Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a…
Tag: Cyber Security News
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected…
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The…
Containing Machine Speed Cyber Attacks Inside AI Infrastructure
A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response…
Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks
A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May…
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation…
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known…
New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used…
Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a…
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a…
Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections
Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package…
cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to…
Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates
Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the “Noble Numbat” long-term support release, delivering a fresh…
Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide
A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000…
New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax,…
IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web
IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500…
Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection
Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could enable stored…
GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution
GitLab has released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including two critical flaws that could…
JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take…
Top 10 Best Cloud Security Posture Management (CSPM) Tools in 2026
CSPM finds the cloud misconfigurations that cause most cloud breaches public buckets, permissive IAM, exposed databases continuously, across accounts and…