For you Ai Security Dev Cloud Hardware Startups Releases General

Security · Top stories

2 sources 2 reports 11d ago

200 GitHub Repositories Used to Spread Malware in 'Operation Muck and Load'

A threat actor has leveraged 200 GitHub repositories to distribute malware in 'Operation Muck and Load'. The campaign uses a deceptive Go module posing as a DNS scanner, distributing over 700 malicious variants since January 2023 to execute spyware, trojans, and other malware. This highlights significant risks in software supply chain security.

security malware github threats goprog
2 sources 2 reports 12d ago

Six Vulnerabilities Found in U-Boot Bootloader Threaten Device Security at Boot

Six vulnerabilities in the U-Boot bootloader, used in devices from routers to servers, have been identified. These flaws enable attackers to execute arbitrary code or crash devices during boot, compromising security before the operating system verifies software. This poses significant risks due to U-Boot's widespread deployment in various embedded systems.

security firmware vulnerabilities u-boot
2 sources 2 reports 12d ago

Armenian Man Pleads Guilty to Involvement in Ryuk Ransomware Attacks

Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty in the US to charges related to deploying Ryuk ransomware. Extradited from Ukraine, Vardanyan facilitated attacks from November 2019 to April 2020, securing approximately $15 million in ransoms. His case underscores ongoing cybersecurity threats impacting various sectors.

security ransomware malware cybersecurity legal
2 sources 2 reports 12d ago

Injective SDK npm Package Compromised to Steal Cryptocurrency Keys

A version of the Injective SDK npm package was compromised, leading to the theft of cryptocurrency wallet private keys via a malicious version. Hackers accessed Injective Labs' GitHub to publish the harmful package, affecting developers in the decentralized finance space.

security crypto npm injective github
2 sources 2 reports 12d ago

Supreme Court Ruling on Location Data May Impact Automated License Plate Cameras

The Supreme Court's decision in Chatrie v. United States mandates warrants for cellphone location data, potentially affecting the use of automated license plate readers (ALPRs) like those used by Flock Safety. This could impose legal constraints on current law enforcement practices utilizing widespread ALPR networks without warrants. The case reflects broader privacy concerns about surveillance technologies and Fourth Amendment rights.

security privacy surveillance court law
2 sources 2 reports 12d ago

Dutch Police Probe Local Hackers in Odido Telecom Data Breach

The Dutch police are investigating local hackers in the February Odido data breach affecting 6.2 million customers. A suspect impersonated an Odido IT employee, facilitating unauthorized access through a customer contact system. Authorities are requesting public assistance to identify the caller.

security cybersecurity odido data breach dutch police
2 sources 2 reports 12d ago

AI Agents Expose Gaps in Enterprise Identity Governance Systems

AI agents are increasing machine identities in enterprises, highlighting gaps in identity governance. Traditional identity access management (IAM) systems were not designed for autonomous AI, often causing security risks due to over-privileged access. Addressing this issue is critical for secure enterprise operations.

security identitygovernance aiagents enterprises ai
2 sources 2 reports 12d ago

GigaWiper: New Sophisticated Windows Backdoor with Destructive Capabilities

Microsoft has uncovered GigaWiper, a sophisticated malware targeting Windows machines. This backdoor combines older destructive programs to offer disk wiping, fake ransomware, and spyware functions, showcasing a shift in wiper malware to extortion activities. Its likely connections to cyber threats against Israeli organizations highlight the need for vigilance and strong cyber defenses.

security malware gigaWiper cybersecurity spyware
2 sources 2 reports 13d ago

UK Unveils AI-Driven 'Cyber Shield' for Enhanced National Cybersecurity

The UK announced the Cyber Shield initiative to improve national cybersecurity through agentic AI systems. The initiative, led by the National Cyber Security Centre, focuses on countering advanced threats that exploit AI to rapidly identify vulnerabilities. This collaboration with academia and industry aims to hardwire AI advancements into national security defenses against increasingly sophisticated cyber threats.

security ai cyber defense cybersecurity government
2 sources 2 reports 13d ago

Mount Royal University Hit by Ransomware Attack, Data Stolen and Deleted

Mount Royal University in Calgary experienced a ransomware attack that led to the theft and deletion of student and employee data from its 'H drive' file storage systems. The CMD Organization, the group responsible for the attack, demanded a $1.9 million ransom for over 10 terabytes of data. This incident, impacting various university systems, emphasizes the ongoing risk of ransomware threats in the education sector.

security breach cybersecurity education data theft
2 sources 2 reports 13d ago

AssuranceAmerica Data Breach Exposes 6.9 Million Driver Records

AssuranceAmerica has suffered a data breach affecting 6.9 million individuals' driver’s license information, names, and contact details. Discovered on March 17, the breach is the largest known exposure of U.S. driver's license data this year, significantly impacting personal data security and prompting potential fraud concerns.

security data breach insurance privacy breach
2 sources 2 reports 14d ago

Suspected China-Linked Hackers Target Roundcube Vulnerabilities in U.S. and Canadian Universities

A China-linked threat group named UNK_MassTraction has exploited a critical Roundcube webmail vulnerability to infiltrate physics and engineering departments in U.S. and Canadian universities, stealing credentials and deploying malware. The targeted campaign, identified by Proofpoint, has significant implications for national security and academic research.

security cybersecurity vulnerabilities threat-actors higher-education
2 sources 2 reports 14d ago

Accenture Confirms Data Breach as Hacker Offers Source Code for Sale

Accenture has confirmed a data breach involving the theft of 35 GB of sensitive data, including source code and Azure credentials. A hacker is offering the data for sale, raising concerns about potential future exploitation. Accenture stated there is no impact on their operations and they have addressed the breach's source.

security accenture data breach cybersecurity hackers
2 sources 2 reports 14d ago

Ubiquiti Releases Critical Security Patch Updates for UniFi OS Suite

Ubiquiti has issued patches for seven critical vulnerabilities in its UniFi OS software suite, affecting applications like UniFi Connect, Talk, Access, and Protect. These security flaws, including CVE-2026-50746, allow command injection and privilege escalation attacks. Users are strongly advised to update their systems to secure versions to mitigate potential breaches.

security ubiquiti vulnerabilities cve unifi
2 sources 2 reports 14d ago

Spanish Police Arrest Suspected Member of Pro-Russian Hacktivist Groups

Spanish authorities arrested a man in Palencia linked to pro-Russian hacktivist groups CARR and Z-Pentest following an FBI tip. The suspect is accused of aiding a hacker's escape and supporting cyber activities against Ukraine. The arrest could impact international investigations into cyber threats.

security hacktivism cybersecurity police cyberattacks
2 sources 2 reports 14d ago

Google Patches Critical Flaw in Dialogflow CX Chatbot Platform

Google has patched a critical vulnerability in its Dialogflow CX platform that could have allowed attackers with specific permissions to compromise multiple chatbots within a single Google Cloud project. Dubbed 'Rogue Agent' by Varonis, the issue involved the execution of shared Code Blocks, which allowed unauthorized data access and message manipulation. No attacks exploiting this flaw were reported, and it was primarily a risk from insiders or compromised accounts.

security google dialogflow vulnerability cloud
2 sources 2 reports 14d ago

Git Commit Signature Malleability Allows Tampered Verified Commit Hashes

Research has revealed Git commit hash malleability, enabling distinct commits with identical content, metadata, and valid signatures. The "hash chain malleability" flaw impacts systems relying on commit hash integrity, like dependency management and reproducible builds, leading to potential integrity risks.

security git cryptography vulnerabilities research
2 sources 2 reports 14d ago

Apple's Antitrust Appeal Over EU 'Gatekeeper' Status Rejected

Apple's legal challenge against its designation as a 'gatekeeper' under the EU's Digital Markets Act has been rejected. The ruling demands Apple allows interoperability with rival services and may affect its business model in Europe by enforcing fairer competition.

security apple antitrust eu dma
2 sources 2 reports 15d ago

Union County, Ohio Paid $1 Million to Cyber Group to Prevent Data Leak

Union County, Ohio paid $1 million to Kairos to prevent the release of stolen data after a May 2025 breach. This marks a significant data extortion case as there was no ransomware involved, emphasizing vulnerabilities in government data security without direct system lock-ups.

security cybersecurity extortion ransomware government
2 sources 2 reports 15d ago

Cordyceps Vulnerability Exposes Over 300 GitHub Repositories to Supply-Chain Attacks

Researchers from Novee Security have identified a CI/CD vulnerability, named Cordyceps, affecting over 300 GitHub repositories. This issue allows unauthenticated users to execute harmful code, potentially impacting major organizations like Microsoft, Google, Apache, and Cloudflare. The flaw, due to weak CI/CD configurations, raises significant supply chain security concerns.

security ci/cd vulnerability github vulnerabilities
2 sources 2 reports 15d ago

Iranian APT Group Targets Israeli Organizations with New C2 Framework

An Iranian hacking group linked to the Ministry of Intelligence and Security is targeting Israeli IT and government entities using a new command-and-control framework, Cavern C2. This development, attributed to the Cavern Manticore cluster, suggests evolving threats in cybersecurity, potentially influencing strategies in these sectors.

security hacking cybersecurity iran c2
2 sources 2 reports 15d ago

BeyondTrust Patches Critical Vulnerabilities in Remote Support Products

BeyondTrust has patched critical vulnerabilities in its Remote Support and Privileged Remote Access software. These flaws, identified as CVE-2026-40138 and CVE-2026-40139, could allow unauthenticated attackers to bypass authentication controls and gain unauthorized access, risking elevated privilege accounts. The company urges users to apply the patches promptly.

security beyondtrust vulnerabilities cybersecurity remote access
2 sources 2 reports 16d ago

Canadian Spy Agency Conducted Cyber Operations Against Criminal Groups

In 2022, Canada's Communications Security Establishment executed cyber operations against drug traffickers, violent extremists, and a ransomware gang. These state-authorized interventions aimed to thwart groups threatening Canada's national security and public safety. The operations utilized signals intelligence to disrupt criminal activities abroad, significantly impacting the targeted groups.

security canada cybersecurity intelligence ransomware
2 sources 2 reports 16d ago

VEIL#DROP Malware Chain Uses Blogger to Deliver PureLogs Stealer

The VEIL#DROP malware delivery chain employs compromised Blogspot pages to deploy the PureLogs Stealer through multi-stage execution involving JavaScript and PowerShell. The use of trusted platforms like Google's Blogspot allows attackers to sidestep traditional defenses. Researchers have identified the sophisticated use of this infrastructure to access victims' sensitive information.

security malware infostealer Blogger cybersecurity
2 sources 2 reports 16d ago

Armored Likho Targets Government and Power Sectors with Malware Attacks

The newly discovered Armored Likho group targets government and electric power sectors in Russia, Brazil, and Kazakhstan. The group uses malware, including the BusySnake Stealer, for cyber espionage and financial motives. This poses significant threats to critical infrastructure security in the affected regions.

security malware cybersecurity threats data theft
2 sources 2 reports 16d ago

FCA Calls for Enhanced Powers to Regulate AI in UK Financial Services

The Financial Conduct Authority (FCA) is advocating for stronger regulatory powers to tackle AI-related risks in UK financial services. A report led by FCA's Sheldon Mills highlights the potential for AI to both support consumer access and increase threats such as fraud and cybersecurity risks. The gravitation towards AI requires robust regulation to safeguard consumer interests as AI reshapes financial markets.

security ai financial services regulation consumer protection
2 sources 2 reports 16d ago

North Korean Hackers Launch Supply Chain Attack with Malicious Software Packages

North Korean hackers have launched the PolinRider campaign, targeting open source developers and cryptocurrency sectors through malicious software packages. The attack involves 108 unique packages and extensions, including npm libraries, Go modules, and a Chrome extension. This campaign is ongoing and poses significant risks by compromising maintainer accounts and using backdoors and information stealers.

security malware north korea software development supply chain
2 sources 2 reports 18d ago

Researchers Uncover Security Flaws in Apple AirDrop and Samsung Quick Share

Security researchers have identified six vulnerabilities in Apple's AirDrop and Samsung's Quick Share affecting billions of devices. These flaws enable nearby attackers to crash file-sharing services without user interaction. Apple has patched one of the AirDrop vulnerabilities, and investigation is ongoing for the others.

security airdrop file-sharing vulnerabilities quickshare
2 sources 3 reports 19d ago

UK Agencies Advise Parents on Risks of AI-Generated Abusive Images of Children

The UK's National Crime Agency and Internet Watch Foundation warn parents of the dangers posed by AI-generated child sexual abuse material. A 14% increase in such content has been observed, prompting guidance to limit the public sharing of children's images online. Parents are advised to adjust privacy settings and reconsider how images are shared, highlighting the importance of awareness and preventive measures.

security ai child safety nudification cybersecurity
2 sources 2 reports 19d ago

Critical Vulnerabilities Found in Cursor AI Code Editor, Prompt Urgent Update

Two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in the Cursor AI code editor, potentially allowing remote code execution by bypassing its security sandbox. These flaws, identified by Cato AI Labs, affect all versions before Cursor 3.0 and have been patched in the new release. The vulnerabilities could impact many Fortune 500 companies that use the editor, highlighting the urgency for affected users to update to version 3.0 to mitigate security risks.

security vulnerabilities cursor ai remote code execution
2 sources 2 reports 19d ago

FTC Urged to Maintain Privacy Audits on Musk's X amid Concerns

Privacy advocates, including the EFF, are urging the FTC to retain audits on X (formerly Twitter) to ensure data privacy compliance. X, having rebranded under Elon Musk, argues for the termination of the audits, citing redundancy with GDPR obligations. The company's history of privacy violations and corrective actions like rebranding are central to this debate, affecting millions of users.

security privacy data protection ftc elon musk
2 sources 3 reports 20d ago

Citrix Patches Six Critical NetScaler Vulnerabilities, Including HTTP/2 Bomb

Citrix released patches for six vulnerabilities in NetScaler ADC and Gateway, including a critical HTTP/2 Bomb exploit. These flaws, affecting versions 14.1 and 13.1, pose severe risks like denial-of-service attacks and data breaches. Organizations using these configurations should urgently update to protect against active threats.

security citrix netscaler vulnerabilities releases
2 sources 2 reports 20d ago

DHS Investigates Cyber Breach on Homeland Security Information Network

The Department of Homeland Security is investigating a recent cyberattack on the Homeland Security Information Network (HSIN). The breach, suspected to occur between late May and early June, affected both HSIN servers and a SharePoint system, key for information sharing among government entities. The attack raises concerns over national security and vulnerabilities in government cybersecurity infrastructure.

security cybersecurity dhs hsin breach
2 sources 2 reports 20d ago

Cisco Acknowledges Exploitation of Unified CM Vulnerability CVE-2026-20230

Cisco has confirmed active exploitation of a critical vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM). This flaw, found in systems with the WebDialer service enabled, allows attackers to execute server-side request forgery attacks and potentially gain root access. Cisco urges users to upgrade to patched versions immediately.

security cisco exploits vulnerability unified_cm
2 sources 2 reports 20d ago

LayerX Reveals AI Browser Vulnerability Exploited by 'BioShocking' Attack

Security firm LayerX has discovered a vulnerability in AI-driven browsers, known as the 'BioShocking' attack, where browsers can be tricked into leaking user credentials. The attack uses game-like puzzle contexts to manipulate AI agents into bypassing security protocols, potentially exposing sensitive data. This discovery raises concerns about the security of AI-assisted browsing applications.

security ai browser credentials
2 sources 2 reports 20d ago

ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized PoC Exploits

ChocoPoC, a Python-based remote access trojan, is being distributed through trojanized proof-of-concept (PoC) exploit repositories on GitHub. The malware targets cybersecurity researchers by installing malicious dependencies from PyPI, enabling attackers to execute commands and steal sensitive data. This highlights security risks associated with using unofficial PoCs in vulnerability research.

security malware research cybersecurity trojan
2 sources 2 reports 20d ago

Password Spray Attack Targets Microsoft Azure CLI, Compromising 78 Accounts

An automated password spray attack on Microsoft's Azure CLI attempted over 81 million logins, affecting 78 accounts across 64 organizations. The attackers exploited a deprecated OAuth flow, bypassing security measures like Conditional Access policies and multi-factor authentication (MFA). This incident underscores vulnerabilities in prevalent security configurations within cloud environments.

security azure oauth passwords microsoft
1 source 47 reports 4h ago Updated 10h ago

ExpressVPN Enhances Password Manager with New Features

ExpressVPN has updated its password manager, ExpressKeys, to include secure sharing and passkey support. This update is part of the broader trend of meeting increasing demands for secure data management across devices.

security vpn passwords updates canvas tv
1 source 1 report 1d ago

Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA

Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.

security post-quantum cryptography quantum computing
1 source 1 report 1d ago

Cloudflare joins UK's Cyber Resilience Pledge to enhance cybersecurity governance

The UK government launched the Cyber Resilience Pledge, aimed at enhancing cybersecurity governance. Cloudflare joined as a founding signatory, emphasizing collective defense principles against increasing cyber threats.

security cloudflare cybersecurity uk government
More stories →