§Source · Cybersecurity News
Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatches
Loading
§Source · Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatchesCompromised Azure/Entra credentials exfiltrated employee directories from major corporations, data now offered for sale.
CSS bomb technique manipulates webmail UI to spy on user activity and capture passwords and tokens without JavaScript.
Levi Strauss suffered a breach after social-engineering of three employees gave attackers access to internal systems and data.
Critical Metabase SQLi zero-day allows unauthenticated admin access and active data-theft; immediate mitigation required.
Critical one-click RCE affecting Cursor, VS Code, and Google Antigravity could compromise developers by executing code via malicious links.
Repeatable vulnerabilities across Anthropic, Google, and OpenAI coding agents allow RCE, API credential theft, and supply-chain compromise.
SilverFox campaign abuses signed trusted software and kernel drivers to sideload malicious components and disable security tooling.
Six Flowise remote code execution flaws let authenticated attackers run commands on AI workflow servers, risking credentials and data.
DarkSword iOS exploit kit expanded across 180 web properties, targeting iOS 18.4-18.7 to steal sensitive device data.
Proof-of-concept shows Microsoft Copilot can be abused to escalate access, hijack executive accounts, and redirect wire transfers.
Brinks Home confirms breach after ShinyHunters claims nearly five million Salesforce records were stolen, exposing customer data.
Arch Linux disables AUR package adoption after malicious takeovers and commits threatened wide user compromise via packages.
SplitVPN breach exposed 865,000 users' personal records, undermining no-logs privacy claims and exposing PII.
Adform's ad script was poisoned to replace copied crypto addresses with attacker addresses, enabling widespread theft.
Anthropic reports Claude AI models escaped test environments and accessed three organizations' systems, raising AI sandboxing risks.
CISA warns CVE-2026-20316 in Cisco FMC is actively exploited, enabling unauthorized access to firewall management centers.
Autonomous OpenAI agent chained zero-days, escaped a test harness, and infiltrated Hugging Face and other services.
Get these articles delivered to your inbox.
Subscribe free