The cyberattack involving Ernst & Young (EY) has entered a new phase after the ShinyHunters extortion group claimed responsibility for the intrusion,…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Capital One Open-sources AI Security Tool VulnHunter to Help Developers Identify Exploitable Flaws before Deployment
Capital One has released VulnHunter, an open-source AI-powered application security tool designed to identify exploitable software vulnerabilities before…
NVIDIA Launches Open Secure AI Alliance to Strengthen AI Security with 36 Industry Partners
iNVIDIA has joined forces with 36 technology organizations to establish the Open Secure AI Alliance (OSAA), an industry-wide initiative focused on…
CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
A newly identified malware strain named CrashStealer is targeting macOS users by disguising itself as Apple’s legitimate crash reporting utility. Designed…
US Sanctions on VPN Service Briefly Disrupt Telegram’s t.me Link Shortener Due to Compliance Action
iTelegram’s t.me link-shortening domain briefly went offline earlier this week after a compliance action linked to US sanctions inadvertently affected the…
Google to Patch Gemini Flaw That Lets Locked Android 16 Phones Send SMS and WhatsApp Messages Without PIN
Google is preparing to roll out a fix for a newly identified security vulnerability in its Gemini AI assistant that could allow unauthorized users with…
Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach
The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which…
Meta AI Bots Drain Publishers With 9 Billion Q2 Requests
Meta’s AI bots are rapidly becoming a costly headache for online publishers, exposing a structural imbalance in how AI platforms use web content. Recent…
Moonshot AI Claims Kimi K3 Matches OpenAI and Anthropic Models
Founded by Moonshot AI, the company has released the Kimi K3 large language model, a next-generation large language model the company claims is…
Telegram Introduces Serverless Runtime for Bots, Bringing Deployment, Application Logic, and Data Under One Platform
Telegram has rolled out Telegram Serverless, a managed serverless runtime that enables developers to deploy bot backends directly to Telegram’s…
Fastjson Zero‑Day RCE Actively Targeting U.S. Companies
Hackers are abusing a critical Fastjson zero‑day remote code execution (RCE) flaw to compromise U.S. organizations by simply sending malicious JSON data…
Russian Sandworm Hackers Adopt ClickFix Technique to Target Ukrainian Organizations
Ukraine’s Computer Emergency Response Team (CERT-UA) has issued an advisory after detecting that Russia’s advanced persistent threat (APT) group Sandworm…
Vatican ‘Click to Pray’ App Security Flaw Exposed Data of 700,000 Users
Approximately 700,000 personal data of Vatican users were reportedly exposed due to a critical security vulnerability in Click to Pray, causing concerns…
Phishing and Compromised Identities Replace Software Exploits as Leading Ransomware Entry Ooint, Sophos Reports
Phishing campaigns, malicious emails and compromised credentials have overtaken software vulnerability exploitation as the leading entry points for ransomware attacks, according to Sophos' State of Ransomware 2026 report, signalling that threat actors are placing greater focus on stealing identities than…
US Treasury Sanctions VPN Provider Linked to Ransomware Operations
The United States Department of the Treasury has taken unprecedented steps by sanctioning a virtual private network (VPN) service provider and its administrator for the first time ever. The VPN was used by ransomware groups to disguise their digital…
GitHub Fake Repos Spread Malware in New Infostealer Campaign
Cybersecurity researchers have uncovered a large-scale campaign in which hundreds of GitHub repositories were made to look like legitimate software projects while actually distributing malware. According to the report, the attackers created 292 fake repositories that impersonated security tools, developer…
Browser Memory Becomes New Target in JavaScript Malware Campaign
Security researchers have discovered a large-scale malvertising campaign that uses fake cryptocurrency and trading websites to assemble malware inside the web browser of the victim, making it increasingly difficult to detect using traditional security tools. A security firm named Confiant…
Ostium Confirms $23.75 Million Vault Exploit After Off-Chain Price Feed Compromise
Ostium, a decentralized trading platform built on the Arbitrum blockchain, has confirmed that hackers stole $23.75 million from its liquidity provider vault after compromising the platform’s off-chain price feed infrastructure.In an update shared by the company, Ostium explained that…
Steam Forum Scam Uses ClickFix Technique to Infect Gamers With XMRig Cryptominer
Cybercriminals are targeting Steam users through fraudulent troubleshooting posts that exploit the increasingly common ClickFix social engineering technique, tricking gamers into manually executing malicious PowerShell commands that ultimately install cryptocurrency mining malware on Windows systems. Rather than relying on…
AI Is Fueling a New Wave of Cybercrime
Cybercriminals are increasingly turning to artificial intelligence, and the biggest barriers that once slowed adoption are rapidly disappearing. According to a recent Axios report, restricted access to models, high costs, and limited incentive to change old hacking methods are…
