Skip to content

Cybersecurity news & advisories

47 / 47 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated
News Krebs On Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

Ransom

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in…

↗ Open article
News CyberScoop

Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

Ransom

A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison , the Justice Department said Friday. Cameron John Wagenius…

↗ Open article
News Bleeping Computer

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Ransom Breach

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an…

↗ Open article
News 404 Media

AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory

We debated for a long time about whether to write about the following video, which comes from a murder trial in which a man named Caleb Flynn is accused of killing his wife. The crime is very serious, and very sad, and…

↗ Open article
News The Record

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

APT

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some…

↗ Open article
News The Record

Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings

Privacy

Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’…

↗ Open article
Trending News The Register Security

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script

Phishing

Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad…

↗ Open article
News The Register Security

ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'

Ransom Breach

ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve their reputation…

↗ Open article
Trending News Cyber Security News

OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services

Vuln

Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services. The vulnerabilities are…

↗ Open article
Trending News Cyber Security News

14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers

Vuln Research

A 14-year-old Linux kernel vulnerability can let a local attacker escalate to root privileges and, in a proof-of-concept environment, escape a Docker container to compromise the underlying host. The flaw in Linux’s…

↗ Open article
News CyberScoop

Supreme Court permits states to use SAVE database for citizenship checks

The U.S. Supreme Court ruled Friday that states may use the federal SAVE database to verify voter citizenship, reversing lower court decisions that found the database was inaccurate and would likely disenfranchise…

↗ Open article
Trending News The Register Security

Crooks use fake desktop apps to fool HR staff into giving them remote access

You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual…

↗ Open article
Trending News The Register Security

Bitget blames North Korea for $387.5M crypto wallet raid

The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s…

↗ Open article
News 404 Media

Behind the Blog: Did you notice?

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss some small changes, an AI song, and internet soup. JOSEPH: We’re…

↗ Open article
Threat Intel Microsoft Security Blog

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Ransom Breach APT

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our…

↗ Open article
Trending News 404 Media

Podcast: OpenAI Admits AI is Killing the Internet

We start this week with Jason’s story about OpenAI and Microsoft’s big admissions from court records that they are destroying the internet in all sorts of ways, and stealing intellectual property on an unprecedented…

↗ Open article
Threat Intel Malwarebytes Labs

LinkedIn adds new checks for fake profiles and work histories

LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off. The company is responding to an environment in…

↗ Open article
News The Register Security

Which copy of that file is the real one? Dinner, off the record, in Midtown

EVENT: The Register is hosting a private dinner in New York on Tuesday 27 October for senior technology, infrastructure and data leaders, with LucidLink. Joe Fay takes the chair, it runs under the Chatham House Rule…

↗ Open article
Trending Threat Intel Malwarebytes Labs

Kothamine malware uses Tailscale’s tailcat to evade network detection

Malware

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent . It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change…

↗ Open article
News Bleeping Computer

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps…

↗ Open article
Trending News The Hacker News

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Malware Breach

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected…

↗ Open article
Trending News Cyber Security News

Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems

Breach Crypto

Attackers broke into a Windows system through a known flaw in Samsung’s MagicINFO software, then built a cryptocurrency miner on the compromised machine. Rather than arriving as a finished program, the miner was…

↗ Open article
News Cyber Security News

Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers

Malware Breach Research

CARBONATO is a botnet that turns Docker servers into footholds for attackers. It places an AI agent inside compromised systems, letting operators send tasks through Telegram and receive results. The campaign begins with…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.