Sensitive court records and personal information were spilled from a data breach in the court system, which impacts at least 12 states in the U.S.,…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Grafana MCP Flaw Exposes Session Spoofing and SSRF Risk
Grafana MCP has come under security scrutiny after researchers found a dangerous combination of unauthenticated tool access and server-side request…
1 Folder Was All It Took: Security Researchers Find AI Coding Agents Can Be Hijacked Before a Single Prompt Is Typed
Opening a folder should not be a security event. For users of at least seven popular AI coding agents, until recently, it could be one. A newly documented…
5 Million WordPress Sites Exposed to SQL Injection Vulnerability
A severe security flaw in a famous WordPress migration plugin and backup could allow threat actors to take command of over millions of sites, experts have…
Brazilian Government Site Compromised to Redirect Users to Betting Pages
An organization known as Gambling Goblin, which is a Chinese-speaking cybercrime group, has compromised Apache web servers owned by Brazilian government…
Sality Botnet Disrupted as Authorities Seize Key Infrastructure
An international public-private operation has disrupted Sality, a peer-to-peer botnet that remained active for more than two decades, by seizing domains…
Russian National Charged Over Malware Campaign Targeting 80,000 Freelancers
A Russian national has been extradited to the United States to face federal charges over an alleged malware campaign that targeted approximately 80,000…
Four Cybersecurity Habits That Can Do More Harm Than Good When Misused
Cybersecurity advice is often reduced to simple rules: change passwords regularly, avoid public Wi-Fi, install antivirus software and enable two-factor…
Received an Apple Threat Notification? How to Verify and Respond Safely
An Apple threat notification is not a routine security warning. Apple issues these high-confidence alerts when its threat intelligence indicates that…
Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens
Cybersecurity researchers have observed attackers exploiting a critical JFrog Artifactory vulnerability shortly after its public disclosure. The flaw…
FBI Investigates Dark Web Service Offering 153 Million Driver’s Licenses
The FBI has opened an investigation into an apparent breach involving identity verification provider IDScan.net after a newly launched dark web service…
Hackers Hijack BGP Routes to Deliver Malicious Virtualizor Update
Hijackers compromised network routes used by Softaculous and redirected traffic to servers where they distributed a rogue Virtualizor update to a limited…
NSA Warning Exposes Common Router Security Risks
The recent warning from the NSA and partner agencies highlights a simple but important reality: routers are often the weakest link in a home or…
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing
Observations have shown that threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, with attacks moving beyond…
Anthropic: Infostealer Malware Hacks Claude Sessions to Drain Consumption Usage
Anthropic has warned Claude users that infostealer malware on their systems has stolen active Claude login sessions, letting threat actors to log into…
ServiceNow Patches Three Critical Code Injection Flaws Rated CVSS 10.0
ServiceNow has released security updates addressing four vulnerabilities in its AI Platform, including three critical flaws rated 10.0 out of 10 under…
OpenAI’s Hugging Face Attack Was Worse Than First Reported, New Reports Reveal
Two recently published reports highlighted additional details about the OpenAI Hugging Face breach, showing that the assault involved a substantial number…
White House AI Vetting Plan Draws Secrecy Concerns
The White House’s new plan to review advanced AI models is meant to reduce safety and cybersecurity risks, but the policy has been criticized for being…
Berlin Defies Hackers After Data Theft From State Network
A Berlin state government official has confirmed that hackers are attempting to extort the city after its administrative network was compromised earlier…
New TerminalFix Campaign Attacks via Fake CAPTCHAs and Installs Backdoors
Microsoft has revealed information of a new ClickFix version, called TerminalFix, that intends to lure users into launching a malicious command in…
