ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
Hackers Breach Polish Medical Software Firm Qbusoft, Expose Patient Data in Second Healthcare Attack in Weeks
A cyberattack on Polish healthcare software company Qbusoft has left patient records from its Medyc platform potentially in the hands of attackers, coming…
DC Health Agency Data Exposure Affects Nearly 400,000 Medicaid Beneficiaries
Almost 400,000 people who enrolled in Medicaid and the DC Healthcare Alliance may have been affected by a data breach, which occurred on the website of…
NVIDIA Unveils Layered Security Architecture for AI Agents
NVIDIA has introduced the Open Agent Safety Platform as a security architecture for controlling autonomous AI agents from testing through deployment.…
NeedyMantis Malware Expands the Post-Compromise Threat Landscape
A modular malware family dubbed NeedyMantis has been identified by Microsoft Threat Intelligence, and has been employed to maintain access to compromised…
Citrix NetScaler Zero-Days Exploited in Attacks
Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are reportedly being exploited in the wild, raising serious…
File Notification APIs in Windows, Linux, and Android Are Leaking What You Do on Your Computer
A research team from Graz University of Technology in Austria has shown that a routine feature built into virtually every major operating system can be…
Singapore Expands AI Cybersecurity After UNC3886 Attacks
Singapore is changing its cybersecurity strategy after a state-sponsored cyber espionage group targeted the country’s four major telecommunications…
Supabase Misconfigurations Leave Customer Data Publicly Exposed
A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to…
Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
Secure file-sharing provider Kiteworks issued an urgent advisory urging customers to power down their servers for a six-hour window following credible…
x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining
A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks,…
Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea
Crypto exchange Bitget confirmed on September 25 that hackers stole approximately $387.5 million from its hot and warm wallets a day earlier, revising an…
Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction
A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which…
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
SolarWinds has issued security updates for two critical vulnerabilities in its Observability Self-Hosted product that could enable remote code execution…
Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other’s Leftover Disk Data
Cloudflare has patched a vulnerability in its Containers product that could have allowed a paying customer to pull residual data out of disk storage…
Astrana Health Data Breach Exposes Private and Confidential Information
In a cybersecurity incident, Astrana Health disclosed, attackers gained access to company servers and obtained confidential and private information. A…
CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting WSO2 and Adobe Commerce to its Known…
Check Point Warns of Active Exploitation of Two Critical Pre-Authentication Vulnerabilities
Check Point has issued urgent warnings to customers following the discovery of active attacks targeting two zero-day flaws in its products. The two…
Critical Roundcube Flaw Under Active Exploitation in Code Injection Attacks
A high-severity vulnerability in Roundcube Webmail, patched in May 2026, is now being actively exploited in code injection attacks, according to the…
How an OpenAI ‘agent’ hacked Australia’s Medicare and What that Means for Governments Worldwide
In June, OpenAI gave one of its AI agents a task so unremarkable it barely warranted attention: look up public data on Australian medicine spending. What…
