Skip to content

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated 04 Sep 2026 18:42 UTC
Threat Intel Malwarebytes Labs

The hidden work of modernizing Malwarebytes

Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath. Runtimes, managed libraries…

↗ Open article
Trending News Cyber Security News

Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally

Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class of high-memory PCs capable of running large AI models directly on-device, marking a significant shift away from…

↗ Open article
Media Schneier on Security

Using a VM to Contain an AI Agent

It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software…

↗ Open article
News The Register Security

Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident

Breach Research

OpenAI’s agents were going rogue as early as May, according to a new report, making the Hugging Face incident far from the first where bots committed a breach. A report published Friday by a group of researchers claims…

↗ Open article
Trending News The Hacker News

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Phishing

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them…

↗ Open article
News The Hacker News

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as…

↗ Open article
Trending News The Hacker News

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Malware

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to…

↗ Open article
Trending News Cyber Security News

Hackers Use Popular Messaging Services to Control New Windows Backdoors

A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run…

↗ Open article
News Cyber Security News

NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots

NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record keystrokes, watch copied text, and capture victims’ screens, turning an account-stealing infection into…

↗ Open article
News Cyber Security News

Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails

Phishing

Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the security systems built to spot suspicious language. The campaign pushed finance-themed messages at massive…

↗ Open article
News Bleeping Computer

39 New Methods That Compromise Passkey Authentication

Research

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced…

↗ Open article
News Cyber Security News

Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks

Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials…

↗ Open article
Podcast Hak5

Hackers Found a Way Into Humanoid Robots | Threat Wire

Vuln Malware Research

What happens when a vulnerability doesn’t just spread between computers—but between humanoid robots? This week on ThreatWire, we break down how researchers turned flaws in Unitree robots into a Bluetooth-range worm…

↗ Open article
Trending News Cyber Security News

Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains

Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on…

↗ Open article
Threat Intel Malwarebytes Labs

X Money rollout linked to password-reset attacks

X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival…

↗ Open article
News Cyber Security News

Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws

Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed security issues affecting Plex…

↗ Open article
News Cyber Security News

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

Vuln

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on…

↗ Open article
News Cyber Security News

OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics

Research

Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public bulletin board, according to research published at collusion.wiki . The…

↗ Open article
Trending Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2026-85046 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of…

↗ Open article ↗ CVE feed
Trending Research Rapid7 Blog

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Malware

Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named…

↗ Open article
Trending News Cyber Security News

Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking

Phishing

Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an unauthenticated message pass a Direct Send safeguard while showing…

↗ Open article
Media Schneier on Security

Security Vulnerability in a Voting System

Vuln

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter…

↗ Open article
Threat Intel Kaspersky Securelist

Angry Birds: Toy Ghouls’ new toys

Privacy

Introduction We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers…

↗ Open article
Trending News CyberScoop

Why judgment is emerging as cybersecurity’s defining skill

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more…

↗ Open article
Trending Threat Intel Malwarebytes Labs

Free streaming boxes may be routing criminal traffic through your home

Privacy Research

“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain…

↗ Open article
Trending News The Hacker News

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

CVE-2026-14894 ↗ Vuln

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) …

↗ Open article ↗ CVE feed
News The Hacker News

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Vuln

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0…

↗ Open article
Trending News The Hacker News

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

CVE-2026-85046 ↗ Vuln

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8)…

↗ Open article ↗ CVE feed
News The Hacker News

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

Vuln Research

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had…

↗ Open article
Trending News The Register Security

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

CVE-2026-20274 ↗

Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 scores 9.8 on the…

↗ Open article ↗ CVE feed
Threat Intel Recorded Future Intelligence

Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization

Vuln

Today, Recorded Future is announcing Automated Signature Creation , a new capability in Attack Surface Intelligence (ASI) to combat the speed of AI-generated exploits. ASI continuously maps an organization’s external…

↗ Open article
Research Elastic Security Labs

Data access: the hidden cost of security vendor lock-in

Your security data is the most important asset in your SOC. Not the dashboards, not the detections, not the AI features on the roadmap slide. The data. And most vendors make you pay, wait, or license your way to getting…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.