Skip to content

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated 10 Sep 2026 18:49 UTC
Trending News The Hacker News

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Phishing

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old…

↗ Open article
Threat Intel Microsoft Security Blog

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive…

↗ Open article
News Cyber Security News

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture platform now commercially available and continuing to add new capabilities, OpenMatter Network today announced a strategic…

↗ Open article
Threat Intel Microsoft Security Blog

Detect and disrupt AI-themed attacks with Microsoft Defender

Research

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular…

↗ Open article
Trending Threat Intel Malwarebytes Labs

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Vuln

BlueMoon , a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch…

↗ Open article
Trending News The Hacker News

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the…

↗ Open article
Threat Intel Check Point Research

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

Research

Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload…

↗ Open article
News Cyber Security News

Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware

Vuln Malware

Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early…

↗ Open article
News Cyber Security News

WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had…

↗ Open article
Trending News Cyber Security News

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

Phishing

A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving…

↗ Open article
News Bleeping Computer

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some…

↗ Open article
News CyberScoop

Governments ‘buying time’ in race between innovation, security, national cyber director says

The United States and allied governments are “buying time for our systems to become more secure” as artificial intelligence advances and spreads, National Cyber Director Sean Cairncross said Thursday. “That is a big…

↗ Open article
Advisory Cisco Security Advisories

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…

↗ Open article
Trending News Cyber Security News

Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware

Vuln Ransom Malware

Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with state-sponsored hacking groups and a ransomware affiliate leveraging the flaws…

↗ Open article
News Graham Cluley

‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

Crypto

Here's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow…

↗ Open article
News The Record

Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers

DoS

Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to…

↗ Open article
Trending News Cyber Security News

CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

CVE-2026-19490 ↗ Vuln

CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must…

↗ Open article ↗ CVE feed
Trending News Cyber Security News

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Phishing

Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign starts with calls and texts to employees. Attackers pose as IT…

↗ Open article
News The Register Security

ShinyHunters expose 6.4M in attack on medical supplier McKesson

Ransom Breach

McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the…

↗ Open article
Research Tenable Blog

The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails

Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment Key takeaways AI models can quickly…

↗ Open article
News Cyber Security News

Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models

Vuln

Enterprise AI workflows can be vulnerable to misuse that exposes sensitive information without prompt injection, account compromise, or jailbreaking a large language model. This vulnerability, termed Workflow Identity…

↗ Open article
Trending News Cyber Security News

Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

CVE-2026-85102 ↗ CVE-2026-85103 ↗ Vuln

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote…

↗ Open article ↗ CVE feed
News Cyber Security News

LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials

LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run code as root inside a container, reach connected tools, and…

↗ Open article
Threat Intel Malwarebytes Labs

Will AI kill us all within the next decade?

The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control. Jacob Coxon, an AI…

↗ Open article
Advisory CISA Alerts & Advisories

Orthanc DICOM Server

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image…

↗ Open article
Advisory CISA Alerts & Advisories

NextGen Healthcare Mirth Connect

Vuln DoS

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are…

↗ Open article
Trending Advisory CISA Alerts & Advisories

ST Engineering iDirect iQ-Series Terminals (Update A)

Vuln DoS

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST…

↗ Open article
Advisory CISA Alerts & Advisories

AVEVA Pipeline Integrity Monitor

Vuln

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA…

↗ Open article
Advisory CISA ICS Advisories

AVEVA Pipeline Integrity Monitor

Vuln

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA…

↗ Open article
Trending Advisory CISA ICS Advisories

ST Engineering iDirect iQ-Series Terminals (Update A)

Vuln DoS

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST…

↗ Open article
Trending News The Hacker News

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Vuln

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only…

↗ Open article
News The Hacker News

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

Vuln

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds…

↗ Open article
Trending News The Hacker News

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Malware

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9…

↗ Open article
Trending Threat Intel Malwarebytes Labs

Update Chrome now to protect against an actively exploited vulnerability

Vuln

Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited . The stable channel has been updated to 153.0.8010.36/.37 for Windows and…

↗ Open article
Media Schneier on Security

AIs Compress Exploit Timeline

Vuln

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been…

↗ Open article
Trending News The Hacker News

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.