IT Security News

Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel
Cyber Security News, EN

Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations

2026-04-18 12:04

A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. According to recent threat research published by Fortinet’s FortiGuard Labs, threat actors are exploiting a known command injection vulnerability…

Read more →

Cyber Security News, EN

Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say

2026-04-18 12:04

Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by Google search. According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal…

Read more →

EN, securityweek

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

2026-04-18 12:04

Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption. The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…

Read more →

EN, Security Boulevard

Ignoring DPDP Compliance? Here’s the Risk to Your Organization

2026-04-18 12:04

In boardroom discussions, data breaches are typically evaluated through the lens of financial impact, regulatory exposure, and operational disruption. While these factors are critical, they often overshadow a more fundamental concern: the consumer. Every piece of personal data collected by…

Read more →

hourly summary

IT Security News Hourly Summary 2026-04-18 12h : 2 posts

2026-04-18 12:04

2 posts were published in the last hour 9:5 : $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims 9:5 : [Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data

Read more →

EN, The Hacker News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

2026-04-18 11:04

Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it’s suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The exchange said it fell victim to what it described as…

Read more →

EN, The Hacker News

[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data

2026-04-18 11:04

In 2024, compromised service accounts and forgotten API keys were behind 68% of cloud breaches. Not phishing. Not weak passwords. Unmanaged non-human identities that nobody was watching. For every employee in your org, there are 40 to 50 automated credentials: service accounts, API…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Nexcorium Mirai Variant Weaponises TBK DVR Vulnerability in Fresh IoT Botnet Push

2026-04-18 10:04

A newly discovered Mirai malware variant named Nexcorium is actively targeting unpatched Internet of Things (IoT) devices. According to recent threat research from FortiGuard Labs, attackers are exploiting a severe vulnerability in TBK DVR systems to build a massive botnet…

Read more →

EN, Security Affairs

Microsoft Defender under attack as three zero-days, two of them still unpatched, enable elevated access

2026-04-18 09:04

Attackers exploit three Microsoft Defender zero-days, code-named BlueHammer, RedSun, and UnDefend, to gain elevated access. Attackers are exploiting three recently disclosed zero-day flaws in Microsoft Defender to gain higher privileges on compromised systems. The vulnerabilities, called BlueHammer, RedSun, and UnDefend,…

Read more →

EN, The Hacker News

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

2026-04-18 09:04

Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42. The attack targeting TBK DVR…

Read more →

hourly summary

IT Security News Hourly Summary 2026-04-18 09h : 1 posts

2026-04-18 09:04

1 posts were published in the last hour 6:11 : That data breach alert might be a trap

Read more →

EN, welivesecurity

That data breach alert might be a trap

2026-04-18 08:04

Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot. This article has been indexed from WeLiveSecurity Read the original article: That data breach alert might be a trap

Read more →

Cybersecurity Today, EN

Cybersecurity Today Month in Review of March/April 2026

2026-04-18 06:04

Cybersecurity Today Month-in-Review: RSAC AI Hype, Agentic Risks, Mythos Claims, and Real-World Resilience Jim Love hosts a delayed March month-in-review with panelists David Shipley and Laura Payne, starting with RSAC takeaways: agentic AI everywhere, heightened marketing spectacle, and industry tension…

Read more →

hourly summary

IT Security News Hourly Summary 2026-04-18 06h : 2 posts

2026-04-18 06:04

2 posts were published in the last hour 3:31 : PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands 3:31 : Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns

Read more →

Cyber Security News, EN

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

2026-04-18 05:04

A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login…

Read more →

Cyber Security News, EN

Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns

2026-04-18 05:04

According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers…

Read more →

EN, Security Boulevard

Belgium’s NIS2 Audit Window Opens April 18, 2026. The Rest of the EU Is Right Behind.

2026-04-18 02:04

Belgium’s NIS2 conformity assessment deadline hits April 18, 2026, and other EU member states are ramping enforcement close behind. See what auditors will demand from your SOC: incident reporting timelines, Article 20 management liability, and automatic documentation. The post Belgium’s…

Read more →

EN, Unit 42

Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)

2026-04-18 01:04

Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders. The post Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) appeared first on Unit 42.…

Read more →

hourly summary

IT Security News Hourly Summary 2026-04-18 00h : 4 posts

2026-04-18 00:04

4 posts were published in the last hour 22:3 : The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes 21:55 : IT Security News Daily Summary 2026-04-17 21:36 : At RSAC 2026, AI optimism and anxiety — and…

Read more →

Cybersecurity Headlines, EN

The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes

2026-04-18 00:04

Link to episode page This week’s Department of Know is hosted by Rich Stroffolino, with guests Andrew Storms, security engineering, Kilo Code, and Eduardo Ortiz-Romeu, VP, global head of cybersecurity, Techtronic Industries.  Missed the live show? Check it out on YouTube.…

Read more →

daily summary

IT Security News Daily Summary 2026-04-17

2026-04-17 23:04

156 posts were published in the last hour 21:36 : At RSAC 2026, AI optimism and anxiety — and an MIA U.S. government 21:36 : Friday Squid Blogging: New Giant Squid Video 21:4 : Critical Exploits, AI Shifts, and Major…

Read more →

EN, Search Security Resources and Information from TechTarget

At RSAC 2026, AI optimism and anxiety — and an MIA U.S. government

2026-04-17 23:04

<p>According to its most ardent proponents, AI is well on its way to creating a new, nirvana-like SOC, in which exposure and threat detection windows are measured in seconds, and human operators are liberated from endless alert triage and chronic…

Read more →

EN, Schneier on Security

Friday Squid Blogging: New Giant Squid Video

2026-04-17 23:04

Pretty fantastic video from Japan of a giant squid eating another squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. This article has…

Read more →

EN, eSecurity Planet

Critical Exploits, AI Shifts, and Major Breaches Redefine Cybersecurity This Week

2026-04-17 23:04

Weekly summary of Cybersecurity Insider newsletters The post Critical Exploits, AI Shifts, and Major Breaches Redefine Cybersecurity This Week appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Critical Exploits, AI Shifts,…

Read more →

Page 3 of 5269
« 1 2 3 4 5 … 5,269 »

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel

Recent Posts

  • IT Security News Hourly Summary 2026-04-19 21h : 3 posts April 19, 2026
  • Webinar: Uncovering Hidden Bugs and Vulnerabilities in C/C++ April 19, 2026
  • Mirai Malware Spreads Through Vulnerable TBK DVR Devices April 19, 2026
  • NSA Urges Americans to Reboot Routers as Russian Hackers Exploit Vulnerable Home Networks April 19, 2026
  • Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures April 19, 2026
  • IT Security News Hourly Summary 2026-04-19 18h : 4 posts April 19, 2026
  • Cyber attacks fuel surge in cargo theft across logistics industry April 19, 2026
  • [un]prompted 2026 – Al Found 12 Zero-Days in OpenSSL April 19, 2026
  • Apple Pay Scam Surge Targets iPhone Users With Fake Fraud Alerts and Urgent Calls April 19, 2026
  • Hackers Hide Credit Card Stealer in 1‑Pixel SVG Image on Magento Sites April 19, 2026
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 93 April 19, 2026
  • Scientists just found a way to control electrons without magnets April 19, 2026
  • I meant to do that! AI vendors shrug off responsibility for vulns April 19, 2026
  • A History of Global Hacking — and Where It’s Going Next April 19, 2026
  • Security Affairs newsletter Round 573 by Pierluigi Paganini – INTERNATIONAL EDITION April 19, 2026
  • Malicious Browser Extensions: An Overlooked Security Threat April 19, 2026
  • $13.74M Exploit Leads to Closure of Sanctioned Grinex Exchange Amid Intelligence Concerns April 19, 2026
  • Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits April 19, 2026
  • OpenAI Expands Cyber Defense Program With GPT-5.4-Cyber Access for Trusted Organizations April 19, 2026
  • Microsoft Teams Right-Click Paste Broken Following Edge Browser Update April 19, 2026

Copyright © 2026 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}