Cybersecurity

179 stories from 26 sources

Recorded Future · 13w ago

Your Supply Chain Breach Is Someone Else's Payday

Your Supply Chain Breach Is Someone Else's Payday A supply chain attack by TeamPCP compromised trusted software tools to harvest credentials at scale, enabling payroll fraud, logistics theft, and ransomware extortion.

impact 42
Dark Reading · 19h ago

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the lar…

impact 41
SecurityWeek · 5h ago

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact F…

impact 38
Dark Reading · 11d ago

Microsoft Reins in RoguePlanet Zero-Day Threat

Microsoft Reins in RoguePlanet Zero-Day Threat The researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Mic…

impact 38
KrebsOnSecurity · 13d ago

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Felons, Fraudsters Flog Offensive Cybersecurity Startup A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theo…

impact 38
Dark Reading · 7d ago

Cursor IDE Auto-Executes Malicious Code in Poisoned Repos

Cursor IDE Auto-Executes Malicious Code in Poisoned Repos Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository…

impact 38
Access Now · 6d ago

Not AI for Good

Not AI for Good Session description: This civil society-led counter-event to the AI for Good Global Summit takes a critical look at the overhyped role of AI in solving humanity’s long-standing problems, and at The post…

impact 34
SecurityWeek · 7h ago

Clover Health Investments Discloses Data Breach

Clover Health Investments Discloses Data Breach Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach ap…

impact 30
Schneier on Security · 10d ago

Friday Squid Blogging: “Squidbleed” Vulnerability

Friday Squid Blogging: “Squidbleed” Vulnerability In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the…

impact 30
Dark Reading · 5d ago

Identity Attacks Overtake Exploits as Top Ransomware Cause

Identity Attacks Overtake Exploits as Top Ransomware Cause Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but…

impact 28
KrebsOnSecurity · 5w ago

Who Runs the Ransomware Group ‘The Gentlemen?’

Who Runs the Ransomware Group ‘The Gentlemen?’ A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an ag…

impact 28
Dark Reading · just now

Ransomware Is Accelerating, But It's Not Because of AI

Ransomware Is Accelerating, But It's Not Because of AI Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.

impact 28
Dark Reading · 13d ago

Vidar Infostealer Hammers SMBs via Malvertising Campaign

Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation uses lures of cracked or pirated software to deliver a two-for-one malware combo for data theft and cryptomining.

impact 28
Recorded Future · 12w ago

Lazarus Doesn't Need AGI

Lazarus Doesn't Need AGI Explore the 2026 Claude Mythos breach, supply chain risks, and the $2B+ crypto theft pipeline.

impact 27
Dark Reading · 3d ago

Inc Ransomware Exploits SonicWall SMA Zero-Days

Inc Ransomware Exploits SonicWall SMA Zero-Days When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.

impact 27
KrebsOnSecurity · 5w ago

A Record-Breaking Patch Tuesday for June 2026

A Record-Breaking Patch Tuesday for June 2026 Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the com…

impact 26
Apple Developer · 91w ago

Apple Push Notification service server certificate update

Apple Push Notification service server certificate update The Certification Authority (CA) for Apple Push Notification service (APNs) is changing. APNs will update the server certificates in sandbox on January 20, 2025,…

impact 26
arXiv Security · 13h ago

DSA Nonce Vulnerabilities: An Interactive Analysis

DSA Nonce Vulnerabilities: An Interactive Analysis arXiv:2607.17107v1 Announce Type: new Abstract: Digital signatures are fundamental to identity authentication and data integrity in cybersecurity, and the NIST-standard…

impact 24
DeepMind · 4d ago

Introducing Gemini 3.5 Flash Cyber

Introducing Gemini 3.5 Flash Cyber Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.

impact 24

All Categories