IT Security News

Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel
EN, Help Net Security

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring

2025-12-18 16:12

Between June 2024 and December 2025, Fortra analysts tracked a persistent business email compromise (BEC) operation that we have now classified as Scripted Sparrow. The group carries out well-crafted highly targeted phishing campaigns that masquerade as professional services firms to…

Read more →

EN, Help Net Security

Apiiro unveils AI SAST built on deep code analysis to eliminate false positives

2025-12-18 16:12

Apiiro introduced Apiiro AI SAST, a new approach to static application security testing (SAST) that automates code risk detection, validation and fixes with the precision and cognitive process of an expert application security engineer. Grounded in Apiiro’s patented Deep Code…

Read more →

hourly summary

IT Security News Hourly Summary 2025-12-18 15h : 12 posts

2025-12-18 16:12

12 posts were published in the last hour 14:2 : From the Hill: The AI-Cybersecurity Imperative in Financial Services 14:2 : Researchers Uncovered New Lazarus and Kimsuky Infrastructure with Active Tools and Tunnelling Nodes 14:2 : The ghosts of WhatsApp:…

Read more →

EN, Palo Alto Networks Blog

From the Hill: The AI-Cybersecurity Imperative in Financial Services

2025-12-18 16:12

Financial institutions face a dual mandate: embrace AI for cyber defense and secure AI with Secure AI by Design. Discover the path forward. The post From the Hill: The AI-Cybersecurity Imperative in Financial Services appeared first on Palo Alto Networks…

Read more →

Cyber Security News, EN

Researchers Uncovered New Lazarus and Kimsuky Infrastructure with Active Tools and Tunnelling Nodes

2025-12-18 16:12

A joint investigation by Hunt.io and the Acronis Threat Research Unit has exposed an extensive network of North Korean state-sponsored infrastructure, revealing fresh connections between Lazarus and Kimsuky operations across global campaigns. The research uncovered active tool-staging servers, credential-theft environments,…

Read more →

EN, Malwarebytes

The ghosts of WhatsApp: How GhostPairing hijacks accounts

2025-12-18 16:12

Criminals are tricking WhatsApp users into linking an attacker’s browser to their account using fake login pages and routine-looking prompts. This article has been indexed from Malwarebytes Read the original article: The ghosts of WhatsApp: How GhostPairing hijacks accounts

Read more →

EN, The Register - Security

FBI dismantles alleged $70M crypto laundering operation

2025-12-18 16:12

Justice Department claims unlicensed exchange funneled ransomware profits US feds have dismantled a crypto laundering service that they say helped cybercrooks wash tens of millions of dollars in dirty digital cash, seizing its servers and unsealing charges against an alleged…

Read more →

EN, Security Boulevard

What the Latest OpenAI Security Breach Reveals About the State of AI Protection

2025-12-18 16:12

A recent OpenAI-related breach via third-party provider Mixpanel exposes how AI supply chain vulnerabilities enable phishing, impersonation, and regulatory risk—even without direct system compromise. The post What the Latest OpenAI Security Breach Reveals About the State of AI Protection  appeared first on…

Read more →

EN, Help Net Security

Microsoft 365 users targeted in device code phishing attacks

2025-12-18 16:12

Attackers are targeting Microsoft 365 users with device code authorization phishing, a technique that fools users into approving access tokens, Proofpoint warns. The method abuses Microsoft’s OAuth 2.0 device authorization grant flow by presenting users with device codes that, when…

Read more →

EN, Help Net Security

AppGate extends zero trust to secure AI workloads with Agentic AI Core Protection

2025-12-18 16:12

AppGate announced the launch of Agentic AI Core Protection, a new capability within AppGate ZTNA designed to secure AI workloads deployed in enterprise core environments across on-prem and cloud venues. This innovation enables organizations to embrace AI-driven transformation while maintaining…

Read more →

EN, Malwarebytes

Chrome extension slurps up AI chats after users installed it for privacy

2025-12-18 15:12

The extension disclosed its AI data collection, but not in a way most users would recognize—or knowingly agree to. This article has been indexed from Malwarebytes Read the original article: Chrome extension slurps up AI chats after users installed it…

Read more →

EN, The Register - Security

NHS tech supplier probes cyberattack on internal systems

2025-12-18 15:12

Around 2,000 GP practices use its products An NHS tech supplier is investigating a cyberattack that affected its systems in the early hours of Sunday.… This article has been indexed from The Register – Security Read the original article: NHS…

Read more →

EN, securityweek

CISA Warns of Exploited Flaw in Asus Update Tool

2025-12-18 15:12

Tracked as CVE-2025-59374, the issue is a software backdoor implanted in Asus Live Update in a supply chain attack. The post CISA Warns of Exploited Flaw in Asus Update Tool appeared first on SecurityWeek. This article has been indexed from…

Read more →

EN, The Hacker News

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

2025-12-18 15:12

Threat actors with ties to the Democratic People’s Republic of Korea (DPRK or North Korea) have been instrumental in driving a surge in global cryptocurrency theft in 2025, accounting for at least $2.02 billion out of more than $3.4 billion…

Read more →

EN, The Hacker News

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

2025-12-18 15:12

This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From…

Read more →

EN, Hackread – Cybersecurity News, Data Breaches, AI, and More

Why Organizations Need to Modify Their Cybersecurity Strategy for 2026

2025-12-18 15:12

Cybersecurity planning continues to advance as organisations integrate new software, cloud platforms, and digital tools into nearly every… This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI, and More Read the original article: Why Organizations Need…

Read more →

EN, Hackers Online Club

GhostPairing Attack: How Hackers Secretly Hijack WhatsApp

2025-12-18 15:12

A recent investigation by cybersecurity firm Gen Digital has uncovered a social engineering campaign known as “GhostPairing Attack.”… The post GhostPairing Attack: How Hackers Secretly Hijack WhatsApp appeared first on Hackers Online Club. This article has been indexed from Hackers…

Read more →

EN, www.infosecurity-magazine.com

North Korea Steals Over $2bn in Crypto in 2025

2025-12-18 15:12

Chainalysis warns North Korea continues to steal billions in crypto for its weapons program This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korea Steals Over $2bn in Crypto in 2025

Read more →

DZone Security Zone, EN

Agentic AI in Cloud-Native Systems: Security and Architecture Patterns

2025-12-18 14:12

AI has long progressed past statistical models that generate forecasts or probabilities. The next generation of AI systems is agents, autonomous cloud-native systems capable of acting and intervening in an environment without human intervention or approval. Agents can provision infrastructure,…

Read more →

EN, The Hacker News

The Case for Dynamic AI-SaaS Security as Copilots Scale

2025-12-18 14:12

Within the past year, artificial intelligence copilots and agents have quietly permeated the SaaS applications businesses use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow now come with built-in AI assistants or agent-like features. Virtually every major…

Read more →

EN, Hackread – Cybersecurity News, Data Breaches, AI, and More

FBI Seizes Crypto Laundering Hub E-Note Linked to Russian Admin

2025-12-18 14:12

The FBI and international police have shut down E-Note, a cryptocurrency exchange that laundered over $70 million for cybercriminals. Read about the indictment of a Russian and how the global task force ended his decade-long operation. This article has been…

Read more →

Cyber Security News, EN

Chinese-based Ink Dragon Compromises Asia and South America into European Government Networks

2025-12-18 14:12

Ink Dragon, a Chinese espionage group, has significantly expanded its operations from Southeast Asia and South America into European government networks. This advancement marks a notable shift in the threat actor’s strategic focus, utilizing a blend of well-engineered tools combined…

Read more →

Cyber Security News, EN

Hackers Hijacking VNC Connections to Gain Access to OT Control Devices in Critical Infrastructure

2025-12-18 14:12

A coalition of U.S. and international cybersecurity agencies issued a stark warning this week about pro-Russia hacktivists exploiting exposed Virtual Network Computing (VNC) connections to infiltrate operational technology (OT) systems in critical infrastructure. The joint advisory, released December 9, 2025,…

Read more →

EN, The Register - Security

React2Shell exploitation spreads as Microsoft counts hundreds of hacked machines

2025-12-18 14:12

Security boffins warn flaw is now being used for ransomware attacks against live networks Microsoft says attackers have already compromised “several hundred machines across a diverse set of organizations” via the React2Shell flaw, using the access to execute code, deploy…

Read more →

Page 1147 of 5791
« 1 … 1,145 1,146 1,147 1,148 1,149 … 5,791 »

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel

Recent Posts

  • IT Security News Hourly Summary 2026-07-30 18h : 20 posts July 30, 2026
  • Jailed Flock vandal wipes out three cameras, racks up thousands in damages July 30, 2026
  • TrendAI™ Joins Nvidia’s Open Secure AI Alliance: Closing the Gap Between AI Builders and AI Defenders July 30, 2026
  • Shadow AI, leadership resistance make AI governance tough for worried CISOs July 30, 2026
  • Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover July 30, 2026
  • Timeless Compliance: Why Better Questions Beat Bigger Frameworks July 30, 2026
  • Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities July 30, 2026
  • Location Sharing: Convenience at the Cost of Safety July 30, 2026
  • Senator Wyden urges federal VPN purge July 30, 2026
  • Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes July 30, 2026
  • MCP Server Security: The Blind Spot in Your AI Stack July 30, 2026
  • Update your iPhone, iPad and Mac to fix Apple security holes July 30, 2026
  • Novee brings continuous AI pentesting to mobile apps July 30, 2026
  • Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility July 30, 2026
  • New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances July 30, 2026
  • Hackers abuse Microsoft Teams in ransomware campaign through fake IT support July 30, 2026
  • Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion July 30, 2026
  • Amazon Attributes Earlier npm Supply Chain Attacks to North Korea’s Sapphire Sleet July 30, 2026
  • Hackers Are Exploiting Nearly One in Four Vulnerabilities Before Defenders Get a CVE July 30, 2026
  • Tribeca Film Festival Data Breach Exposes 666K Records July 30, 2026

Copyright © 2026 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}