Skip to content

Cybersecurity news & advisories

45 / 45 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated
News The Register Security

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a…

↗ Open article
Trending News Bleeping Computer

Reducing shadow IT visibility gaps with Wazuh

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and…

↗ Open article
News 404 Media

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

Breach

A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data…

↗ Open article
Trending News The Register Security

NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past

Vuln Research

Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri…

↗ Open article
News 404 Media

Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center

Last week, Meta executives announced that its much-hyped AI agent, Muse, had a new feature: It could call businesses for you to do things like make a restaurant reservation or a haircut appointment. But in reality, Meta…

↗ Open article
News The Register Security

Z.ai says sorry for slurping up your code, open sources ZCode

Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over which Elon Musk’s xAI…

↗ Open article
News Cyber Security News

Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards

A financially motivated operator has been running three open-source AI tools against many online retailers, mostly without supervision. The results are shocking: over 600,000 credit card records have been stolen…

↗ Open article
Trending News The Record

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

Breach

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached…

↗ Open article
Trending News Cyber Security News

CAIRN – A New Tool to Track AI Malware That Operates Without Human Control

Malware Research

Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research…

↗ Open article
News CyberScoop

Citing China, President Trump doubles down on hands-off approach to AI regulation

Policy

By Derek B. Johnson President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers…

↗ Open article
Threat Intel Malwarebytes Labs

Some cheap smart glasses are a security disaster

Privacy Research

Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all. ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested…

↗ Open article
Threat Intel Microsoft Security Blog

Unmasking EvilTokens: Getting to the root of device code phishing

Phishing

Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and…

↗ Open article
Trending News CyberScoop

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

Breach

Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email…

↗ Open article
Trending News The Register Security

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

Phishing

A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying…

↗ Open article
News The Register Security

Who signed off on that AI agent? Nobody? Thought so

If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that an autonomous swarm of OpenAI agents running in a sandbox broke…

↗ Open article
Research SANS Internet Storm Center

The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain…

↗ Open article
Podcast Darknet Diaries

LOW - Now Available

After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in…

↗ Open article
Trending News Cyber Security News

Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges

Vuln

Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user…

↗ Open article
Trending News Cyber Security News

New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords

Malware

TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code…

↗ Open article
Trending News Cyber Security News

Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access

CVE-2026-89775 ↗ Vuln

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested…

↗ Open article ↗ CVE feed
Research SANS Internet Storm Center

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

Malware

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached…

↗ Open article
News 404 Media

People Training OpenAI’s AI Fired for Using AI to Train the AI

OpenAI has an army of contractors who read real ChatGPT users’ prompts and other data to help improve the chatbot’s responses. The idea is that the contractors provide an, obviously, human touch to OpenAI’s models…

↗ Open article
Trending News Cyber Security News

Veeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows

CVE-2026-32996 ↗ Vuln Research

A critical local privilege escalation flaw in Veeam Agent for Microsoft Windows is drawing attention after public proof-of-concept exploit code became available. The vulnerability, tracked as CVE-2026-32996 , could let…

↗ Open article ↗ CVE feed
News Cyber Security News

Red Hat OpenShift Flaw Lets Attackers Bypass PGP Checks and Push Malicious Releases

Vuln

Red Hat has disclosed an Important security vulnerability in the OpenShift oc-mirror tool that could allow attackers to bypass PGP signature verification and introduce malicious release images into disconnected…

↗ Open article
Trending News The Hacker News

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A…

↗ Open article
Trending News Cyber Security News

BambooToken Linux Backdoor Uses MQTT C2 to Execute Shell Commands and Exfiltrate Files

Malware

BambooToken is a Linux backdoor that turns a lightweight messaging protocol into a remote control channel. The newly analysed sample can collect information about a host, run shell commands, and move files between a…

↗ Open article
News The Hacker News

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

CVE-2026-93952 ↗ Vuln

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may…

↗ Open article ↗ CVE feed
Trending Advisory CISA Alerts & Advisories

Siemens Industrial Edge Management

Vuln

View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without…

↗ Open article
Advisory CISA Alerts & Advisories

OpenPLC Runtime v3

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the…

↗ Open article
Advisory CISA Alerts & Advisories

lwIP (Lightweight IP)

Vuln

View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP…

↗ Open article
Trending Advisory CISA Alerts & Advisories

Siemens WTV676 and WTV776

Vuln DoS

View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity…

↗ Open article
Trending Advisory CISA Alerts & Advisories

Siemens SIPLUS and SIMATIC Products

Vuln

View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is…

↗ Open article
Advisory CISA Alerts & Advisories

Siemens Desigo CC family

Vuln

View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics…

↗ Open article
Advisory CISA Alerts & Advisories

Siemens SIMOVE Fleetmanager and SIPLANT

Vuln

View CSAF Summary SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected…

↗ Open article
Advisory CISA Alerts & Advisories

Siemens Siveillance Control

Vuln

View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability…

↗ Open article
Trending Advisory CISA Alerts & Advisories

lwIP TCP/IP Stack MQTT Client Application

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: MQTT…

↗ Open article
Advisory CISA ICS Advisories

OpenPLC Runtime v3

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the…

↗ Open article
Trending Advisory CISA ICS Advisories

Siemens WTV676 and WTV776

Vuln DoS

View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity…

↗ Open article
Trending Advisory CISA ICS Advisories

Siemens SIMOVE Fleetmanager and SIPLANT

Vuln

View CSAF Summary SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected…

↗ Open article
Trending Advisory CISA ICS Advisories

Siemens Industrial Edge Management

Vuln

View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without…

↗ Open article
Advisory CISA ICS Advisories

Siemens Desigo CC family

Vuln

View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics…

↗ Open article
Advisory CISA ICS Advisories

Siemens SIPLUS and SIMATIC Products

Vuln

View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is…

↗ Open article
Advisory CISA ICS Advisories

Siemens Siveillance Control

Vuln

View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability…

↗ Open article
Advisory CISA ICS Advisories

lwIP (Lightweight IP)

Vuln

View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP…

↗ Open article
Trending Advisory CISA ICS Advisories

lwIP TCP/IP Stack MQTT Client Application

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: MQTT…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.