AI security and governance platform Zenity has announced a $125 million Series C funding round led by Norwest. The investment signals escalating…
Tag: Cyber Security News
Alert Fatigue Is Hitting US SOCs Hard: How to Cut Through the Noise
US SOC teams are dealing with a growing volume of alerts, while analyst time and security budgets remain limited. Too much of that time is spent checking…
Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal
Claroty Team82 has uncovered 23 vulnerabilities in Copeland’s XWEB Pro supervisory controllers, widely used to manage commercial refrigeration in…
Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks
Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITY\SYSTEM. The technique, published by…
Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub
Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was…
Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix
Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked…
Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack
Poland’s energy sector attack has revealed how one compromised remote-access device can become the first step in a wider industrial intrusion. The…
Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware
Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote…
Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment
Proactive AI-native security vendor Horizon3 has announced a major $20 million investment into its global partner ecosystem. The funding reinforces the…
DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July…
New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines
A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings,…
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open…
LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident…
CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being…
Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter…
New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp
A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
New Phishing Attack Leverage SSL/TLS Certificates to Target High-value Brands Customers Via Whatsapp
A phishing operation is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition
Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning…
Anthropic to Add Invisible Watermarks to All Claude AI Outputs
Anthropic has announced plans to add invisible watermarks and signed metadata to content created by Claude AI. The move follows the company’s decision to…
OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming
OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue…