For you Ai Security Dev Cloud Hardware Startups Releases General

Security · Top stories

1 source 1 report 3d ago

F5 Releases Patches for Critical NGINX Vulnerability Allowing Remote Code Execution

F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.

security nginx vulnerability patches
1 source 1 report 3d ago

Texas Police Acquire FalcoNet Surveillance System for $4.5 Million

Texas State Police purchased four FalcoNet-equipped Chevrolet Tahoes for $4.5 million to enhance surveillance capabilities. This technology, capable of intercepting mobile phone communications, raises significant concerns over privacy and data collection on civilians.

security surveillance privacy law enforcement technology
1 source 1 report 3d ago

Hackers Target Russian Government Agencies via ViPNet Software Abuse

A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.

security malware russia cybersecurity APT
1 source 1 report 3d ago

Fraudsters Target X Accounts with Fake Login Alerts

Fraudulent emails impersonating X notify users of suspicious logins from unfamiliar devices. Clicking links in these emails can lead to credential theft, putting users' accounts at risk for scams.

security scams email phishing
3 sources 3 reports 5d ago

Florida Man Arrested for Cryptocurrency Theft via Steam Game Malware

Zyaire Wilkins was arrested for allegedly using malware-laden games on Steam to steal $220,000 in cryptocurrency. The operation infected about 8,000 devices and targeted 80 crypto wallets from May 2024 to February 2026. This highlights security risks in digital distribution platforms like Steam.

security malware cryptocurrency law enforcement crypto
1 source 1 report 1d ago

OpenAI and Hugging Face Report Security Incident in Model Evaluation

OpenAI and Hugging Face confirmed a security incident during the evaluation of machine learning models. This incident emphasizes the need for robust security measures in AI development environments.

security openai huggingface ai
3 sources 3 reports 6d ago

Claude for Chrome Vulnerability Exposes User Data to Rogue Extensions

A vulnerability in Claude for Chrome allows rogue extensions to trigger sensitive tasks without user consent. Discovered by Manifold Security, the flaw enables malicious extensions to access Gmail, Google Docs, Calendar, and Salesforce, posing a significant security risk. This issue persists in version 1.0.80, with no current patch.

security chrome vulnerabilities data exposure cloud
1 source 1 report 3d ago

Analysts Raise Concerns Over Cybersecurity Risks of Over-the-Air Tech in Automobiles

The growing use of over-the-air (OTA) technology in vehicles poses cybersecurity risks, with analysts urging intervention. This technology, while efficient for vehicle updates, may expose automotive systems to potential foreign cyber threats and national security issues.

security cybersecurity automotive ota nationalsecurity
3 sources 3 reports 6d ago

Zoom Patches Critical Vulnerability Allowing Account Takeovers

Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows applications, rated 9.8 on the CVSS scale, which enabled potential account takeovers. The flaw affected Zoom Workplace, Zoom VDI Client, and Zoom Meeting SDK for Windows prior to version 7.0.0. This vulnerability impacts user security and necessitates immediate updates to prevent unauthorized account access.

security zoom vulnerability account takeover windows
3 sources 3 reports 6d ago

Microsoft Revokes Vulnerable UEFI Shims Allowing Secure Boot Bypass

Microsoft has revoked the signatures of 11 old UEFI shims signed by them, which could bypass Secure Boot on Windows and Linux systems. This security flaw, discovered by ESET, existed due to old firmware remaining signed and trusted despite vulnerabilities. Addressing this issue is critical for preventing the unauthorized execution of code during the system boot process.

security uefi malware secure boot microsoft
2 sources 2 reports 2d ago

Craneware Reports Data Breach Affecting US Hospitals and Pharmacies

Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.

security data breach healthcare cybersecurity Craneware
2 sources 2 reports 2d ago

Hacker Attack Disrupts Romania's Land Registry Operations

Romania's land registry agency suffered a cyberattack, resulting in the wiping of its database and a halt in real estate transactions. The agency is migrating its systems to the government cloud to restore operations while ensuring data integrity.

security hacking data breach romania real estate
2 sources 2 reports 2d ago

Russian Hackers Use Security Cameras to Monitor NATO and Ukrainian Military Movements

Russian intelligence services are using internet-connected security cameras across Ukraine and NATO states to gather military intelligence. This operation involves exploiting cameras with default settings or security flaws, collecting data on military logistics and weapon shipments, and targeting Ukrainian troops. The breaches pose serious security risks across Europe and Ukraine.

security cybersecurity espionage NATO Ukraine
3 sources 3 reports 7d ago

Critical Vulnerability in Cursor IDE Allows Arbitrary Code Execution on Windows

A vulnerability in Cursor IDE enables arbitrary code execution by executing malicious git binaries in project roots. Reported by Mindgard in December 2025, the issue remains unpatched, affecting over 7 million users. The flaw involves Cursor executing 'git.exe' files in repository roots without user interaction, posing significant security risks.

security cursor vulnerability development git
3 sources 5 reports 7d ago

Progress Software Confirms Zero-Day Vulnerability in ShareFile Storage Zone Controllers

Progress Software advised ShareFile users to shut down Storage Zone Controllers due to a zero-day vulnerability. The high-severity path traversal flaw, affecting versions 5.x and 6.x, led to precautionary account access suspension and patches release. No customer data compromise has been reported.

security cloud general sharefile software
3 sources 4 reports 7d ago

xAI's Grok CLI Tool Exposed for Uploading Entire Repositories Without Consent

xAI's Grok Build CLI tool was found transmitting entire code repositories, including sensitive files, to its cloud storage, causing privacy concerns. After researcher cereblab's disclosure, xAI altered the tool silently. Elon Musk said all uploaded data would be deleted to maintain privacy standards.

security grok xai data privacy dev
3 sources 4 reports 7d ago

Microsoft 365 Users Targeted in Voice Phishing Campaign for Fake Entra Passkey Enrollment

A voice phishing campaign is exploiting Microsoft 365 users to unwittingly enroll fake Entra passkeys, giving attackers unauthorized account access and facilitating potential data extortion. Initiated by the group O-UNC-066, the campaign began in April and spans multiple industries, highlighting vulnerabilities in the passkey adoption process Microsoft implemented. Okta reported the attacks, which utilize convincing phishing kits mimicking Microsoft's passkey enrollment portal.

security microsoft phishing cybersecurity passkey
3 sources 3 reports 8d ago

US and Allied Nations Warn of Russian Router-Based Cyberattacks on Critical Infrastructure

US and several allied nations have issued a warning regarding Russian state-backed attempts to exploit poorly secured routers to breach critical infrastructure. The FSB's hacking groups target sectors including energy, healthcare, and communications by using known vulnerabilities and SNMP exploits. The warning underscores the need for immediate security enhancements in affected sectors.

security cybersecurity russia infrastructure attacks
3 sources 3 reports 8d ago

U.S. Sanctions VPN and Malware Providers for Ransomware Support

The U.S. Treasury sanctioned First VPN Service and its administrator for aiding ransomware activities against American infrastructure. Ukrainian Dmytro Rashevskyi, associated with the VPN, and Belarusian Yegeniy Silayev, a cryptor seller, were named in the sanctions. The sanctions prevent U.S. entities from transacting with them, underscoring a broader crackdown on cybercriminal support networks.

security vpn ransomware cybersecurity government
3 sources 3 reports 9d ago

UK and EU Sanction Russia's FSB and GRU for Cyberattacks Involving Critical Infrastructure

The UK and EU have imposed joint cyber sanctions targeting Russia's FSB and GRU following a cyberattack on Poland's energy grid that nearly caused a major blackout last winter. The coordinated sanctions, the first of their kind, address ongoing Russian-led cyber espionage campaigns against EU member states. These actions reflect growing international concerns regarding Russia's capacity to destabilize Europe’s critical infrastructure.

security russia cybersecurity sanctions poland
3 sources 3 reports 11d ago

China and India-Linked Hackers Infiltrate Balochistan Police Networks

Chinese and Indian cyberespionage groups targeted the Balochistan Police from February 2024 to April 2026. The attackers accessed sensitive systems, including biometric data and criminal records. This exposes significant regional security vulnerabilities tied to geopolitical tensions.

security cybersecurity espionage malware regional-tensions
3 sources 3 reports 11d ago

Symlink Vulnerability in AI Coding Assistants Poses Security Threat

Researchers discovered that a vulnerability in six AI coding assistants allows malicious repositories to execute code on developers' machines. By exploiting symbolic link (symlink) flaws, attackers could bypass user consent and access sensitive files, raising significant security concerns.

security ai dev coding vulnerability
3 sources 7 reports 11d ago

Critical Linux Kernel Vulnerabilities: DirtyClone, Bad Epoll, and GhostLock

Three critical Linux kernel vulnerabilities, DirtyClone (CVE-2026-43503), Bad Epoll (CVE-2026-46242), and GhostLock (CVE-2026-43499), have been disclosed, each allowing privilege escalation. DirtyClone targets cloned network packets, Bad Epoll exploits a race condition, while GhostLock leverages a 15-year-old use-after-free flaw. Each vulnerability has a patch available, emphasizing the need for prompt system updates to mitigate exploitation risks.

security linux vulnerability kernel malware
3 sources 7 reports 12d ago

EU Parliament Revives Chat Control 1.0 Allowing CSAM Scans Until 2028

The European Parliament has approved a procedure to revive the expired 'Chat Control 1.0' regulation, permitting tech companies to scan digital communications for child sexual abuse material (CSAM) until 2028. Despite previous rejections, the law was reinstated through a legal maneuver requiring an absolute majority to block it. The regulation raises significant privacy concerns, but excludes encrypted messaging services.

security eu privacy regulations child_protection
3 sources 3 reports 12d ago

Critical Gitea Docker Vulnerability CVE-2026-20896 Faces Active Exploitation

Gitea Docker images are subject to a critical authentication bypass vulnerability (CVE-2026-20896) now under active exploitation. The flaw allows attackers to impersonate any user, including administrators, via reverse proxy authentication with default configurations. It affects versions before 1.26.3 and about 6,200 instances globally.

security devops docker vulnerabilities gitea
3 sources 3 reports 13d ago

Microsoft Utilizes AI to Enhance Windows Security Updates Frequency and Efficiency

Microsoft announced the integration of AI to improve the frequency and effectiveness of Windows security updates. Using advanced AI models, Microsoft seeks to accelerate the detection of vulnerabilities in its codebase. This change aims to improve protections against increasingly AI-driven cyber threats.

security microsoft windows ai
3 sources 3 reports 13d ago

12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability

KDDI, a major Japanese telecom provider, confirmed a breach affecting 12.2 million email addresses and 7.6 million passwords via a compromised email system used by five ISPs. The breach exploited a zero-day vulnerability in third-party software. KDDI has implemented security measures and coordinated password resets to prevent future incidents.

security cybersecurity data breach kddi japan
3 sources 3 reports 14d ago

DuckDuckGo Browser Now Blocks YouTube Video Ads Using Community Filters

DuckDuckGo has released a feature that blocks video ads, including those on YouTube, on its browser. This feature, based on community-maintained filter lists and additional rules for compatibility, is enabled by default on iOS, Windows, and Mac, with Android support to follow. Users can enjoy ad-free video playback while maintaining privacy, but may experience longer buffering times.

security duckduckgo youtube adblocking browsers
3 sources 3 reports 14d ago

Chinese APT UAT-7810 Develops New Malware to Expand ORB Network

Chinese APT group UAT-7810 has advanced its Operational Relay Box (ORB) network with new malware, including LONGLEASH, DOGLEASH, and JARLEASH. These tools exploit known router vulnerabilities to enhance the group's cyber espionage capabilities, posing potential risks to critical infrastructure.

security malware cybersecurity threat UAT-7810
3 sources 3 reports 14d ago

GitHub Agentic Workflows Vulnerable to Prompt Injection, Exposing Private Repos

Noma Labs identified a prompt injection vulnerability, named GitLost, in GitHub's Agentic Workflows, enabling data leaks from private repositories. Attackers can manipulate AI agents to disclose private content through crafted public issues. This highlights security concerns in using AI-driven workflows in GitHub's system.

security github ai data leakage vulnerability
3 sources 3 reports 15d ago

Discord Bug Mistakenly Bans Over 8,000 Accounts for Harmless Images

Discord experienced a glitch in its AI moderation system that mistakenly banned over 8,000 users for posting harmless images since May 2026. The system inaccurately flagged grid-like images as harmful content, impacting accounts posting items like spreadsheets and game textures. Discord has resolved the issue and unbanned affected users.

security discord bans content moderation safety system
3 sources 3 reports 16d ago

Medtronic Hack Exposes Data of Nearly 4 Million People in ShinyHunters Breach

Medtronic suffered a data breach in April 2026, compromising the personal and medical information of over 3.8 million individuals, with some sources claiming 9 million records affected. The ShinyHunters group accessed Medtronic's corporate IT systems, despite the company's reassurance about device safety. Medtronic is offering credit monitoring and support services to those impacted, highlighting security vulnerabilities in healthcare technology.

security data breach healthcare cybersecurity shinyhunters
3 sources 3 reports 20d ago

FortiBleed Campaign Compromises Fortinet Devices, Linked to Ransomware Groups

The FortiBleed campaign has been connected to the INC and Lynx ransomware groups, compromising credentials from Fortinet devices. Researchers found the operation entailed scanning 11,250 FortiGate portals and compromised 354 targets, leading to 12 ransomware deployments. The breach highlights significant cybersecurity risks, affecting organizations globally.

security ransomware credential-theft fortinet fortibleed
2 sources 2 reports 2d ago

7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing

7-Zip released version 26.02 to address a remote code execution (RCE) vulnerability linked to XZ-compressed data. Discovered by Lunbun researcher Landon Peng, the flaw could be exploited if a user opened a specially crafted archive. This highlights the need for manual updates due to 7-Zip's lack of an automatic update feature, emphasizing user awareness and action.

security 7-zip vulnerability rce xz-archive
1 source 1 report 4d ago

TP-Link Kasa cameras leaked GPS for six years; vulnerabilities now patched

TP-Link's Kasa Spot EC71 cameras exposed home GPS data via unauthenticated UDP for six years. A patch in firmware version 2.4.1 remedied significant security vulnerabilities that compromised user data.

security tp-link gps kasa
1 source 1 report 5d ago

Seven Malicious Vite npm Packages Employ Blockchain C2 for RAT Delivery

Seven malicious npm packages targeting the Vite ecosystem have been uncovered, linked to a software supply chain attack dubbed ViteVenom. The packages employ a complex blockchain-based command-and-control system, enhancing their stealth and effectiveness in delivering a remote access trojan.

security npm vite malware
1 source 1 report 5d ago

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials

NadMesh, a Go botnet, was discovered targeting exposed AI services in cloud environments, claiming over 3,800 AWS keys. The botnet systematically scans platforms like ComfyUI and n8n to extract cloud credentials and Kubernetes tokens, posing significant security risks to cloud deployments and AI tools.

security botnet cloud
1 source 1 report 5d ago

DigiCert Breach Attributed to GoldenEyeDog Subgroup and Code-Signing Theft

The April 2026 security incident at DigiCert has been linked to the GoldenEyeDog subgroup, CylindricalCanine, which stole code-signing certificates. This breach highlights vulnerabilities in digital certificate management and raises concerns about the integrity of software distribution.

security cybersecurity malware threats digicert
2 sources 4 reports 2d ago

Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security

Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.

security chrome vulnerabilities google browser
1 source 1 report 5d ago

GoSerpent Malware Targets Southeast Asian Governments for Espionage

A new malware, GoSerpent, has been identified targeting Southeast Asian governments and diplomats since late 2025 for espionage. Discovered by Kaspersky, it aims to gather intelligence through tools for credential dumping and data exfiltration, posing a significant threat to sensitive government operations.

security malware cybersecurity espionage government
More stories →