News Archive
552 stories · page 3 of 23Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Rubio restricts visas for sextortionists, cyber scammers
The move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes. The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.

Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]

Introducing Cache Response Rules
Cloudflare has introduced Cache Response Rules, a new feature designed to optimize content caching by running after an origin server responds but before the content is cached. These rules allow users to modify response headers, such as stripping `Set-Cookie` or adjusting `Cache-Control` directives, which were previously difficult or impossible to manage without origin server changes. This aims to improve cache hit ratios, reduce origin load, and enhance performance by addressing common caching inefficiencies.

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A sophisticated Russian espionage campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), has been actively exploiting a zero-day vulnerability in Zimbra Collaboration's webmail client since at least July 2025. This flaw allowed attackers to steal sensitive data, including emails, contact lists, browser-saved passwords, and two-factor authentication codes, by simply having a user view a specially crafted HTML email. The vulnerability, identified as CVE-2025-66376, was patched by Zimbra in November 2025, but the attackers continued to leverage it for months prior to the fix.

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.

Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

International alert spotlights Russia-linked attacks on Zimbra webmail
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.

Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]

Year-long Russian attacks infect users as soon as they look at an email
Phishing for dummies

Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]

Millions of California-bought cars can be hijacked via Bluetooth
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers

Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite

Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. [...]

Oracle drops 1,449 security patches like it's the new normal
Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads

Iran-linked crews are probing more flavors of US industrial kit
CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. [...]

Microsoft Copilot Deployments Delayed Over Security Concerns
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data

Swiss train maker tells ransomware crooks to get off at the next stop
Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform

How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist. Since no real victim monitors misuse, a

Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Flash architecture and designed specifically to find, validate, and patch software vulnerabilities. It […]

PyPI hardens package security with new upload restrictions
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the amount of “cleanup” work associated with project compromises for PyPI admins. This restriction also means that compromises

Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]

New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.