Companies are adopting AI tools faster than they are testing whether their underlying data is appropriately secure, a new report from governance firm…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Conti Ransomware Ties Lead to Four-Year Prison Sentence
Ukrainian nationals have been sentenced to four years in U.S. prison for participating in the Conti ransomware operation. Between 2020 and 2022, the…
Several Chinese Hacking Groups Observed Using Identical Chrome Zero-Day Exploit
Based on cybersecurity firm Proofpoint, four cyber-espionage groups, most of which are linked to Chinese state intelligence, have been exploiting the same…
Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer’s Personal Device
Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police…
GitLab’s Worst-Rated Vulnerability Is Already Being Exploited
GitLab on September 10 shipped emergency patches for a maximum-severity vulnerability that lets unauthenticated attackers read arbitrary files off a…
Google Play Early Access Exploited for Fake Reward Apps
Cybersecurity firm Bitdefender has unearthed a large-scale exploit of Google Play’s Early Access program, where attackers are distributing thousands of…
Attackers Use Expired Websites for Malware Scams
Dead websites may seem harmless once they are abandoned by their owners, but their old internet reputation can make them important tools for threat…
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company’s software…
Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots
Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker in close…
MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign
MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to…
US Disrupts Xinbi Guarantee Marketplace Linked to Cyber Scams
A Telegram-based marketplace known as Xinbi Guarantee has been sued by U.S. authorities for providing services to scam centers engaged in cyber fraud and…
Check Point Discloses Two Critical VPN Vulnerabilities Allowing RCE
Check Point has addressed two critical flaws in the way its management and firewall products manage VPN certificates. Both vulnerabilities have been…
Microsoft Tracks Cloud Intrusion Campaign Using Passkey Phishing and Graph API Abuse
Microsoft Security Research published a report on September 9, 2026, detailing active cloud-based intrusions spanning multiple accounts, in which unusual…
The Four-Character Password Guarding Your Company’s AI Keys
Security researchers at Wiz scanned 3,074 internet-facing deployments of LiteLLM in February and found something that should embarrass more than a few…
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud…
DoppelCart Fake-Shop Network Found Operating Across 119,000 Domains
A newly published investigation has uncovered what may be the largest documented fake-shop network to date, spanning roughly 119,000 domains and dubbed…
One WeChat Call Was Enough to Hijack Accounts Across iPhone and Android
A new wave of WeChat vulnerability can turn an incoming voice call into a zero-click account takeover, enabling a compromised account to target another…
LG Targets Residential Proxies in New Smart TV Security Move
Several webOS apps using residential proxy technology are being suspended by LG Electronics for routing third-party traffic through smart TVs. The company…
Ransomware Affiliate Pretends to be Recovery Service for Extortion
An alleged ransomware affiliate is pretending to be a ransomware recovery service named “Ransom Busters,” reaching out to victims before the attacks…
Critical FreeIPA Bug Can Let Attackers Take Over Admin Rights
FreeIPA users and Red Hat Identity Management administrators should treat CVE-2026-76578 as a critical authentication-bypass flaw that can lead to full…
