Skip to content

Cybersecurity news & advisories

48 / 48 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated
Trending News Cyber Security News

Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attack

Vuln

Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming that attackers are exploiting two critical remote code execution vulnerabilities against unmitigated appliances…

↗ Open article
Trending News Cyber Security News

New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory

Research

A Windows process injection method disclosed by security researcher Two Seven One Three sidesteps two APIs closely associated with remote code injection: VirtualAllocEx and WriteProcessMemory . Dubbed console named-pipe…

↗ Open article
Trending Research Tenable Blog

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Vuln

There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time. Key takeaways…

↗ Open article
Trending News The Hacker News

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Vuln

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six…

↗ Open article
Trending News Cyber Security News

Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks

Vuln

Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world attacks. watchTowr said the flaws are unpatched zero-days, were…

↗ Open article
News 404 Media

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It

Welcome back to the Abstract! Here are the studies this week that sailed alien seas, beat the heat, went retro, and got caught in the food web. First, scientists make the case that Saturn’s moon Enceladus could resolve…

↗ Open article
News Bleeping Computer

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

CVE-2026-35273 ↗ Ransom

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread…

↗ Open article ↗ CVE feed
Trending News The Hacker News

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Malware Breach

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings…

↗ Open article
Trending News Cyber Security News

Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection

A locally hosted, uncensored artificial intelligence model modified a Windows credential-dumping utility until it evaded two Endpoint Detection and Response (EDR) products in a controlled lab, highlighting how…

↗ Open article
Trending News Cyber Security News

F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery

F-Droid has released version 2.0 of its official Android app, delivering its largest client update in a decade. The open-source Android app repository said the release follows more than a year of development and 14 test…

↗ Open article
Trending News The Hacker News

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Vuln

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the…

↗ Open article
News The Hacker News

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much…

↗ Open article
Trending News The Hacker News

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Vuln

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control…

↗ Open article
Trending News The Hacker News

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing…

↗ Open article
News The Hacker News

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks…

↗ Open article
News Cyber Security News

OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted

Research

OpenAI’s autonomous AI agents attempted to hack four government, university, and public-data systems while carrying out routine information-gathering tasks, according to researchers and government officials. The agents…

↗ Open article
Trending News Cyber Security News

16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records

Vuln Research

A 16-year-old security researcher known as Faav uncovered an authentication flaw in Microsoft’s internal Titan analytics service that potentially exposed an estimated 17.3 trillion database rows. The vulnerability…

↗ Open article
News Krebs On Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

Ransom

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in…

↗ Open article
News CyberScoop

Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

Ransom

A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison , the Justice Department said Friday. Cameron John Wagenius…

↗ Open article
News Bleeping Computer

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Ransom Breach

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an…

↗ Open article
News 404 Media

AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory

We debated for a long time about whether to write about the following video, which comes from a murder trial in which a man named Caleb Flynn is accused of killing his wife. The crime is very serious, and very sad, and…

↗ Open article
News The Record

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

APT

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some…

↗ Open article
News The Record

Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings

Privacy

Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’…

↗ Open article
Trending News The Register Security

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script

Phishing

Yes, criminals have job listings too. A Telegram user recruiting callers to work in an apparent Google Security Team voice-phishing scam told applicants that they weren’t allowed to read from scripts – in the same ad…

↗ Open article
News The Register Security

ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'

Ransom Breach

ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve their reputation…

↗ Open article
Trending News Cyber Security News

OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services

Vuln

Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services. The vulnerabilities are…

↗ Open article
News Cyber Security News

14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers

Vuln Research

A 14-year-old Linux kernel vulnerability can let a local attacker escalate to root privileges and, in a proof-of-concept environment, escape a Docker container to compromise the underlying host. The flaw in Linux’s…

↗ Open article
News CyberScoop

Supreme Court permits states to use SAVE database for citizenship checks

The U.S. Supreme Court ruled Friday that states may use the federal SAVE database to verify voter citizenship, reversing lower court decisions that found the database was inaccurate and would likely disenfranchise…

↗ Open article
Trending News The Register Security

Crooks use fake desktop apps to fool HR staff into giving them remote access

You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual…

↗ Open article
Trending News The Register Security

Bitget blames North Korea for $387.5M crypto wallet raid

The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s…

↗ Open article
News 404 Media

Behind the Blog: Did you notice?

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss some small changes, an AI song, and internet soup. JOSEPH: We’re…

↗ Open article
Threat Intel Microsoft Security Blog

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Ransom Breach APT

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our…

↗ Open article
Trending News 404 Media

Podcast: OpenAI Admits AI is Killing the Internet

We start this week with Jason’s story about OpenAI and Microsoft’s big admissions from court records that they are destroying the internet in all sorts of ways, and stealing intellectual property on an unprecedented…

↗ Open article
Threat Intel Malwarebytes Labs

LinkedIn adds new checks for fake profiles and work histories

LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off. The company is responding to an environment in…

↗ Open article
News The Register Security

Which copy of that file is the real one? Dinner, off the record, in Midtown

EVENT: The Register is hosting a private dinner in New York on Tuesday 27 October for senior technology, infrastructure and data leaders, with LucidLink. Joe Fay takes the chair, it runs under the Chatham House Rule…

↗ Open article
Trending Threat Intel Malwarebytes Labs

Kothamine malware uses Tailscale’s tailcat to evade network detection

Malware

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent . It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.