LIVE · cybersecurity feed
Live wire

News Archive

561 stories · page 13 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ai

SharpHound Recon Attack – How AI enhanced the threat hunt

Researchers integrated an AI-driven security agent with full packet capture technology at Cisco Live AMER 2026 to automate threat hunting and analysis. The system successfully identified a potential SharpHound reconnaissance attack, analyzed network traffic, and accurately determined it to be a benign near-miss, saving significant analyst time and demonstrating the AI's potential to boost SOC efficiency.

ai

Machine Speed, Human Judgement: How AI Changed the SOC in 2026

The article provides an inside perspective on how artificial intelligence and automation are reshaping security operations centers (SOCs). It highlights the integration of AI, automated processes, and agent-based workflows as key drivers of change in modern security.

cisco

Cisco Live Event SOC Educates Attendees on Security Operations

The Cisco Event SOC at Cisco Live AMER 2026 served a dual purpose of providing security operations during the event and educating attendees. Through guided tours, dedicated speaker sessions, and interactions at the World of Solutions, the SOC shared insights into its live operations.

ai

What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

A product manager shared insights gained from working at the Cisco Live Security Operations Center. The experience highlighted the effective use of artificial intelligence, Splunk Enterprise Security, and Extended Detection and Response (XDR) technologies for accelerating threat investigations and improving the development of security detection and response tools.

social engineeringhigh

How the Reddit and Discord false report scam steals accounts

Scammers are targeting users on platforms like Reddit and Discord by initiating conversations under the guise of a mistaken account report. They aim to trick victims into revealing login credentials or verification codes, or into changing their account's linked email address. The ultimate goal is to gain unauthorized access to accounts, lock users out, or extort payment by threatening account deletion or misuse.

ransomwarehigh

County Government Reportedly Paid $1 Million to Cyber Extortion Group

A small county government in Ohio reportedly paid a cyber extortion group one million dollars. The payment was made to prevent the public release of data stolen during a cyberattack.

vulnerabilityhigh

Hidden backdoor in Tenda router firmware grants admin access

A hidden backdoor has been discovered in multiple versions of Tenda router firmware. The hardcoded authentication backdoor allows unauthorized administrative access to the router web management panel.

CVE-2026-20896critical

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

A critical vulnerability in Gitea, tracked as CVE-2026-20896, is being actively exploited. The flaw lets attackers bypass authentication with a single HTTP header to access repositories and secrets.

malwarehigh

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A new Malware-as-a-Service offering called RedWing packages Android bank fraud tools and is rented via Telegram. It provides ready-made malware capable of taking over phones and stealing banking credentials and one-time passcodes.

vulnerabilityhigh

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

A now-patched flaw in Google Dialogflow CX could have allowed chatbot hijacking. An attacker with edit rights on a single Code Block agent could compromise other agents in the same Google Cloud project and read live conversations.

legal

Supreme Court allows Texas app law requiring age verification to take effect

The Supreme Court has permitted a Texas law requiring app age verification to take effect. Advocacy and technology trade groups had sought an emergency stay of the Texas App Store Accountability Act.

roundcubehigh

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers

A sophisticated threat group, believed to be operating from China, is actively exploiting security weaknesses in Roundcube webmail servers. Their objective is to gain unauthorized access to university networks across the United States and Canada, with the ultimate goal of stealing user login information.

ai

Britain plans to build autonomous AI 'Cyber Shield' to defend nation

Britain is developing an autonomous AI-powered Cyber Shield to strengthen national defense against cyber threats. The National Cyber Security Centre says such a system is needed as attackers could operate at machine speed and scale.

vulnerabilityhigh

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

A vulnerability dubbed GitLost leaks private data from GitHub Agentic Workflows. An unauthenticated attacker can craft a public GitHub Issue to silently exfiltrate data from private repositories.

arrest

Spain arrests suspected member of pro-Russian hacktivist groups

Spanish authorities have arrested an individual suspected of active membership in pro-Russian hacktivist groups, reportedly including CyberArmy of Russia Reborn and Z-Pentest.

phishing

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did no

vulnerability management

Qualys Joins Cisco Cloud Control Studio as a Launch Partner to Bring Risk Intelligence to Agentic Operations

Qualys has partnered with Cisco to integrate its risk intelligence capabilities into Cisco's new Cloud Control Studio platform. This collaboration aims to provide joint customers with unified asset inventory, prioritized vulnerability findings, and automated remediation workflows directly within Cisco's AI-driven operational environment. The integration is designed to help security teams manage expanding attack surfaces and overwhelming alert volumes by providing context and enabling faster, more efficient responses.

data breachhigh

Major Japanese telco says cyberattack exposed 12 million emails

A major Japanese telecommunications company reported a cyberattack that exposed 12 million email accounts. The breach hit an email system managing accounts, webmail, and storage across five internet service providers.

vulnerabilityhigh

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Noma Security demonstrated that a public GitHub Issue can trick GitHub Agentic Workflows into leaking private repository data. A seemingly innocuous issue on a public repo can be crafted to exfiltrate private contents.

github actions

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

ActiveState detailed a GitHub Actions attack pattern that often bypasses traditional CI security scanners. The analysis explains how these attack chains evade detection and how to better govern CI/CD pipelines.

phishinghigh

Fake Netflix, Coca-Cola, and FIFA job scams target marketers

Scammers are impersonating well-known brands like Netflix, Coca-Cola, and FIFA to target marketing professionals with fake job offers. The fraudulent websites use sophisticated techniques, including mimicking Google sign-in pop-ups and routing victims through legitimate services, to appear credible. This campaign has been active for at least five months, exploiting the competitive job market and the increasing use of AI in recruitment.

law enforcement

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

A court filing revealed that a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker. The identifier linked the suspect to a break-in at a luxury jewelry retailer.

vulnerabilitycritical

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

A now-patched critical session isolation flaw was found in the enterprise generative-AI platform Writer. It could have let agent previews leak session tokens, enabling cross-tenant compromise.

cisa

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

CISA is reportedly using Anthropic Mythos AI to scan government software for vulnerabilities. The audits are said to be led by the agency Attack Surface Evaluation team to strengthen federal security reviews.