The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler ADC and NetScaler Gateway security flaw, tracked as…
Category: Cyber Security News
Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations
Two Western Australian men have been charged over alleged TeamPCP supply-chain attacks that police say planted malicious open-source code and reached more…
AWS Shows How Hackers Can Turn Stolen Cloud Credentials Into Full-Scale Attacks
Stolen cloud credentials can turn an incident into a wider breach. An attacker who gets a valid AWS key or session can enter as an approved user and move…
Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data
A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear…
Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks
TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially…
Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency
Hackers are increasingly turning AI platforms into a doorway to valuable corporate systems. New Microsoft research shows that exposed AI gateways,…
Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations
Aurora ransomware has been tied to a Russian-speaking affiliate that used an AI coding assistant while targeting more than 20 organisations. A wrongly…
OpenAI AI Agents Chain Zero-Days to Compromise Hugging Face and Internal Systems
OpenAI has disclosed a major AI safety incident in which internal research agents bypassed sandbox restrictions, gained internet access, and compromised…
Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account
Russian-linked operators are using fake cloud-storage pages and diplomatic themes to trick targets into giving away access to online accounts. The…
New Apache Log4j2 Flaw Lets Attackers Bypass Security Checks and Execute Remote Code
A newly disclosed Apache Log4j2 issue could allow attackers to bypass a deserialization allowlist and execute code remotely in narrowly defined…
Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs
Veeam has disclosed a critical security vulnerability in Veeam ONE 13 that could allow an unauthenticated remote attacker to coerce SMB authentication…
FBI Shuts Down China-Linked Hacking Platforms Used to Target NASA and U.S. Networks
The U.S. Department of Justice and FBI have seized domains associated with two China-linked hacking platforms, QScan and QTRouter, allegedly used to…
Nutex Health Data Breach – Hackers Gained Access to Network and Exfiltrated Data
Nutex Health has disclosed a cybersecurity incident involving unauthorized activity on its computer network, with preliminary findings indicating that an…
New Windows Backdoor Hides Inside ESET Agent and Wakes Up With a Secret Network Packet
SLEEPWALKER is a Windows backdoor built to stay quiet until an operator sends a specially crafted network packet. Rather than calling home to a fixed…
AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones
AnonyMousKIT is turning stolen iPhones into an entry point for account theft. The phishing-as-a-service platform targets people already searching for a…
WatchGuard Agent for Windows Vulnerability Allows Code Execution with Elevated Privileges
WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute…
Adobe Campaign Classic Vulnerabilities Enable Arbitrary Code Execution
Adobe has released a Priority 1 security update for Adobe Campaign Classic following the identification of three critical vulnerabilities that could allow…
CISA Warns of Gitea Code Injection Vulnerability Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency has added a newly disclosed Gitea vulnerability to its Known Exploited Vulnerabilities catalog,…
Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers
The Apache Software Foundation has patched a dozen security vulnerabilities in Apache Tomcat, the widely deployed open-source Java servlet container, with…
21 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege Escalation
Ubiquiti has patched 21 critical-severity vulnerabilities spanning nearly its entire UniFi product line, warning that attackers with only network access…