Unpatched vulnerabilities in OnePlus software can allow a malicious Android application to gain root-level control of affected devices without requesting…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
F5 Fixes BIG-IP APM Zero-Day Enabling Unauthenticated RCE
BIG-IP Access Policy Manager (APM) vulnerabilities have been patched by F5 as a result of zero-day attacks utilizing this vulnerability, which allows…
OAuth Phishing Attacks Bypass Passwords by Turning User Consent Into a Security Threat
Cybercriminals are targeting something more difficult to protect with traditional password advice: the user consent. New phishing techniques called OAuth…
GitLab Email Feature Exposes Critical Security Risk
GitLab’s “Email work item to this project” feature, intended to simplify issue creation, has been found to expose a serious security vulnerability that…
A Go Worm Stole MemTensor’s CI Tokens and Shipped Backdoored Packages to npm and PyPI
On September 23, 2026, an attacker spent roughly five hours poisoning two packages belonging to MemTensor, the company behind the MemOS operating system…
How We Got AD Admin In Red Teaming With GLM5.3 and RedactProxy
A client engaged us to red team their internal network. It was fully black box: zero input, no starting credentials, and no guidance on where to begin.…
BigCommerce Merchants Hit in Supply Chain Breach After Ribon App Credentials Were Stolen
BigCommerce has started alerting merchants that customer data was stolen from their stores after attackers got hold of API credentials belonging to Ribon,…
Arista Warns of Critical Actively Exploited VCO Vulnerability
Arista has published Security Advisory 0183 warning of a critical vulnerability in on-premises VeloCloud Orchestrator (VCO), tracked as CVE-2026-93952.…
Meta Muse Flaw Lets Attackers Hijack AI Assistant
The Muse artificial intelligence assistant from Meta has been found to be vulnerable to an attack which allows malicious software to redirect its…
Chinese Hackers Exploit ZyXEL Switch Flaw to Steal Data From Nearly 1,000 Devices
A Chinese threat actor has been using the recently discovered vulnerability in ZyXEL GS1900 switches to steal crucial information from the devices around…
Cyberattack Hits University of Munich, Exposing Student Data
Germany’s Ludwig Maximilian University of Munich (LMU) is investigating a significant cyberattack that potentially exposed sensitive student information,…
Foreign Hackers Got Into Two Colorado Water Systems, Messed With Pump Controls and Killed the Alarms
Foreign actors broke into the industrial control systems of two small private water utilities in Colorado last month, altered pumping cycles, changed…
STOMP Backdoor Uses PowerShell for Sensitive Data Theft
An advanced malware campaign known as TASK#STOMP has recently been discovered, which utilizes a PowerShell-based backdoor to collect business documents,…
TraderTraitor Mac Malware Targets IT Firm Through Weaponized Terraform Projects
A North Korean-linked cybercrime group known as TraderTraitor has tied another macOS infection in an IT services company with no cryptocurrency ties to…
Claude Code Glitch Erases Years of Bengaluru Heritage Data
A critical AI mishap has put years of digital heritage preservation at risk in Bengaluru, after an automated coding assistant inadvertently wiped out…
Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang
The extortion group ShinyHunters hacked the dark web leak site run by Clop, one of the most active ransomware operations in the world, defaced it with…
Researchers Escape OpenAI Codex Sandbox to Run Commands on Host
In OpenAI Codex, security researchers have identified two sandbox escape vulnerabilities, one of which allows developers to execute commands on their…
Four Linux Kernel Flaws Expose Systems to Local Root Exploits
A security researcher has publicly released working exploit code for four Linux kernel vulnerabilities that can allow local users to escalate their…
Critical Orkes Conductor Flaw Exploited for Unauthenticated Remote Code Execution
A critical vulnerability in Orkes Conductor is being actively exploited by attackers, potentially allowing them to execute arbitrary commands on…
An AI Helped Researchers Break Into OpenAI
A three-person security research team quietly walked into OpenAI’s internal infrastructure last July, submitted a pull request inside the company’s…
