Skip to content

Cybersecurity news & advisories

41 / 41 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated
Threat Intel Malwarebytes Labs

Fake parcel delivery messages steal your card and bank details

Phishing

Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be…

↗ Open article
Trending News The Hacker News

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Malware Research

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control…

↗ Open article
News Cyber Security News

Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories

Vuln Research

Researchers used Anthropic’s Claude Opus 5 to help weaponize an image-decoder vulnerability, compromise OpenAI’s community forum, take over employees’ ChatGPT and Codex accounts, and reach an internal source-code…

↗ Open article
Trending News Cyber Security News

Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges

Vuln

A newly disclosed Windows zero-day affecting the Steam Client Service can reportedly let a standard local user obtain NT AUTHORITY\SYSTEM privileges without administrator credentials, a User Account Control prompt…

↗ Open article
News The Register Security

USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech

Privacy

Think tank the Australian Strategic Policy Institute (ASPI) has warned that Venezuela is poised to adopt Chinese AI systems to enhance surveillance systems that already rely on Middle Kingdom tech, and called for US…

↗ Open article
Trending News The Register Security

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

Vuln

A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents - Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub…

↗ Open article
Trending News 404 Media

‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft

Executives working on AI at Microsoft and OpenAI admitted what its critics have been saying all along: Large language models are predatory pieces of technology that have been built on what a Microsoft executive called…

↗ Open article
Advisory Cisco Security Advisories

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…

↗ Open article
Trending News CyberScoop

Cisco alerts customers to second actively exploited zero-day in as many days

CVE-2026-76460 ↗ Vuln

Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a…

↗ Open article ↗ CVE feed
News The Register Security

Researchers find way to listen in on headphones from afar

Research

Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and smart devices by injecting electromagnetic (EM) signals. The…

↗ Open article
News CyberScoop

The AI hacking apocalypse is not inevitable

The past few weeks have “felt very strange” for Juan Andres Guerrero-Saade. Like many, he is trying to sort through the spate of frontier-model AI agents from OpenAI , Anthropic , Meta and others hacking their way onto…

↗ Open article
Threat Intel Malwarebytes Labs

Flock cameras are tracking people as well as cars

Privacy

Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED , based on data recovered from a physically…

↗ Open article
Trending News The Hacker News

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Vuln

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is…

↗ Open article
News 404 Media

‘Flock City PD:’ The Fake Flock-Owned ‘Police Department’ That Searched Real Cameras for Real People

Privacy

Flock created a fake police department called “Flock City PD” that it used to search a series of live automated license plate readers in several U.S. cities during demonstrations of its surveillance system’s…

↗ Open article
Threat Intel Cisco Talos

Should you care about an “AI slowdown?”

Welcome to this week’s edition of the Threat Source newsletter. There’s been a lot of talk recently about slowing down the pace of AI development . And yes, there are legitimate moral, ethical, geopolitical, and safety…

↗ Open article
News The Register Security

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Malware

China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to…

↗ Open article
News The Hacker News

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Vuln

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly…

↗ Open article
Threat Intel Microsoft Security Blog

From guidance to action: Security fundamentals that materially reduce risk

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and…

↗ Open article
News Cyber Security News

OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permission

OpenAI has disclosed six cases in which AI models concealed errors, used an exposed API key, uploaded data to public services, and communicated through unauthorized channels. The incidents, observed during…

↗ Open article
Advisory Cisco Security Advisories

Cisco Secure Email Gateway SQL Injection Vulnerability

Vuln

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying…

↗ Open article
Threat Intel Microsoft Security Blog

Improving email security outcomes with real-world Microsoft Defender insights

Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into…

↗ Open article
News Cyber Security News

FBI Takes Down NightmareStresser DDoS Service Used in Hundreds of Thousands of Attacks

DoS

The FBI has seized domains supporting NightmareStresser, disrupting one of the world’s longest-running DDoS-for-hire operations . The court-authorized action targets a service that allegedly enabled paying customers to…

↗ Open article
Trending Podcast Hak5

A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire

Vuln Malware Research

What if a phone call could spread a zero-click worm without you answering, tapping a link, or doing anything at all? Security researchers built WeWorm, a proof-of-concept that exploited WeChat calls on iOS and Android…

↗ Open article
Trending News The Hacker News

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on…

↗ Open article
Trending News 404 Media

University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It

Georgia State University has rescinded a job offer given to a high profile activist who is currently fighting a case in which he allegedly wiped a security-focused Android phone before Customs and Border Protection…

↗ Open article
News The Register Security

London property manager breach may have exposed bank details and lockbox codes

Breach

London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance. City Relay…

↗ Open article
Research SANS Internet Storm Center

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

Malware

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached…

↗ Open article
News 404 Media

Contest to Open for Ed Sheeran Flooded With Free Palestine Videos and Fart Memes

After Ed Sheeran dropped Macklemore from his tour over the singer’s support for Palestine, people flooded an online contest to open for Sheeran’s Mexico City show with fart videos, bouncing WWE butts, and troll posts…

↗ Open article
News Cyber Security News

BIND DNS Servers Hit by 14 Security Flaws Enabling Cache Poisoning and Remote Crashes

Vuln

Internet Systems Consortium has released security updates for BIND 9 after identifying 14 vulnerabilities that could allow attackers to poison DNS caches, crash exposed servers remotely , exhaust resources, or bypass…

↗ Open article
News Graham Cluley

US Coast Guard and FBI board oil tanker to investigate cyber attack

Breach

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. According to the US Coast Guard, the supertanker was…

↗ Open article
Threat Intel Check Point Research

AI Threat Landscape Digest: July–August 2026

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI…

↗ Open article
News Cyber Security News

CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers

CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency published its new guidance, Using Cyber…

↗ Open article
Threat Intel Malwarebytes Labs

Revolut phishing texts appear days after data breach

Phishing Breach

Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to…

↗ Open article
News The Hacker News

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

Malware Privacy

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin…

↗ Open article
News Bleeping Computer

What Recent AI-Powered Attacks Mean for Your Identity Security

AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.