IT Security News

Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel
EN, securityweek

Interpol Says 260 Suspects in Online Romance Scams Have Been Arrested in Africa

2025-09-26 16:09

The operation took place in July and August and focused on scams in which perpetrators build online romantic relationships to extract money from targets or blackmail them with explicit images, Interpol said. The post Interpol Says 260 Suspects in Online…

Read more →

EN, eSecurity Planet

Vietnamese Hackers Exploit Fake Copyright Notices to Spread “Lone None” Stealer

2025-09-26 16:09

Vietnamese hackers use fake copyright notices and Telegram-based malware to steal data and crypto in a growing phishing campaign. The post Vietnamese Hackers Exploit Fake Copyright Notices to Spread “Lone None” Stealer appeared first on eSecurity Planet. This article has…

Read more →

EN, Malwarebytes

Google and Flo to pay $56 million after misusing users’ health data

2025-09-26 16:09

Flo Health and Google agreed to pay $56 million to settle lawsuits alleging the period-tracking app shared sensitive health data for ads. This article has been indexed from Malwarebytes Read the original article: Google and Flo to pay $56 million…

Read more →

CySecurity News - Latest Information Security and Hacking Incidents, EN

OpenAI Patches ChatGPT Gmail Flaw Exploited by Hackers in Deep Research Attacks

2025-09-26 16:09

  OpenAI has fixed a security vulnerability that could have allowed hackers to manipulate ChatGPT into leaking sensitive data from a victim’s Gmail inbox. The flaw, uncovered by cybersecurity company Radware and reported by Bloomberg, involved ChatGPT’s “deep research” feature.…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Malicious MCP Server Discovered Stealing Sensitive Emails Using AI Agents

2025-09-26 15:09

Enterprises everywhere are embracing MCP servers—tools that grant AI assistants “god-mode” permissions to send emails, run database queries, and automate tedious tasks. But no one ever stopped to ask: Who built these tools? Today, the first real-world malicious MCP server—postmark-mcp—has…

Read more →

Check Point Blog, EN

How to Defend Against Credential Attacks with a Hybrid Mesh Architecture

2025-09-26 15:09

Introduction Credential-based attacks have reached epidemic levels. The 2025 Verizon Data Breach Investigations Report (DBIR) underscores the trend: 22% of breaches now start with compromised credentials, while Check Point External Risk Management found that leaked credential volumes surged 160% year-over-year.…

Read more →

EN, Fortinet Threat Research Blog

SVG Phishing hits Ukraine with Amatera Stealer, PureMiner

2025-09-26 15:09

A phishing campaign in Ukraine uses malicious SVG files to drop Amatera Stealer and PureMiner, enabling data theft and cryptomining. Learn more.        This article has been indexed from Fortinet Threat Research Blog Read the original article: SVG Phishing hits…

Read more →

Cyber Security News, EN

First-Ever Malicious MCP Server Found in the Wild Steals Emails via AI Agents

2025-09-26 15:09

The first-ever malicious Model-Context-Prompt (MCP) server discovered in the wild, a trojanized npm package named postmark-mcp that has been secretly exfiltrating sensitive data from users’ emails. The package, downloaded approximately 1,500 times per week, contained a backdoor that copied every…

Read more →

Cyber Security News, EN

New Variant of The XCSSET Malware Attacking macOS App Developers

2025-09-26 15:09

The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques,…

Read more →

Cyber Security News, EN

Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch

2025-09-26 15:09

A critical, perfect 10.0 CVSS score vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution was actively exploited as a zero-day at least a week before the company released a patch. The vulnerability, tracked as CVE-2025-10035, is a command injection…

Read more →

EN, The Hacker News

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks

2025-09-26 15:09

The Russian advanced persistent threat (APT) group known as COLDRIVER has been attributed to a fresh round of ClickFix-style attacks designed to deliver two new “lightweight” malware families tracked as BAITSWITCH and SIMPLEFIX. Zscaler ThreatLabz, which detected the new multi-stage…

Read more →

EN, www.infosecurity-magazine.com

Singapore Threatens Meta With Fines Over Facebook Impersonation Scams

2025-09-26 15:09

The Singapore police said Facebook is the top platform for online scams in the country This article has been indexed from www.infosecurity-magazine.com Read the original article: Singapore Threatens Meta With Fines Over Facebook Impersonation Scams

Read more →

Cyber Defense Magazine, EN

Customer Authentication Challenges That Impact Your Organization’s Security Posture

2025-09-26 15:09

Introduction In today’s cybersecurity landscape, CISOs face the challenge of securing data while managing costs effectively. As cyber threats become more sophisticated, traditional user authentication methods often prove inadequate or… The post Customer Authentication Challenges That Impact Your Organization’s Security…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Apache Airflow Vulnerability Lets Read-Only Users Access Sensitive Data

2025-09-26 15:09

Apache Airflow maintainers have disclosed a serious security issue, tracked as CVE-2025-54831, that allows users holding only read permissions to view sensitive connection details via both the Airflow API and web interface. The vulnerability, present in Airflow version 3.0.3, undermines…

Read more →

EN, Malwarebytes

Neon App pays users to record their phone calls, sells data for AI training

2025-09-26 15:09

An app called Neon Mobile which pays a small price for privacy is storming the popularity chart in the US Apple app store. This article has been indexed from Malwarebytes Read the original article: Neon App pays users to record…

Read more →

EN, The Register - Security

Prompt injection – and a $5 domain – trick Salesforce Agentforce into leaking sales

2025-09-26 15:09

More fun with AI agents and their security holes A now-fixed flaw in Salesforce’s Agentforce could have allowed external attackers to steal sensitive customer data via prompt injection, according to security researchers who published a proof-of-concept attack on Thursday. They…

Read more →

CySecurity News - Latest Information Security and Hacking Incidents, EN

Teens Arrested Over Scattered Spider’s $115M Hacking Spree

2025-09-26 15:09

  Law enforcement authorities in the United States and United Kingdom have arrested two teenagers connected to the notorious Scattered Spider hacking collective, charging them with executing an extensive cybercrime operation that netted over $115 million in ransom payments. The…

Read more →

EN, The Register - Security

Volvo North America confirms staff data stolen following ransomware attack on IT supplier

2025-09-26 14:09

The downstream consequences of Miljödata’s ransomware attack continue to affect major organizations Volvo North America is the latest large organization to announce attackers accessed employee data after a ransomware attack struck its HR system provider.… This article has been indexed…

Read more →

EN, securityweek

North Korea’s Fake Recruiters Feed Stolen Data to IT Workers

2025-09-26 14:09

North Korean threat actors pose as recruiters to steal developers’ identities and supply them to fraudulent IT workers. The post North Korea’s Fake Recruiters Feed Stolen Data to IT Workers appeared first on SecurityWeek. This article has been indexed from…

Read more →

EN, securityweek

Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza

2025-09-26 14:09

Microsoft said Thursday it had disabled services to a unit within the Israeli military after a company review had determined its artificial intelligence and cloud computing products were being used to help carry out mass surveillance of Palestinians. The action…

Read more →

EN, Security Boulevard

Salesforce Faces Lawsuits Over Compromises of Third-Party Apps: Report

2025-09-26 14:09

Salesforce is facing a possible class action lawsuit from almost two dozen plaintiffs who say the SaaS giant should have had better security around its platform, even though a spate of high-profile data-stealing attacks on third-party partners did not start…

Read more →

EN, The Hacker News

Crash Tests for Security: Why BAS Is Proof of Defense, Not Assumptions

2025-09-26 14:09

Car makers don’t trust blueprints. They smash prototypes into walls. Again and again. In controlled conditions. Because design specs don’t prove survival. Crash tests do. They separate theory from reality. Cybersecurity is no different. Dashboards overflow with “critical” exposure alerts.…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Malware Gangs Enlist Covert North Korean IT Workers in Corporate Attacks

2025-09-26 14:09

Malware operators aligned with North Korea have forged a sophisticated partnership with covert IT workers to target corporate organizations worldwide. This collaboration, detailed in a new white paper presented at Virus Bulletin 2025, sheds light on the intertwined operations of…

Read more →

EN, Security Affairs

UK NCSC warns that attackers exploited Cisco firewall zero-days to deploy RayInitiator and LINE VIPER malware

2025-09-26 14:09

UK NCSC warns that threat actors exploited Cisco firewall zero-days to deploy new malware strains RayInitiator and LINE VIPER. The U.K. NCSC reported that threat actors exploited recently disclosed Cisco firewall flaws (CVE-2025-20362, CVE-2025-20333) in zero-day attacks to deploy novel…

Read more →

Page 628 of 4872
« 1 … 626 627 628 629 630 … 4,872 »

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel

Recent Posts

  • Bithumb Mistakenly Sends 620,000 Bitcoin ($40B) to Customer Accounts February 7, 2026
  • IT Security News Hourly Summary 2026-02-07 21h : 1 posts February 7, 2026
  • How to Suppress Negative Content Without Triggering the Streisand Effect February 7, 2026
  • Italian university La Sapienza still offline to mitigate recent cyber attack February 7, 2026
  • Dozens of Government and Infrastructure Networks Breached in Global Espionage Campaign February 7, 2026
  • Firefox Will Give Users an AI Kill Switch for Better Privacy February 7, 2026
  • IT Security News Hourly Summary 2026-02-07 18h : 2 posts February 7, 2026
  • Security Architecture Part I: Introduction to Security Architecture Concepts, CIA, and Rules February 7, 2026
  • Threat Actors Exploit Fortinet Devices and Steal Firewall Configurations February 7, 2026
  • Unsecured Database Exposes 149 Million Logins Linked to Infostealer Malware Operations February 7, 2026
  • ACF Plugin Flaw Exposes 50,000 WordPress Sites to Admin Takeover February 7, 2026
  • BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages February 7, 2026
  • IT Security News Hourly Summary 2026-02-07 15h : 3 posts February 7, 2026
  • Hackers Linked to State Actors Target Signal Messages of Military Officials and Journalists February 7, 2026
  • Organizations Urged to Replace Discontinued Edge Devices February 7, 2026
  • China-Linked DKnife Threat Underscores Risks to Network Edge Devices February 7, 2026
  • Apple Pay Users Targeted by Phishing Attack Aimed at Stealing Payment Details February 7, 2026
  • Study confirms experience beats youthful enthusiasm February 7, 2026
  • German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists February 7, 2026
  • State-Backed Hackers Target Military Officials and Journalists on Signal in Latest Cyberattack February 7, 2026

Copyright © 2026 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}