fixed.

U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog
The U.S. CISA has added several vulnerabilities to its catalog of actively exploited flaws. These include a critical path traversal vulnerability in Adobe ColdFusion that allows for unauthenticated code execution, and multiple issues affecting Joomlack Page Builder and JoomShaper SP Page Builder that can lead to unauthorized access and malicious file uploads. Organizations are urged to update affected software immediately.

Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has issued updates to address seven critical vulnerabilities within its UniFi OS. Among these patched flaws is a command injection vulnerability rated at maximum severity.

NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense
The UK's National Cyber Security Centre is seeking AI partners to develop a national-scale "Cyber Shield." This initiative aims to enhance the country's cyber defenses by leveraging artificial intelligence.

Understanding Program Memory Stack with Stack Simulator
An explanation of the program memory stack, detailing how local variables and return addresses are managed. It uses a stack-of-plates analogy to make the concept easy to follow.

State IDs for AI Agents: Will Estonia Set a Precedent?
Estonia is exploring methods to facilitate the use of AI agents by its citizens for governmental services. This initiative brings forth important questions regarding digital identity and authentication for AI entities.

CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's advanced AI model, Mythos, to proactively scan government code for security vulnerabilities. The goal is to identify and fix flaws before malicious actors, such as foreign intelligence agencies or cybercriminals, can exploit them. Initial audits using the AI have allegedly uncovered a significant number of bugs, though details on the scope and severity remain undisclosed.

CISA orders feds to patch max severity ColdFusion flaw by Friday
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a maximum-severity Adobe ColdFusion vulnerability. This flaw is currently being actively exploited and requires patching by Friday.

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Nebula Security has revealed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present for 15 years. This flaw allows any logged-in user to achieve root privileges and container escape on unpatched systems, as it is included by default in most Linux distributions.

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

The Threat Isn’t the Frontier Model
The article argues that the primary AI security threat is not advanced frontier models, but rather the increasing accessibility of powerful open-source AI models that can be run on modest hardware. Adversaries are expected to leverage these models for autonomous attacks as quantization reduces their resource requirements. CISOs are urged to proactively build and test defensive AI agents now to counter this emerging threat, focusing on areas like Continuous Threat Exposure Management (CTEM), Breach and Attack Simulation (BAS), and Security Operations.

Accenture confirms breach after hacker offers stolen data for sale
Accenture has verified a data breach following claims by a threat actor who offered stolen information for sale. The compromised data reportedly includes 35 GB of source code and other sensitive material.

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Researchers have uncovered a sophisticated campaign distributing the Vidar stealer and XMRig cryptocurrency miner, primarily targeting users seeking cracked software. Attackers use malvertising to lure victims into downloading password-protected archives containing malicious loaders. These loaders are signed with a fake certificate and employ techniques like file-size inflation and AMSI bypass to evade detection before dropping the final payloads.

Spain arrests suspected hacker linked to Russian hacktivist campaign
Spanish police, with assistance from the FBI, have arrested an individual suspected of supporting the pro-Russian hacktivist group Cyber Army of Russia Reborn. The arrest, which occurred in March but was announced recently, is part of a broader international effort to combat cybercrime. The suspect allegedly provided logistical support to another hacker and participated in activities aimed at spreading pro-Russian narratives.

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese state-sponsored hackers, identified as UAT-7810, have developed new malware named LONGLEASH. It is being used to expand their ORB network by compromising internet-facing devices, specifically targeting unpatched Ruckus routers.

OMB M-26-14: Why federal agencies must fix asset visibility first
The U.S. Office of Management and Budget (OMB) has issued Memorandum M-26-14, a new directive for federal agencies focused on improving logging and network visibility. This memo replaces previous mandates with a five-level maturity model for logging, where progress is directly tied to an agency's ability to discover and inventory its IT, OT, and IoT assets. Achieving higher maturity levels requires progressively higher percentages of asset capture, making comprehensive asset visibility the foundational step for compliance.

Uncommon NIMLOC DNS Record Type Observed
The SANS Internet Storm Center has published an entry discussing the uncommon NIMLOC DNS record type, which has been observed appearing in network logs.