SolarWinds has issued an urgent security advisory for a high-severity vulnerability in its Access Rights Manager (ARM) product, tracked as CVE-2026-28326.…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
Gyazo Server Vulnerability Targeted to Steal Millions of User Records
Gyazo, an image-sharing platform, has confirmed a breach after attackers exploited a vulnerability in its upload server, gaining unauthorized access to…
Plugin4Shell: The Zero-Click Flaw That Broke Every Prominent AI Coding Agent at Once
The security promise was simple. A plugin marketplace reviews a piece of code, locks it to a specific, verified version, and every AI coding agent that…
Microsoft Fixes Critical Azure AI Flaw Rated CVSS 10.0
Microsoft has patched a maximum-severity vulnerability in Azure AI Foundry that could allow unauthorized attackers to escalate their privileges over a…
WeaselBiscuit Stealer Found in 13 Malicious npm Packages
Researchers have discovered 13 npm packages carrying a previously undocumented JavaScript information stealer called WeaselBiscuit, introducing yet…
RatHat Android Malware Uses AI to Control Infected Devices
A new Android backdoor called RatHat utilizes an AI-powered system to remotely navigate compromised devices, while also stealing sensitive information and…
Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files
Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its intended…
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s…
Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws
A major security update has been issued for Unbound, the widely used validating DNS resolver developed by NLnet Labs. On September 16, 2026, the project…
Cyberattack Knocks International Meteor Organization Website Offline
A cyberattack has forced the International Meteor Organization (IMO), one of the leading providers of meteor observation, to take much of the website…
Brevo Breach Exposes Customer Websites to ClickFix Malware
Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code…
Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix
Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname “ParaShells.” JFrog…
Cyberattack on Tanker Prompts Coast Guard-FBI Security Boarding
A tanker crossing the Gulf of Mexico was boarded by U.S. Coast Guard and FBI personnel last month after its onboard network came under attack from…
Vercel Sandbox Challenge Uncovers Linux Kernel Flaws
Vercel has conducted a two-week security challenge that has uncovered numerous vulnerabilities in the Linux kernel networking stack that is used by its…
US Lawmakers Raise Alarm Over Alleged Hacking by India-Based Firms
Three Indian-based companies have been accused of conducting hacking campaigns and stealing data from thousands of Americans and US businesses, according…
Acronis Discloses Actively Exploited Privilege Escalation Bug in Its cPanel Backup Plugin
Acronis has confirmed that attackers are actively exploiting a high-severity security flaw in its backup plugin for cPanel and WebHost Manager (WHM),…
Spanish Data Watchdog Publicises First AI Agent-Linked Data Breach Report
Spain’s data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial…
Homebrew 7.0.0 Ships With Fixes for Eight Security Advisories
Homebrew, a popular package manager for installing command-line tools and desktop apps on macOS and Linux, released version 7.0.0 on Sunday, with eight…
A $159 Circuit Board Just Broke Cloud Computing’s Strongest Security Guarantee
Security researchers have found a way to defeat the memory protections that Intel and AMD sell to cloud customers as their last line of defense against an…
Pro-Ukraine Hacking Cat Group Deploys New Malware Against Russian Targets
A pro-Ukraine hacktivist group known as Hacking Cat has significantly escalated its cyber operations against Russian targets by deploying newly developed…
