AI-powered customer service bots are being given more responsibility inside businesses, including access to customer profiles, billing data, support…
Category: Cyber Security News
Top 10 Best Managed XDR Services in 2026
Managed XDR is MDR with a wider aperture: analysts monitoring correlated telemetry from endpoints, network, email, identity, and cloud rather than…
ShinyHunters Gained Access to 6 Million Customers’ Records Using a Single Call
A single phone call was all it took to trigger one of the largest data breaches in Dutch history. In early February 2026, Dutch telecom giant Odido and…
Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials
A critical security incident at Coder exposed users of its Terraform module registry to malicious packages designed to steal credentials from cloud…
Shai-Hulud npm Worm Resurfaces After 111 Days and Slips Past Malware Scanning
A familiar npm worm has returned after more than three months of silence, carrying the same malicious file linked to an earlier supply-chain incident. The…
New InjectEave Attack Allows Hackers to Recover Audio Playing on Headphones from 30 Meters
Researchers have unveiled a novel electromagnetic (EM) attack called InjectEave that lets an adversary eavesdrop on audio playing through wired and…
Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers
A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers. Instead of leaving an…
Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack
Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day…
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
A new Linux bot called Tengu is built to stay hidden and turn compromised systems into tools for disruption. The 32-bit malware poses as a routine kernel…
LG Smart TVs Caught Scanning Networks and Logging Audio in Standby
Your LG smart TV may be doing far more than displaying your favorite shows while it sits “off” in the corner of your living room. A new investigation from…
OpenAI Commits $1 Billion to Give Critical Infrastructure Defenders Frontier AI Cyber Tools
OpenAI has launched Daybreak for Frontline Defenders, a global cybersecurity initiative designed to help organizations protecting essential services use…
New BYOTC Attack Hijacks Trusted Windows Apps to Abuse Privileged Kernel Drivers
A new Windows attack shows how a trusted program can become a path to sensitive system functions. The method, called Bring Your Own Trusted Caller, or…
ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps
ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and…
Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users
Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents,…
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs…
Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives
Switzerland’s federal administration is preparing to test a sovereign, open-source digital workplace that could reduce its long-term dependence on…
Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance
Microsoft will retire support for Manifest V2 browser extensions in Microsoft Edge by early 2027, requiring users, enterprises, and developers to move to…
Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach
Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and…
DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms
South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access. The malware hides inside…
Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to…