A third-party logistics breach has put thousands of Trezor hardware wallet buyers at higher phishing risk, even though Trezor’s own systems and devices…
Category: Cyber Security News
Hackers Actively Exploiting Microsoft SharePoint Vulnerability Following PoC Release
Threat actors have wasted no time weaponizing a newly disclosed Microsoft SharePoint authentication bypass, launching real-world attacks against…
1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity
Cloudflare has reported a sharp rise in large-scale distributed denial-of-service attacks during the first half of 2026, blocking 935 network-layer…
Gunra Uses Stolen Sessions and RDP to Pivot Into Active Directory and IT Workstations
Gunra ransomware has moved from a new name to a serious enterprise threat in a short time. The group breaks into exposed edge devices, steals valuable…
Thousand of Internet-Exposed Contollers Could Put Data center Cooling and Power at Risk
Thousands of internet-exposed building controllers may be putting the physical backbone of U.S. data centers at risk. They manage cooling, electrical…
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD…
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog,…
Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails. The messages can look ordinary because they come from…
Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser…
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia. Once opened, the fake…
Wireshark 4.6.8 Released With Patch for 28 Vulnerabilities That Lead to Crashes
The Wireshark Foundation has officially rolled out Wireshark 4.6.8, a security update that patches 28 distinct vulnerabilities capable of triggering…
Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data
SpecterOps has released Blacklight, an open-source toolkit that identifies local artifacts from AI coding agents like Codex, Claude Code, Cursor, and…
40 Minute LiteLLM Hack Exposes Cloud Keys and CI/CD Secrets From 2,488 Companies
A supply-chain breach involving LiteLLM has widened from a compromised software release into an exposure event affecting thousands of corporate build…
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Kimwolf v7 is raising the stakes for attacks launched from everyday Android TV boxes and set-top devices. The latest version can make disruptive web…
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Phantom Stealer is taking a familiar computer file and turning it into a hiding place. The credential-stealing malware can conceal its next stage in PNG…
Trump Signs Memo Authorizing Private Firms for Cyber Operations Against Foreign Criminals
President Donald Trump has signed a presidential memorandum that creates a pathway for companies to take part in government-led cyber operations against…
Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor
Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised…
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to…
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed…
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with…