Skip to content

Cybersecurity news & advisories

46 / 46 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated
Trending News The Register Security

Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions

Malware

A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’…

↗ Open article
News CyberScoop

After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

Policy

A House Democrat tapped to lead his party’s efforts on artificial intelligence has introduced legislation that would establish a test program within the Cybersecurity and Infrastructure Security Agency to give critical…

↗ Open article
Research SANS Internet Storm Center

The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain…

↗ Open article
Trending News CyberScoop

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

Vuln Research

Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday. The threat group it…

↗ Open article
Trending News The Hacker News

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

CVE-2026-93616 ↗ Vuln

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the…

↗ Open article ↗ CVE feed
Trending News The Hacker News

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

Vuln

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to…

↗ Open article
News The Hacker News

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Research

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily…

↗ Open article
News The Register Security

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a…

↗ Open article
Trending News Bleeping Computer

Reducing shadow IT visibility gaps with Wazuh

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and…

↗ Open article
Trending News Cyber Security News

Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks

CVE-2026-93616 ↗ Vuln

Check Point has warned customers that attackers are exploiting a critical zero-day vulnerability in its Security Management infrastructure. Tracked as CVE-2026-93616 , the flaw carries a CVSS score of 9.8 and enables an…

↗ Open article ↗ CVE feed
Trending News The Hacker News

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Phishing

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization…

↗ Open article
News Cyber Security News

Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents

Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit , the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced…

↗ Open article
News 404 Media

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

Breach

A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data…

↗ Open article
News Cyber Security News

Scaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout

A suspicious IP, unfamiliar domain, or file hash can trigger an investigation in seconds. Understanding what that indicator means can take much longer. An IOC rarely tells the full story. Analysts may need to determine…

↗ Open article
News The Hacker News

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Vuln

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP…

↗ Open article
Trending News The Register Security

NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past

Vuln Research

Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri…

↗ Open article
News 404 Media

Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center

Last week, Meta executives announced that its much-hyped AI agent, Muse, had a new feature: It could call businesses for you to do things like make a restaurant reservation or a haircut appointment. But in reality, Meta…

↗ Open article
Trending News The Hacker News

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

Vuln Research

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster…

↗ Open article
News The Register Security

Z.ai says sorry for slurping up your code, open sources ZCode

Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over which Elon Musk’s xAI…

↗ Open article
News Cyber Security News

Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards

A financially motivated operator has been running three open-source AI tools against many online retailers, mostly without supervision. The results are shocking: over 600,000 credit card records have been stolen…

↗ Open article
Trending News The Record

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

Breach

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached…

↗ Open article
Trending News Cyber Security News

CAIRN – A New Tool to Track AI Malware That Operates Without Human Control

Malware Research

Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research…

↗ Open article
News CyberScoop

Citing China, President Trump doubles down on hands-off approach to AI regulation

Policy

President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry…

↗ Open article
Threat Intel Malwarebytes Labs

Some cheap smart glasses are a security disaster

Privacy Research

Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all. ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested…

↗ Open article
Threat Intel Microsoft Security Blog

Unmasking EvilTokens: Getting to the root of device code phishing

Phishing

Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and…

↗ Open article
Trending News CyberScoop

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

Breach

Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email…

↗ Open article
Trending News The Register Security

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

Phishing

A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying…

↗ Open article
News The Register Security

Who signed off on that AI agent? Nobody? Thought so

If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that an autonomous swarm of OpenAI agents running in a sandbox broke…

↗ Open article
Podcast Darknet Diaries

LOW - Now Available

After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in…

↗ Open article
Trending News Cyber Security News

Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges

Vuln

Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user…

↗ Open article
Trending News Cyber Security News

New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords

Malware

TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code…

↗ Open article
Trending News Cyber Security News

Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access

CVE-2026-89775 ↗ Vuln

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested…

↗ Open article ↗ CVE feed
No articles found
Try adjusting your search, category, tags, source selection, or date range.