top of page

Latest Cyber Security NEWS

Fake Reservation Links Prey on Weary Travelers

Fake Reservation Links Prey on Weary Travelers

Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

No Perfect Fix for AI Browser Prompt Injection Flaws

No Perfect Fix for AI Browser Prompt Injection Flaws

AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

How legitimate cloud platforms enable phishers to bypass MFA

How legitimate cloud platforms enable phishers to bypass MFA

We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.

PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Toy Ghouls’ new toy: the GenieLocker ransomware

Toy Ghouls’ new toy: the GenieLocker ransomware

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research shows content inside an email can escape its message boundary and interfere with the webmail interface.

Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.

PortSwigger researcher Gareth

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

HelloNet campaign: new malicious modules launched through the ViPNet update system

HelloNet campaign: new malicious modules launched through the ViPNet update system

We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Twitter Whistleblower Complaint: The TL;DR Version

Twitter Whistleblower Complaint: The TL;DR Version

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671.

"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Researcher Claims Control of ChatGPT Secure Sandbox

Researcher Claims Control of ChatGPT Secure Sandbox

A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

AI-Generated Patches Fail Half the Time

AI-Generated Patches Fail Half the Time

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Ransomware Attacks are on the Rise

Ransomware Attacks are on the Rise

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Growing Up The Hard Way

Growing Up The Hard Way

Open Source had a great childhood.

For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.

Then,

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Firewall Bug Under Active Attack Triggers CISA Warning

Firewall Bug Under Active Attack Triggers CISA Warning

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

A new extortion cocktail: office printers, small ransoms, and BitLocker

A new extortion cocktail: office printers, small ransoms, and BitLocker

We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.

"

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.

"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses

Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

CSS: The Hidden Threat Lurking in Your Inbox

CSS: The Hidden Threat Lurking in Your Inbox

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

An analysis of incidents at Brazilian educational institutions

An analysis of incidents at Brazilian educational institutions

Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

iPhone Users Urged to Update to Patch 2 Zero-Days

iPhone Users Urged to Update to Patch 2 Zero-Days

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Google Patches Chrome’s Fifth Zero-Day of the Year

Google Patches Chrome’s Fifth Zero-Day of the Year

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Mirage Kitten targets Middle East and Africa region with new malware

Mirage Kitten targets Middle East and Africa region with new malware

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

AI titans to tidy agent frontier with plugin prescription

AI titans to tidy agent frontier with plugin prescription

Agent Plugins 1.0 defines a write-once-run-anywhere container for passing tools and skills across different agent platforms

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

AI Sends Global Crime Syndicates Into Fraud Nirvana

AI Sends Global Crime Syndicates Into Fraud Nirvana

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Watering Hole Attacks Push ScanBox Keylogger

Watering Hole Attacks Push ScanBox Keylogger

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks

Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks

Calling all defenders

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Student Loan Breach Exposes 2.5M Records

Student Loan Breach Exposes 2.5M Records

2.5 million people were affected, in a breach that could spell more trouble down the line.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

Network Anomaly Detection in KATA

Network Anomaly Detection in KATA

An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.

"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said.

"This is not a duplicate of our

Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)

Read Full Article @

Date Published:

bottom of page