Skip to content

Cybersecurity news & advisories

46 / 46 active
Advisory
Threat Intel
Research
News
Media
Podcast
500 articles RSS ↗ Updated 05 Sep 2026 17:48 UTC
News The Hacker News

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

Vuln Breach

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to…

↗ Open article
Trending News The Hacker News

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The…

↗ Open article
News 404 Media

Breakthrough Quantum Test Resolves a Major Cosmic Mystery

Welcome back to the Abstract! Here are the studies this week that transcended realms, switched sexes, went south, and expanded their range. First, scientists break new ground in trying to get the universe to fit nicely…

↗ Open article
News The Hacker News

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Breach

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names…

↗ Open article
News Bleeping Computer

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment"…

↗ Open article
Media Wired Security

OpenAI Agents Hacked Another Website

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

↗ Open article
Trending News Cyber Security News

Microsoft Teams Desktop Client Fails to Load on Windows System – Microsoft Investigating

Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked…

↗ Open article
News The Hacker News

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

Research

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a…

↗ Open article
Trending News Cyber Security News

AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials

Breach

A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to…

↗ Open article
News The Hacker News

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Vuln Research

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed…

↗ Open article
Media Ars Technica Security

OpenAI agents discussed ways to escape their sandbox on public wiki

Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents’…

↗ Open article
News CyberScoop

European parliament members call for slowdown of Serbia’s EU entry over spyware use

Malware

A group of European Parliament representatives are seeking to delay Serbia’s entry into the European Union and send other messages to Belgrade over the government’s usage of spyware. The 29 members of the European…

↗ Open article
Trending News The Register Security

ASCII smuggling isn't just an AI security risk

Phishing

Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing. Microsoft uncovered a massive phishing campaign using…

↗ Open article
Threat Intel Microsoft Security Blog

How to secure edge AI in customer-owned environments

Edge AI moves model execution, model IP, customer data, and system authority into infrastructure the customer owns and operates. That changes who must verify the stack before sensitive assets are released. Edge AI…

↗ Open article
Trending Advisory Cisco Security Advisories

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…

↗ Open article
Threat Intel Malwarebytes Labs

The hidden work of modernizing Malwarebytes

Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath. Runtimes, managed libraries…

↗ Open article
Trending News Cyber Security News

Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally

Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class of high-memory PCs capable of running large AI models directly on-device, marking a significant shift away from…

↗ Open article
Media Schneier on Security

Using a VM to Contain an AI Agent

It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software…

↗ Open article
News The Register Security

Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident

Breach Research

OpenAI’s agents were going rogue as early as May, according to a new report, making the Hugging Face incident far from the first where bots committed a breach. A report published Friday by a group of researchers claims…

↗ Open article
Trending News The Hacker News

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Phishing

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them…

↗ Open article
News The Hacker News

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as…

↗ Open article
Trending News The Hacker News

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Malware

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to…

↗ Open article
Trending News Cyber Security News

Hackers Use Popular Messaging Services to Control New Windows Backdoors

A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run…

↗ Open article
News Cyber Security News

NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots

NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record keystrokes, watch copied text, and capture victims’ screens, turning an account-stealing infection into…

↗ Open article
News Cyber Security News

Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails

Phishing

Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the security systems built to spot suspicious language. The campaign pushed finance-themed messages at massive…

↗ Open article
News Bleeping Computer

39 New Methods That Compromise Passkey Authentication

Research

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced…

↗ Open article
News Cyber Security News

Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks

Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials…

↗ Open article
Podcast Hak5

Hackers Found a Way Into Humanoid Robots | Threat Wire

Vuln Malware Research

What happens when a vulnerability doesn’t just spread between computers—but between humanoid robots? This week on ThreatWire, we break down how researchers turned flaws in Unitree robots into a Bluetooth-range worm…

↗ Open article
Trending News Cyber Security News

Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains

Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on…

↗ Open article
Threat Intel Malwarebytes Labs

X Money rollout linked to password-reset attacks

X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival…

↗ Open article
News Cyber Security News

Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws

Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed security issues affecting Plex…

↗ Open article
News Cyber Security News

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

Vuln

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on…

↗ Open article
Trending Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2026-85046 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of…

↗ Open article ↗ CVE feed
Trending Research Rapid7 Blog

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Malware

Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.