GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD…
Tag: Cyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog,…
Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails. The messages can look ordinary because they come from…
Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser…
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia. Once opened, the fake…
Wireshark 4.6.8 Released With Patch for 28 Vulnerabilities That Lead to Crashes
The Wireshark Foundation has officially rolled out Wireshark 4.6.8, a security update that patches 28 distinct vulnerabilities capable of triggering…
Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data
SpecterOps has released Blacklight, an open-source toolkit that identifies local artifacts from AI coding agents like Codex, Claude Code, Cursor, and…
40 Minute LiteLLM Hack Exposes Cloud Keys and CI/CD Secrets From 2,488 Companies
A supply-chain breach involving LiteLLM has widened from a compromised software release into an exposure event affecting thousands of corporate build…
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Kimwolf v7 is raising the stakes for attacks launched from everyday Android TV boxes and set-top devices. The latest version can make disruptive web…
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Phantom Stealer is taking a familiar computer file and turning it into a hiding place. The credential-stealing malware can conceal its next stage in PNG…
Trump Signs Memo Authorizing Private Firms for Cyber Operations Against Foreign Criminals
President Donald Trump has signed a presidential memorandum that creates a pathway for companies to take part in government-led cyber operations against…
Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor
Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised…
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to…
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed…
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with…
Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access
Palo Alto Networks has released its August 12, 2026 security bulletin, disclosing 11 new vulnerabilities affecting PAN-OS, the GlobalProtect App, Prisma…
Mindgard Raises $30 Million to Tackle AI’s Fastest-Growing Attack Surface
AI security startup Mindgard has closed a $30 million Series A funding round, pushing the company’s total funding to nearly $42 million. The milestone…
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
A newly identified threat actor is running a large-scale, long-running cyber campaign targeting Salesforce Experience Cloud sites and ServiceNow Service…
China-linked Hackers Using AI Agents to Attack Taiwan Government Websites
Suspected China-linked attackers have carried out what researchers describe as the first fully autonomous cyberattack on a foreign government, using…
Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code
Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to…