LIVE · cybersecurity feed
Live wire

News Archive

561 stories · page 9 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

data breachhigh

Ernst & Young Data Breach Linked to Compromised Third-Party Support System

Ernst & Young (EY) has reported a data breach stemming from a compromised third-party IT support ticket system. The attackers gained access to documents containing client tax information that were stored within the platform. EY detected suspicious activity on April 23rd and has engaged cybersecurity experts to investigate the incident, confirming that unauthorized access has ceased.

CVE-2026-60137critical

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws

Cloudflare has released new Web Application Firewall (WAF) rules to protect WordPress sites from two severe vulnerabilities. These flaws include an unauthenticated remote code execution (RCE) bug in the REST API and a related SQL injection vulnerability, affecting specific versions of WordPress. While Cloudflare's WAF provides immediate protection, users are strongly advised to update their WordPress installations to the patched versions released by the WordPress security team.

wordpresscritical

WordPress Core Flaw Allows Unauthenticated Code Execution

A critical vulnerability in WordPress core allows unauthenticated attackers to execute arbitrary code on affected websites. The flaw, discovered by Adam Kues of Searchlight Cyber, impacted all sites running versions 6.9 and 7.0. WordPress has since released patches 6.9.5 and 7.0.2, and has enabled forced updates to protect all sites.

cybersecurityhigh

Abbott Investigates Two Cyber Incidents Amid Extortion Claims

Abbott Laboratories is looking into two distinct cybersecurity events. One incident involved unauthorized access to internal legacy systems within its Cancer Diagnostics business. Separately, the company is investigating claims that its LabCentral portal was breached and data was exfiltrated.

openssl

OpenSSL Flaw Allows Denial-of-Service via Small TLS Requests

A denial-of-service vulnerability in OpenSSL, dubbed HollowByte, can be triggered by sending an 11-byte TLS request. This request causes unpatched servers, particularly those using glibc, to allocate up to 131 KB of memory that remains unavailable until the server process is restarted. The fix was released in June without specific disclosure.

ransomwarecritical

Inc Ransomware Exploits SonicWall SMA Zero-Days

The Inc ransomware group is actively exploiting two zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances. Successful exploitation grants attackers root-level control over the affected devices, enabling further malicious activities.

metasploit

Metasploit Adds Linux Fetch Multi Payload for Architecture Agnostic Exploits

The Metasploit Framework has introduced a new Linux Fetch Multi payload family. This enhancement allows for on-the-fly identification of the target host's architecture, enabling a single payload and handler to serve multiple Linux targets without manual architecture selection. This feature is available for HTTP and HTTPS-based fetch payloads.

npmhigh

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT

Researchers have identified seven malicious npm packages that were part of a software supply chain attack targeting the Vite frontend tooling ecosystem. These packages, dubbed ViteVenom, utilized a sophisticated four-tier blockchain-based command-and-control infrastructure across multiple networks to deliver a remote access trojan (RAT).

CVE-2026-58644critical

Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild

Microsoft has released a security advisory for CVE-2026-58644, a critical vulnerability in on-premises SharePoint Server versions that allows unauthenticated remote code execution. The flaw, stemming from untrusted data deserialization, has been actively exploited and added to CISA's Known Exploited Vulnerabilities catalog. Organizations are urged to apply security updates immediately and monitor for exploitation attempts.

opensslhigh

HollowByte DDoS flaw bloats OpenSSL server memory

A vulnerability named HollowByte has been discovered that enables unauthenticated attackers to cause a denial-of-service on OpenSSL servers. The attack requires only a small, 11-byte malicious payload to trigger the condition, which reportedly causes server memory to bloat.

cyberattackhigh

Cyberattack Disrupts Operations at Japanese Food Giant Nichirei

Nichirei, a major Japanese food company, has confirmed that a cyberattack on July 13th caused system outages, disrupting logistics and shipments. The company has established an emergency response team and is gradually restoring operations while withholding specific details to prevent further damage. The incident has impacted various businesses that rely on Nichirei's services, including restaurant chains and retailers.

botnethigh

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials

A newly identified botnet written in Go, dubbed NadMesh, is actively scanning for and exploiting exposed AI services. The botnet specifically targets cloud environments, seeking to steal AWS keys and Kubernetes tokens from vulnerable AI platforms. Researchers have observed it scanning for services like ComfyUI and Ollama, which are often deployed without adequate security measures.

ai

Blind Trust in AI Creates Cybersecurity Risks

Allowing AI models to both interpret and execute commands without human oversight introduces significant cybersecurity vulnerabilities. This lack of critical review can lead to unintended consequences and security breaches.

apthigh

Chinese APT Group Linked to DigiCert Breach and Code Signing Certificate Theft

Researchers have linked a Chinese cybercrime group, known as GoldenEyeDog and CylindricalCanine, to a security incident at DigiCert that resulted in the theft of code-signing certificates. This group has previously targeted the gambling and gaming industries.

phishing

Attackers Use Text Salting to Evade AI-Powered Spam Filters

Cybersecurity firm Barracuda reports that attackers are increasingly using a technique called 'text salting' to bypass AI-driven email filters. This method involves embedding harmless-looking words within malicious emails to confuse machine-learning and LLM-based security tools. Barracuda has observed over a million phishing attacks employing this tactic since April.

ai

Microsoft Discusses AI and Supply Chain Threats at Black Hat

Microsoft Security will present at Black Hat USA 2026 on how threat actors are targeting trusted systems, including software, services, and AI, to scale their attacks. The company will share insights into identifying these threats earlier and how threat intelligence, response, and security operations can collaborate across various systems. Sessions will cover the increasing ease of offensive capabilities and deep dives into hunting supply chain attacks within software ecosystems and developer workflows.

ransomwarehigh

Government Agencies Face Daily Ransomware Attacks, Study Warns

A recent study indicates that government agencies are frequently targeted by ransomware attacks. Attackers exploit the critical nature of public services, knowing that disruptions can be particularly damaging and may increase the likelihood of ransom payments.

data breach

Ernst & Young Reports Data Breach After Support System Hack

Ernst & Young has alerted its clients to a data breach resulting from a security incident involving a third-party support ticket system. The compromised system was utilized by the company's IT staff, leading to unauthorized access to sensitive information.

data breachhigh

23andMe Settles Data Breach Lawsuit for $18 Million

Genetic testing company 23andMe has reached an $18 million settlement with 42 state attorneys general following a significant data breach in 2023. The agreement includes mandates for the company to implement stricter data security measures to prevent future incidents.

espionage

Iran Tracks US Military Phones, macOS Malware, Data Breaches

Reports indicate Iran is tracking US military personnel's mobile phones, and new macOS malware dubbed CrashStealer has emerged. Additionally, vulnerabilities in OpenClaw AI agents, a ransomware attack on naval defense firm TKMS, and a data breach at Lidl are highlighted.

scattered spiderhigh

Two Scattered Spider members sentenced to 66 months for London transport cyberattack

Two individuals, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in prison in the UK for their roles in a cyberattack that disrupted Transport for London's operations. The pair were identified as leading members of the Scattered Spider hacking group. Authorities linked them to significant cryptocurrency transactions and numerous cyberattacks, including extortion of US organizations and an attack on the federal court system.

fraud

Cybercriminals Seek Clean Residential Proxies for Fraud

Fraudsters are finding that traditional residential proxies are becoming less effective for carding operations. To bypass advanced fraud detection systems, criminals are now combining these proxies with other identity information, such as browser fingerprints and device profiles.

phishinghigh

Phishing Emails Use Fake Font Files to Deliver Windows Malware

Threat actors are distributing malware through phishing emails that use specially crafted font files. These malicious files, when opened, can execute arbitrary code on a victim's Windows system, leading to malware infection. The emails often masquerade as legitimate business documents to trick recipients into opening the dangerous attachments.

malwarehigh

North Korean Hackers Use SVG Images to Hide Malware in Fake Coding Tests

North Korean threat actors, associated with the Contagious Interview campaign, are using steganography within SVG image files to hide malware. This technique is employed in a campaign that uses fake job postings and coding challenges to deliver malicious payloads, including credential and crypto wallet stealers.