TheHackerNews
·
9h ago
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vul…
SecurityWeek
·
1d ago
Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exp…
TheHackerNews
·
2d ago
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the…
TheHackerNews
·
5d ago
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on…
Recorded Future
·
14w ago
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day January 2026 saw 23 actively exploited CVEs, including APT28’s Microsoft Office zero-day and critical au…
TheHackerNews
·
3d ago
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including o…
Recorded Future
·
7w ago
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day March 2026 saw a 139% increase in high-impact vulnerabilities, with Recorded Future's Insikt Gr…
TheHackerNews
·
1d ago
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from ther…
TheHackerNews
·
7d ago
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come unde…
CISA
·
2w ago
CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form
TheHackerNews
·
3d ago
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attack…
Dark Reading
·
2w ago
Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Ransomware and vendor breaches persist. The "2026 Data Breach Investigations Report" (DBIR) highlights how evolving social engineering tactics make…
Recorded Future
·
7w ago
Your Supply Chain Breach Is Someone Else's Payday A supply chain attack by TeamPCP compromised trusted software tools to harvest credentials at scale, enabling payroll fraud, logistics theft, and ransomware extortion.
TheHackerNews
·
1d ago
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active install…
SentinelOne
·
6w ago
Hypersonic Supply Chain Attacks: One Solution That Didn’t Need to Know the Payload Learn how SentinelOne has stopped three recent zero-day supply chain attacks with AI-driven defense built for machine-speed threats.
Dark Reading
·
4d ago
Microsoft's Zero-Day Legal Threats Spark Backlash After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order.
JPCERT
·
5w ago
注意喚起: Cisco ASAおよびFTDにおける複数の脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起 (更新)
JPCERT
·
2w ago
注意喚起: Palo Alto Networks製PAN-OSにおける認証回避の脆弱性(CVE-2026-0265)に関する注意喚起 (公開)
CoinTelegraph
·
1d ago
ZEC drops 30% as Shielded Labs reveals more about infinite counterfeit bug ZEC market capitalization fell by almost $3 billion over the past 24 hours following the disclosure of a critical vulnerability, despite it bein…
NIST
·
40w ago
NIST Revises Security and Privacy Control Catalog to Improve Software Update and Patch Releases The catalog revision is part of NIST’s response to a recent executive order on strengthening the nation’s cybersecurity.
Decrypt
·
1d ago
ZEC Crashes 38% as Zcash Discloses ‘Critical Counterfeiting Vulnerability’ An Orchard vulnerability that allowed undetectable counterfeiting of ZEC in its shielded pool has reignited debate over privacy coins.
Dark Reading
·
1d ago
4 Critical Threats Where Attackers Have the Advantage Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.
CISA
·
6w ago
CISA Warns of FIRESTARTER Malware Targeting Cisco ASA including Firepower and Secure Firewall Products
CISA
·
14w ago
CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat
TheHackerNews
·
1d ago
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days befor…
TheHackerNews
·
2d ago
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspec…
TheHackerNews
·
3d ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gainin…
SecurityWeek
·
1d ago
Hackers Leak DentaQuest Information Impacting 2.6 Million The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Informat…
SecurityWeek
·
1d ago
Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI S…
Dark Reading
·
4d ago
Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense Twenty years after Dark Reading launched, we're looking ahead at what's next for enterprise security. Spoiler: It's hyper-segmented, AI-orches…
Dark Reading
·
8d ago
With Complex Cloud Integrations, Small Errors Lead to Major Compromises Researchers discover an exploit chain combining over-permissioned roles, secrets discovery, and non-human identities that could have compromised a…
KrebsOnSecurity
·
4w ago
Canvas Breach Disrupts Schools & Colleges Nationwide An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities…
TheHackerNews
·
2d ago
DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and pri…
Dark Reading
·
10d ago
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos In just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer…
Kaspersky Securelist
·
2w ago
IT threat evolution in Q1 2026. Non-mobile statistics The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as Internet of Things (IoT) devices, dur…
Dark Reading
·
9d ago
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced remote access Trojan is propagating online. Notably, it's delivered via an operator licensing model and features a no-code malware-development interface.
Recorded Future
·
12w ago
Digital Citizenship Glossary: Key Terms Every Internet User Should Know A glossary of key internet terms every user should know to protect themselves from scams, phishing, malware, and other digital threats.
Dark Reading
·
9d ago
Ransomware Actors Show Up In Person to Steal Law Firm Data The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and social-engineering its way into servers and databases.
Recorded Future
·
5w ago
Lazarus Doesn't Need AGI Explore the 2026 Claude Mythos breach, supply chain risks, and the $2B+ crypto theft pipeline.
Dark Reading
·
2d ago
Attackers Use AI to Automate EDR Evasion Testing Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
Recorded Future
·
4w ago
Threat Activity Enablers: The Backbone of Today’s Threat Landscape Behind every ransomware demand, botnet, or threat activity group is a server sitting in a data center.
Dark Reading
·
4d ago
Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit Exploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-M…
Apple Developer
·
10w ago
Update on regulated medical device apps in the European Economic Area, United Kingdom, and United States To provide additional transparency to customers, the App Store will now display whether an app is a regulated medi…
Apple Developer
·
85w ago
Apple Push Notification service server certificate update The Certification Authority (CA) for Apple Push Notification service (APNs) is changing. APNs will update the server certificates in sandbox on January 20, 2025,…
EFF
·
3w ago
Victory! End-to-End Encrypted RCS Comes to Apple and Android Chats This week, Apple released iOS 26.5 , an update that supports end-to-end encryption for Rich Communication Services (RCS), meaning conversations between…
Recorded Future
·
3w ago
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals NVD enrichment now covers only 15–20% of CVEs. Learn how Recorded Future Vulnerability Intelligence prioritizes risk using r…
NIST
·
41w ago
NIST Guidelines Can Help Organizations Detect Face Photo Morphs, Deter Identity Fraud Face morphing software, which combines photos of different people into a single image, is being used to commit identity fraud.
NIST
·
24w ago
Draft NIST Guidelines Rethink Cybersecurity for the AI Era New guidelines can help an organization determine ways to incorporate AI into its operations while mitigating cybersecurity risks.
NIST
·
37w ago
NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States There are currently more than 514,000 cybersecurity job openings in the U.S.
NIST
·
24w ago
Securing Smart Speakers for Home Health Care: NIST Offers New Guidelines Cybersecurity and privacy risks can threaten patient confidentiality.
Cloudflare Blog
·
1d ago
Your AI bill is out of control. Cloudflare can fix it now.
TheHackerNews
·
19h ago
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate…
TheHackerNews
·
23h ago
Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybe…
TheHackerNews
·
1d ago
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") t…
TheHackerNews
·
2d ago
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., G…
TheHackerNews
·
2d ago
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called…
TheHackerNews
·
3d ago
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apa…
TheHackerNews
·
4d ago
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targetin…
TheHackerNews
·
4d ago
Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults d…
TheHackerNews
·
5d ago
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing al…