LIVE · cybersecurity feed
Live wire

News Archive

561 stories · page 8 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

vulnerability

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package meant to run inside a private environment. Dusseldorf is an out-of-band application security testing pla

ransomware

More alerts are making your team slower, and an outcome-based SOC fixes that

In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account, and exposed thousands of passwords in three minutes. Ransomware gr

CVE-2026-42533critical

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

A critical vulnerability (CVE-2026-42533) has been discovered in NGINX, potentially allowing remote attackers to crash worker processes or even execute arbitrary code. The flaw, present in versions from 0.9.6 up to 1.31.2, arises from a specific configuration involving regex-based maps and string expressions. While F5 has released patches, researchers suggest that existing mitigations might not be entirely effective, emphasizing the need for immediate upgrades.

ai

Connecting AI agents to outside services explodes the risk radius

Connect all the things and watch what happens

vulnerability

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots AsyncAPI npm organization compromised, 2M weekly downloads affected OkoBot: new sophisticated malware framework targets cryptocur

ransomwarehigh

Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

The latest Security Affairs newsletter covers a range of global cybersecurity incidents and trends. Key topics include ransomware extortion, significant cyberattacks on major companies like Odido and a Japanese taxi operator, and the compromise of the AsyncAPI npm organization. The newsletter also highlights new malware strains, exploitation campaigns targeting CMS, and state-sponsored cyber activities from Russia, China, and North Korea.

apthigh

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor, potentially Chinese-speaking, is targeting Russian government and other high-value organizations by abusing the update mechanism of ViPNet, a popular Russian cybersecurity product. The campaign, active since at least May and dubbed HelloNet, involves injecting malicious DLLs into the ViPNet update directory, which then load further malware payloads like proxies, backdoors, and log cleaners. Researchers have low confidence in the attribution due to weak evidence.

malware

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's

CVE-2026-15409critical

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

vulnerabilitycritical

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep research agent Running a large language model against a live cloud account to hunt for security holes comes w

CVE-2026-63030critical

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default

vulnerability

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

opensslhigh

OpenSSL Vulnerability Allows Memory Exhaustion via 11-Byte Payload

Okta's Red Team has identified a denial-of-service vulnerability in OpenSSL named HollowByte. A remote, unauthenticated attacker can exploit this flaw using an 11-byte payload to trigger excessive memory allocation on the server before the TLS handshake completes, leading to a denial of service. The vulnerability stems from OpenSSL's trust in the declared message size, which allows for large memory allocations based on untrusted input, and the issue is compounded by heap fragmentation preventing memory reuse.

vulnerabilitycritical

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]

CVE-2026-60137high

Two High-Severity WordPress Vulnerabilities Require Immediate Patching

WordPress version 6.9 has been impacted by two significant security flaws. One vulnerability allows for SQL injection, while the other, a REST API issue, could lead to remote code execution. Both have been addressed in the latest security release, version 7.0.2.

malwarehigh

Microsoft Warns of Increased ACR Stealer Malware Attacks

Microsoft has reported a significant increase in attacks leveraging the ACR Stealer malware. This malicious software targets enterprise customers, aiming to pilfer sensitive information such as stored browser passwords, authentication tokens, and important documents.

malwarehigh

China-Linked Daxin Malware Active on Manufacturer's Network Since 2013

Researchers have discovered the China-linked Daxin rootkit and a new Stupig backdoor still active on the network of a Taiwanese subsidiary of a high-tech manufacturer. Evidence suggests the intrusion dates back to 2013, meaning it remained undetected for thirteen years. Daxin, a Windows kernel-mode rootkit, employs advanced techniques to communicate within secured networks and hide its traffic.

CVE-2026-25089critical

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities affecting Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog. The flaws include OS command injection in FortiSandbox and a deserialization vulnerability in SharePoint that allows for remote code execution without authentication. Microsoft has confirmed active exploitation of the SharePoint flaw.

breach

Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

ai

Prompt Injection Attacks Disrupt AI Hacking Agents

New "context bombing" techniques are being used to thwart malicious AI agents. These methods trick the AI into shutting down by feeding it misleading information, preventing it from carrying out harmful actions.

north koreahigh

North Korean hackers use fake coding interviews to steal developer credentials

Elastic Security Labs has identified a new campaign by North Korean threat actors, dubbed 'Contagious Interview,' targeting software developers. The attackers use fake job postings and coding challenges, embedding malware within SVG files using steganography. Successful execution of these projects leads to the deployment of a multi-stage payload designed to steal credentials, cryptocurrency, and provide remote access.

android

Gemini AI Flaw Lets Strangers Message From Locked Android Phones

A vulnerability has been discovered in Google's Gemini AI assistant for Android devices. This flaw allows unauthorized individuals to send messages from a user's locked phone. The issue potentially exposes users to misuse of their communication channels.

CVE-2026-63030critical

Critical RCE Vulnerability in WordPress Core Affects Millions of Sites

A critical unauthenticated remote code execution vulnerability has been discovered in WordPress Core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw, identified by Searchlight Cyber, allows attackers to execute code via the REST API batch endpoint without needing any user interaction or valid account. While exploit details are not yet public, the widespread use of WordPress makes this a significant risk, and urgent patching is recommended.