The Indian government has directed Google to take down dozens of websites and databases hosted on Firebase after finding that cybercriminals were…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
Your Company’s Phishing Tests Are Measuring the Wrong Thing
When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets renewed. But a…
Lost Phone Reporting Flaws Could Let Hackers Block Any Mobile Device for $4
A new security investigation has revealed serious weaknesses in the systems used by mobile carriers to block lost or stolen phones. Researchers found that…
Android Simplifies Secure Migration of Saved Logins
With the advent of Android’s new credential transfer feature, passwords and passkeys can be transferred directly between supported password managers…
South Korean Startup Suffers Breach Due to Encryption Management Failure
Modu-ui, a South Korean government backed startup support platform, suffered a data breach in July. The breach later disclosed a critical encoding key…
Study Warns Enterprise AI Rollouts Are Outpacing Data Security Checks
Companies are adopting AI tools faster than they are testing whether their underlying data is appropriately secure, a new report from governance firm…
Conti Ransomware Ties Lead to Four-Year Prison Sentence
Ukrainian nationals have been sentenced to four years in U.S. prison for participating in the Conti ransomware operation. Between 2020 and 2022, the…
Several Chinese Hacking Groups Observed Using Identical Chrome Zero-Day Exploit
Based on cybersecurity firm Proofpoint, four cyber-espionage groups, most of which are linked to Chinese state intelligence, have been exploiting the same…
Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer’s Personal Device
Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police…
GitLab’s Worst-Rated Vulnerability Is Already Being Exploited
GitLab on September 10 shipped emergency patches for a maximum-severity vulnerability that lets unauthenticated attackers read arbitrary files off a…
Google Play Early Access Exploited for Fake Reward Apps
Cybersecurity firm Bitdefender has unearthed a large-scale exploit of Google Play’s Early Access program, where attackers are distributing thousands of…
Attackers Use Expired Websites for Malware Scams
Dead websites may seem harmless once they are abandoned by their owners, but their old internet reputation can make them important tools for threat…
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company’s software…
Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots
Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker in close…
MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign
MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to…
US Disrupts Xinbi Guarantee Marketplace Linked to Cyber Scams
A Telegram-based marketplace known as Xinbi Guarantee has been sued by U.S. authorities for providing services to scam centers engaged in cyber fraud and…
Check Point Discloses Two Critical VPN Vulnerabilities Allowing RCE
Check Point has addressed two critical flaws in the way its management and firewall products manage VPN certificates. Both vulnerabilities have been…
Microsoft Tracks Cloud Intrusion Campaign Using Passkey Phishing and Graph API Abuse
Microsoft Security Research published a report on September 9, 2026, detailing active cloud-based intrusions spanning multiple accounts, in which unusual…
The Four-Character Password Guarding Your Company’s AI Keys
Security researchers at Wiz scanned 3,074 internet-facing deployments of LiteLLM in February and found something that should embarrass more than a few…
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud…