Information security

[ follow ]
Information security
fromThe Hacker News
1 hour ago

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

AI chatbot queries can be used to deliver cryptojacking payloads by steering users to attacker-controlled download sites that impersonate legitimate utilities.
#ai-security
Information security
fromSilicon Canals
2 hours ago

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards - Silicon Canals

Security and governance must be built into AI and data platforms from the start, not added afterward, as real incidents show ongoing API key and billing risks.
Information security
fromDevOps.com
18 hours ago

Perplexity Bumblebee Shakes Loose Hidden Threats on Dev Desktops - DevOps.com

Bumblebee is a read-only scanner that checks developer Linux and macOS machines for known vulnerable packages, extensions, and AI tool configurations using a curated threat catalog.
Information security
fromtheregister
2 days ago

Anthropic to release Mythos-class models to the public

Mythos bug-finding AI remains restricted while stronger safeguards are developed, with expansion to government partners planned before general release.
fromInfoQ
2 days ago
Information security

Microsoft Introduces MDASH for Large-Scale AI Vulnerability Research

Information security
fromSilicon Canals
2 hours ago

A Google Cloud developer woke up to a $17,000 bill from API calls he never made, and the part that actually matters is what it reveals about how cloud platforms define their own security standards - Silicon Canals

Security and governance must be built into AI and data platforms from the start, not added afterward, as real incidents show ongoing API key and billing risks.
Information security
fromSecurityWeek
3 hours ago

Anthropic Releases New Claude Sandbox, Security Guidance Plugin

Claude AI adds a self-hosted sandbox for managed agents and a security guidance plugin that scans code edits and commits for vulnerabilities.
Information security
fromDevOps.com
18 hours ago

Perplexity Bumblebee Shakes Loose Hidden Threats on Dev Desktops - DevOps.com

Bumblebee is a read-only scanner that checks developer Linux and macOS machines for known vulnerable packages, extensions, and AI tool configurations using a curated threat catalog.
Information security
fromwww.techzine.eu
22 hours ago

Fortinet strengthens partnership with Nvidia

FortiAIGate integrates with Nvidia AI infrastructure to provide runtime, zero-trust security for AI workloads, monitoring agents and LLM traffic with minimal latency.
Information security
fromtheregister
2 days ago

Anthropic to release Mythos-class models to the public

Mythos bug-finding AI remains restricted while stronger safeguards are developed, with expansion to government partners planned before general release.
Information security
fromInfoQ
2 days ago

Microsoft Introduces MDASH for Large-Scale AI Vulnerability Research

MDASH is a multi-agent, model-agnostic AI system that automates large-scale vulnerability discovery, validation, and proof generation across Microsoft codebases.
Information security
fromTechzine Global
1 hour ago

Vulnerability in open-source component puts AI platforms at risk

CVE-2026-48710 in Starlette enables HTTP Host header manipulation to bypass access controls, risking internal server exposure and credential access for AI agents.
#c
Information security
fromTechzine Global
1 hour ago

Microsoft is tightening restrictions on the use of unsafe code in C#

Unsafe in C# will become an explicit, propagating contract requiring unsafe operations to be contained in unsafe blocks and declared at method boundaries.
Information security
fromtheregister
17 hours ago

Microsoft wants safer C# without turning it into Rust

C# 16 will redefine unsafe so it propagates requires-unsafe to callers, improving memory safety while keeping automatic memory management.
Information security
fromTechzine Global
1 hour ago

Microsoft is tightening restrictions on the use of unsafe code in C#

Unsafe in C# will become an explicit, propagating contract requiring unsafe operations to be contained in unsafe blocks and declared at method boundaries.
Information security
fromtheregister
17 hours ago

Microsoft wants safer C# without turning it into Rust

C# 16 will redefine unsafe so it propagates requires-unsafe to callers, improving memory safety while keeping automatic memory management.
Information security
fromComputerWeekly.com
1 hour ago

The Gentlemen emerging as key ransomware player | Computer Weekly

The Gentlemen ransomware gang is rapidly evolving into a RaaS operation using advanced encryption and affiliate proxy malware to scale extortion attacks across platforms.
#cybercrime
Information security
fromSecurityWeek
1 hour ago

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

Silent Ransom Group impersonates IT support to gain remote access, exfiltrate data, and extort victims after phishing and social engineering attacks.
Information security
fromSecurityWeek
5 days ago

'First VPN' Cybercrime Service Disrupted, Administrator Arrested

Law enforcement disrupted First VPN, a cybercrime service used for ransomware and intrusions, dismantling servers, arresting an alleged administrator, and notifying 506 users.
Information security
fromSecurityWeek
1 hour ago

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

Silent Ransom Group impersonates IT support to gain remote access, exfiltrate data, and extort victims after phishing and social engineering attacks.
Information security
fromSecurityWeek
5 days ago

'First VPN' Cybercrime Service Disrupted, Administrator Arrested

Law enforcement disrupted First VPN, a cybercrime service used for ransomware and intrusions, dismantling servers, arresting an alleged administrator, and notifying 506 users.
#cve-2026-48172
Information security
fromSecurityWeek
3 hours ago

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

CVE-2026-48172 in LiteSpeed cPanel user-end plugin is actively exploited and enables root-level script execution; patch to 2.4.5+ or remove plugin immediately.
Information security
fromThe Hacker News
4 days ago

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

LiteSpeed LiteSpeed User-End cPanel Plugin CVE-2026-48172 enables arbitrary root script execution and is actively exploited; upgrade or uninstall to remediate.
Information security
fromSecurityWeek
3 hours ago

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

CVE-2026-48172 in LiteSpeed cPanel user-end plugin is actively exploited and enables root-level script execution; patch to 2.4.5+ or remove plugin immediately.
Information security
fromThe Hacker News
4 days ago

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

LiteSpeed LiteSpeed User-End cPanel Plugin CVE-2026-48172 enables arbitrary root script execution and is actively exploited; upgrade or uninstall to remediate.
fromTechzine Global
27 minutes ago

Windows Server 2016 fails to find domain controller

When the hostname is 15 characters long, DCLocator calls (for example, using nltest /dsgetdc:<domain> /pdc) will return ERROR_INVALID_PARAMETER, preventing applications and administrative tools from locating a domain controller.
Information security
Information security
fromComputerworld
8 hours ago

Microsoft previews automatic device isolation in Defender for Endpoint

Automatic device isolation in Defender for Endpoint can rapidly cut off attacks, but must be carefully tuned to prevent attackers from disabling accounts.
fromwww.bbc.com
9 hours ago

Champion ethical hacker warns AI tools like Mythos could put her out of business

Valentina Palmiotti, better known as Chompie, was the most successful individual at the annual Pwn2Own hacking competition in Berlin. She told BBC News that, for now, AI tools were helping her to win “bug bounties” - money given to hackers who spot vulnerabilities in online systems before they can be exploited by cyber-criminals. But she said systems like Mythos were so powerful that even champion hackers like her would soon struggle to compete with them.
Information security
Information security
fromThe Hacker News
22 hours ago

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

Push-based MFA can be bypassed when attackers repeatedly trigger prompts and socially engineer approval, gaining access without stealing the second factor.
#cybersecurity
Information security
fromThe Hacker News
23 hours ago

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

Patch critical vulnerabilities in internet-exposed systems within 12 hours when feasible to reduce AI-enabled cyber exploitation speed and autonomy.
fromTechCrunch
18 hours ago
Information security

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover | TechCrunch

fromTNW | Anthropic
3 days ago
Information security

Anthropic's Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can't keep up.

Information security
fromThe Hacker News
23 hours ago

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

Patch critical vulnerabilities in internet-exposed systems within 12 hours when feasible to reduce AI-enabled cyber exploitation speed and autonomy.
Information security
fromArs Technica
14 hours ago

Millions of AI agents imperiled by critical vulnerability in open source package

BadHost in Starlette enables trivial HTTP Host header injection to bypass path-based authorization, exposing AI tooling servers and stored third-party credentials.
Information security
fromTechCrunch
18 hours ago

Ghost hackers: the cybersecurity mystery that nobody has solved | TechCrunch

Shadow Brokers leaked alleged NSA hacking tools and vanished, leaving many motives and culprits unknown despite later arrests of other hacking groups.
fromTechCrunch
18 hours ago
Information security

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover | TechCrunch

Information security
fromWIRED
1 day ago

The AI Era Is Creating a Bug Hunting Arms Race

Criminal actors dominate most security incidents, while AI-driven bug reports are reshaping vulnerability reward programs and mailing lists through quality and volume changes.
Information security
fromTNW | Anthropic
3 days ago

Anthropic's Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can't keep up.

Project Glasswing found 10,000+ high-severity vulnerability candidates in critical software, but only 97 were patched, showing remediation lags discovery by orders of magnitude.
Information security
fromwww.itpro.com
1 day ago

Does your business need a software bill of materials?

SBOMs provide an inventory of software components to quickly identify exposure and patch vulnerabilities across complex software supply chains.
Information security
fromthehackernews.com
21 hours ago

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

A SharePoint remote code execution flaw (CVE-2026-45659) can be triggered by authenticated attackers with Site Member permissions and requires no elevated privileges.
Information security
fromSecurityWeek
20 hours ago

AppOmni's Marlin AI Brings Autonomous Investigation to SaaS Security

SaaS security depends mainly on app configuration, and standard controls and tools often fail because SaaS runs on providers’ infrastructure and is used differently by each customer.
Information security
fromThe Hacker News
1 day ago

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

Nimbus Manticore used AI-assisted MiniFast backdoor and updated tradecraft, including AppDomain hijacking and SEO poisoning, targeting aviation and software organizations across multiple regions.
Information security
fromComputerworld
23 hours ago

FAQ: What you need to know about expiring Windows Secure Boot certificates

Secure Boot certificates issued in 2011 are expiring starting June, requiring Windows devices to install newer Microsoft certificates to maintain trusted boot security.
Information security
fromThe Hacker News
1 day ago

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

Hard-coded ASP.NET machine keys enabled unauthenticated ViewState deserialization, allowing zero-day exploitation to deploy Godzilla web shells and Cobalt Strike Beacon.
Information security
fromSecurityWeek
22 hours ago

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

A KnowledgeDeliver ASP.NET zero-day enabled ViewState deserialization using hardcoded machineKey values, leading to web shells, Godzilla malware, and Cobalt Strike backdoors.
#supply-chain-attacks
Information security
fromnews.bitcoin.com
1 day ago

Trapdoor Malware: The Massive Supply Chain Attack Targeting Crypto Developers

Trapdoor supply-chain malware infected 34 crypto-related developer packages across npm, PyPI, and Crates.io to steal wallets, keys, and secrets, including via AI tool manipulation.
Information security
fromtheregister
4 days ago

Megalodon chums the waters in 5.5K+ GitHub repo poisonings

Megalodon injected CI/CD credential-stealing malware into thousands of GitHub repositories, enabling attackers to steal cloud keys, tokens, and secrets and impersonate developers.
Information security
fromTechzine Global
5 days ago

GitHub investigates attack via malicious VS Code extension

A malicious VS Code extension likely enabled unauthorized access to GitHub internal repositories, with no confirmed customer data compromise yet.
Information security
fromSecurityWeek
5 days ago

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Unauthorized access to Grafana Labs GitHub repositories resulted from a TanStack supply chain attack, leading to token compromise, code theft, and mitigations without customer production impact.
Information security
fromnews.bitcoin.com
1 day ago

Trapdoor Malware: The Massive Supply Chain Attack Targeting Crypto Developers

Trapdoor supply-chain malware infected 34 crypto-related developer packages across npm, PyPI, and Crates.io to steal wallets, keys, and secrets, including via AI tool manipulation.
Information security
fromtheregister
4 days ago

Megalodon chums the waters in 5.5K+ GitHub repo poisonings

Megalodon injected CI/CD credential-stealing malware into thousands of GitHub repositories, enabling attackers to steal cloud keys, tokens, and secrets and impersonate developers.
Information security
fromTechzine Global
5 days ago

GitHub investigates attack via malicious VS Code extension

A malicious VS Code extension likely enabled unauthorized access to GitHub internal repositories, with no confirmed customer data compromise yet.
Information security
fromSecurityWeek
5 days ago

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Unauthorized access to Grafana Labs GitHub repositories resulted from a TanStack supply chain attack, leading to token compromise, code theft, and mitigations without customer production impact.
Information security
fromSecurityWeek
20 hours ago

Iranian APT Targets Aviation, Software Companies With Updated Tools

Nimbus Manticore updated phishing and payload execution methods, using AppDomain hijacking and new backdoors to target aviation and software organizations.
Information security
fromwww.ynetnews.com
5 years ago

State comptroller: Israel unprepared for major cyberattack as ministries lag on defenses

Emergency agencies were not properly prepared for cyberattack scenarios, and key cybersecurity guidelines were not distributed, contributing to major security incidents and persistent technological gaps.
Information security
fromNextgov.com
12 hours ago

Why compliance alone doesn't make federal networks secure

Zero Trust compliance mandates are increasing, but incomplete implementation—especially across IT and OT—creates exploitable gaps that adversaries use for lateral movement.
Information security
fromSecurityWeek
22 hours ago

Anthropic Expands Claude's Enterprise Security Governance With 28 New Integrations

Claude Enterprise now integrates with 28 security and compliance platforms via a Compliance API for governed monitoring and policy enforcement in corporate IT environments.
#ai-vulnerability-discovery
Information security
fromThe Hacker News
3 days ago

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Project Glasswing using Claude Mythos Preview identified 10,000+ high/critical vulnerabilities, yielding 1,726 true positives and 97 upstream patches.
Information security
fromThe Hacker News
3 days ago

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Project Glasswing using Claude Mythos Preview identified 10,000+ high/critical vulnerabilities, yielding 1,726 true positives and 97 upstream patches.
Information security
fromThe Hacker News
17 hours ago

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

MuddyWater used signed binaries for DLL side-loading, credential theft via ChromElevator, and Node.js-driven PowerShell discovery across nine countries in early 2026.
Information security
fromthenextweb.com
23 hours ago

Iran-linked hackers reached LA Metro's rail-yard control display in March, Israeli firm finds

Iranian-linked infrastructure was used in a March cyberattack that disrupted parts of LACMTA systems, with data traced to exposed files and prior Iranian campaigns.
#software-supply-chain-attacks
Information security
fromThe Hacker News
1 day ago

Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

A poisoned VS Code extension led to GitHub repository exfiltration, showing evolving software supply chain threats and smarter phishing and botnet activity.
fromArs Technica
4 days ago
Information security

A hacker group is poisoning open source code at an unprecedented scale

TeamPCP has carried out frequent software supply chain attacks by corrupting legitimate tools, including a GitHub breach via a poisoned VSCode extension, compromising thousands of repositories.
fromWIRED
6 days ago
Information security

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

Hackers used a poisoned VSCode extension to compromise thousands of GitHub repositories, spreading malware through open source tools and extorting victims.
Information security
fromThe Hacker News
1 day ago

Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

A poisoned VS Code extension led to GitHub repository exfiltration, showing evolving software supply chain threats and smarter phishing and botnet activity.
Information security
fromThe Hacker News
3 days ago

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

A supply-chain attack compromised multiple Laravel-Lang PHP packages to auto-execute a host-fingerprinting backdoor and download cross-platform credential-stealing payloads.
Information security
fromArs Technica
4 days ago

A hacker group is poisoning open source code at an unprecedented scale

TeamPCP has carried out frequent software supply chain attacks by corrupting legitimate tools, including a GitHub breach via a poisoned VSCode extension, compromising thousands of repositories.
Information security
fromWIRED
6 days ago

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

Hackers used a poisoned VSCode extension to compromise thousands of GitHub repositories, spreading malware through open source tools and extorting victims.
Information security
fromSecurityWeek
2 days ago

Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack

Megalodon used GitHub Actions workflow injection via automated commits to steal CI and cloud secrets from thousands of repositories.
#ghost-cms
Information security
fromThe Hacker News
1 day ago

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

A critical Ghost CMS SQL injection flaw enables unauthenticated attackers to steal admin API keys and inject malicious JavaScript for ClickFix poisoning.
Information security
fromSecurityWeek
1 day ago

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
Information security
fromThe Hacker News
1 day ago

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

A critical Ghost CMS SQL injection flaw enables unauthenticated attackers to steal admin API keys and inject malicious JavaScript for ClickFix poisoning.
Information security
fromSecurityWeek
1 day ago

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

CVE-2026-26980 SQL injection in Ghost has been exploited at scale to steal Admin API keys and inject malicious JavaScript into unpatched sites.
Information security
fromSecurityWeek
1 day ago

Laravel-Lang Packages Poisoned for Malware Delivery

Malicious Composer package tags were published for Laravel-Lang libraries, pointing to commits in a malicious fork and delivering credential-stealing malware.
Information security
fromSecuritymagazine
2 days ago

Weaponizing SBOMs: A Practical Guide for Security Practitioners

SBOMs provide precise visibility into software components, enabling faster vulnerability response, reduced attack surface, and more effective incident response and threat hunting.
Information security
fromFuturism
1 day ago

Riot Games Denies Using Anti-Cheat Software That Bricks Hackers' Computers

Vanguard targets DMA cheats without damaging hardware or disabling devices, but a PR post was misread as remote bricking.
Information security
fromFuturism
2 days ago

Hackers Find That Inaudible Sounds Hidden in Podcasts or Random Videos Can Hijack Your AI Voice Chatbot

Inaudible adversarial audio can be hidden in everyday media to trick voice AI into leaking or misusing personal data.
Information security
fromThe Verge
2 days ago

Hackers are learning to exploit chatbot 'personalities'

Jailbreaks can bypass AI safety by prompting systems to ignore rules, enabling harmful outputs like malware, meth recipes, and bomb-making guides.
Information security
fromSecurityWeek
3 days ago

'Underminr' Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

Underminr abuses shared CDN routing and TLS/Host mismatches to conceal malicious connections to hidden domains behind trusted front domains.
Information security
fromtheregister
3 days ago

Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend

AI-accelerated discovery and disclosure of Linux privilege-escalation bugs is increasing, with page-cache abuse enabling rapid, widely shared vulnerabilities across distros.
Information security
fromEngadget
3 days ago

Anthropic says Mythos has already found more than 10,000 vulnerabilities - Engadget

AI model Claude Mythos Preview finds thousands of vulnerabilities quickly, enabling Project Glasswing to accelerate bug discovery and patching while safeguards delay public release.
Information security
fromThe Hacker News
4 days ago

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

CISA added CVE-2026-9082, a Drupal Core SQL injection flaw, to KEV due to active exploitation evidence, urging rapid patching across supported versions.
#phishing
Information security
fromtheregister
4 days ago

FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale

Stolen Microsoft OAuth tokens from phishing kits can bypass MFA and grant attackers access to email and Teams accounts without credentials.
fromComputerworld
4 days ago
Information security

FBI warns of Kali Oauth stealers

Kali365 phishing uses a trusted cloud document email and a Microsoft code to grant attacker access to victims’ Microsoft accounts.
Information security
fromtheregister
4 days ago

FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale

Stolen Microsoft OAuth tokens from phishing kits can bypass MFA and grant attackers access to email and Teams accounts without credentials.
Information security
fromDevOps.com
5 days ago

Modernizing DevOps Security With Intelligent KYC Enforcement Layers - DevOps.com

DevOps security failures stem mainly from identity weaknesses, so continuous identity validation must be built into automated delivery pipelines.
Information security
fromSecurityWeek
4 days ago

In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking

Iranian hackers allegedly breached gas station tank gauge systems by exploiting unprotected internet-connected devices, altering display readings without changing fuel volumes.
Information security
fromThe Hacker News
4 days ago

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Megalodon used forged CI workflow commits to exfiltrate CI secrets, cloud credentials, tokens, keys, and configuration data from thousands of GitHub repositories within hours.
Information security
fromTechRepublic
4 days ago

Microsoft Warns: Windows Zero-Day 'YellowKey' Can Bypass BitLocker

Microsoft released a temporary mitigation for YellowKey, a Windows zero-day that can bypass BitLocker via WinRE, while a permanent fix is pending.
#ai-agents
Information security
fromtheregister
4 days ago

Minor edits to AI skills can make agents go rogue

AI agent skills can be weaponized through text-based prompt injection, expanding attack surfaces beyond code via online skill registries and loaded instructions.
Information security
fromDevOps.com
6 days ago

Microsoft Open-Sources RAMPART and Clarity to Bring Agent Safety Into the Dev Workflow - DevOps.com

AI agents now perform real actions across systems, requiring continuous safety engineering beyond one-time checks.
Information security
fromtheregister
4 days ago

Minor edits to AI skills can make agents go rogue

AI agent skills can be weaponized through text-based prompt injection, expanding attack surfaces beyond code via online skill registries and loaded instructions.
Information security
fromDevOps.com
6 days ago

Microsoft Open-Sources RAMPART and Clarity to Bring Agent Safety Into the Dev Workflow - DevOps.com

AI agents now perform real actions across systems, requiring continuous safety engineering beyond one-time checks.
#cisco-secure-workload
Information security
fromTechzine Global
5 days ago

Cisco Secure Workload vulnerability can be exploited via API call

A critical unauthenticated flaw in Cisco Secure Workload internal REST APIs grants full Site Admin privileges, enabling cross-tenant data access and configuration changes.
Information security
fromThe Hacker News
5 days ago

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

A maximum-severity flaw in Cisco Secure Workload allows unauthenticated remote attackers to access sensitive data and change configurations across tenant boundaries.
Information security
fromTechzine Global
5 days ago

Cisco Secure Workload vulnerability can be exploited via API call

A critical unauthenticated flaw in Cisco Secure Workload internal REST APIs grants full Site Admin privileges, enabling cross-tenant data access and configuration changes.
Information security
fromSecurityWeek
4 days ago

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

Drupal detects active exploitation attempts for CVE-2026-9082, a PostgreSQL-backed SQL injection flaw, and warns that attackers may quickly escalate from probing to impact.
Information security
fromSecuritymagazine
5 days ago

Why CISA Accepting KEV Nominations Is So Important

CISA will accept standardized public nominations for KEV catalog entries to improve early discovery, responsible communication, and rapid mitigation of exploited vulnerabilities.
Information security
fromTechzine Global
5 days ago

Zscaler acquires AI security firm Symmetry Systems

Zscaler acquires Symmetry Systems to add access graph technology that maps AI agent and application access, permissions used, and data flows for stronger Zero Trust security.
Information security
fromSecurityWeek
5 days ago

TrendAI Patches Apex One Zero-Day Exploited in the Wild

CVE-2026-34926 is a patched Apex One directory traversal flaw exploited in the wild, requiring admin access and affecting on-premises deployments.
Information security
fromtheregister
5 days ago

Cisco used AI to write security incident reports, with mixed results

Large language models can draft incident reports faster but can produce inaccuracies, hallucinations, and cross-contaminated content without careful prompting and controls.
Information security
fromThe Hacker News
4 days ago

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

Ghostwriter targets Ukrainian government organizations using Prometheus-themed phishing lures, delivering JavaScript that writes encrypted payloads, collects system data, and runs Cobalt Strike.
Information security
fromnews.bitcoin.com
4 days ago

Polymarket Suffers $700K Breach After Internal Admin Wallet is Compromised

Polymarket lost about $700K in POL after an internal private key compromise, but user funds and market resolution functions remain safe while keys are moved to KMS.
fromThe Hacker News
5 days ago

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

The impact is severe: successful exploitation not only compromises the Langflow instance but also exposes all sensitive access tokens and API keys stored within the workspace. This can trigger a cascading compromise across all integrated downstream services in cloud and SaaS environments.
Information security
Information security
fromThe Hacker News
4 days ago

Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective

Windows kernel driver vulnerabilities can remain reachable from user mode even without the original hardware, enabling exploitability evaluation for hardware-gated code.
fromtheregister
4 days ago

A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets

“We have reached an inflection point for cybercrime conspiracies,” Tom Kellermann, TrendAI's VP of AI security and threat research, told The Register, adding that “bandcampro's conspiracy underscores the sophistication of the Russian cybercriminal community and how weaponized jailbroken LLMs are manipulated to orchestrate a systemic cybercrime campaign.”
Information security
Information security
fromSecuritymagazine
6 days ago

Strategies, Expert Insights from the 2026 Verizon DBIR

Software vulnerabilities became the leading access method, mobile attacks rose, and generative AI is accelerating exploitation and expanding breach patterns.
Information security
fromThe Hacker News
5 days ago

ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

Attacks increasingly use trusted systems and normal workflows, with AI enabling faster, harder-to-detect intrusion tooling and tunneling into internal networks.
Information security
fromTechRepublic
5 days ago

New Verizon Report Reveals the Security Gap Attackers Are Exploiting Most

Vulnerability exploitation, AI-enabled attacks, third-party risk, and ransomware are driving breaches, while human error remains a major factor.
Information security
fromtheregister
5 days ago

Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw

Unauthenticated crafted API requests can grant Site Admin privileges, enabling cross-tenant data access and configuration changes in Cisco Secure Workload.
Information security
fromSecurityWeek
6 days ago

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

Velocity without visibility creates a supply chain cybersecurity crisis as exploitation outpaces patching and only a small subset of CVEs is truly exploitable.
Information security
fromSecurityWeek
6 days ago

Google's Surge in Chrome Vulnerability Discoveries Likely Driven by AI

Chrome vulnerability counts reported by Google surged from single digits to 100 within weeks, likely aided by AI-driven testing and remediation automation.
#microsoft-defender
Information security
fromThe Hacker News
5 days ago

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

Microsoft Defender privilege escalation and denial-of-service vulnerabilities are actively exploited, and fixes are available via updated Defender Antimalware Platform versions and definition updates.
Information security
fromSecurityWeek
6 days ago

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Microsoft released patches for two Microsoft Defender vulnerabilities exploited in the wild, adding them to CISA’s KEV list with a June 3 patch deadline.
Information security
fromThe Hacker News
5 days ago

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

Microsoft Defender privilege escalation and denial-of-service vulnerabilities are actively exploited, and fixes are available via updated Defender Antimalware Platform versions and definition updates.
Information security
fromSecurityWeek
6 days ago

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Microsoft released patches for two Microsoft Defender vulnerabilities exploited in the wild, adding them to CISA’s KEV list with a June 3 patch deadline.
Information security
fromtheregister
5 days ago

Microsoft storms RAMPART, adds Clarity to agentic AI safety

RAMPART and another open-source tool help teams test, measure, and mitigate risks in agentic AI through automated red-teaming in CI/CD pipelines.
Information security
fromTechRepublic
6 days ago

Microsoft Disrupts Malware-Signing Service Used by Ransomware Gangs

Fox Tempest abused Azure Artifact Signing to generate fraudulent code-signing certificates, enabling malware and ransomware to appear trusted and evade defenses.
Information security
fromThe Hacker News
5 days ago

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Showboat is a modular Linux post-exploitation malware used against a Middle East telecom provider, providing remote shell, file transfer, and SOCKS5 proxy capabilities.
Information security
fromtheregister
5 days ago

Npm registry sets stage for more secure package publishing

GitHub added staged (gated) publishing for npm packages, requiring maintainer review and 2FA approval before staged releases become public.
[ Load more ]