§Source · Cybersecurity News
Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatches
Loading
§Source · Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatchesFoxit Reader updater flaw CVE-2026-57239 allows local standard users to escalate to SYSTEM under specific conditions.
APT42 leverages AI-assisted reconnaissance and the resilient TAMECAT malware to target senior government and defense personnel.
CVE-2026-42533 in nginx script engine enables crashing worker processes and potential remote code execution since 2011.
Spirals ransomware used IIS web shell and PsExec to achieve full network encryption at an IT firm within 24 hours.
Newsletter aggregates multiple incidents including EY breach, wp2shell exploit, and numerous high-impact patches and breaches.
NadMesh botnet scans Shodan for exposed AI services, harvesting cloud keys and Kubernetes tokens to hijack model-serving infrastructure.
Two Scattered Spider members jailed for a 2024 attack disrupting 148 TfL systems and forcing 27,000 staff password resets.
Citrix Secure Access and Endpoint clients for Windows have a privilege-escalation flaw (CVE-2026-53565) enabling SYSTEM access.
Ransomware forced Coca‑Cola's Fairlife to suspend U.S. production, impacting supply chains and operations.
Unauthenticated wp2shell RCE affects millions of WordPress sites; public exploits available — apply emergency patch now.
BitLocker zero-day CVE-2026-50661 allows physical attackers with hands-on access to bypass device encryption protections.
SonicWall SMA1000 zero-days (including SSRF CVE-2026-15409) are actively exploited; apply mitigations and emergency patches.
AsyncAPI packages were trojanized after attacker stole an npm publishing token via GitHub Actions, risking developer and CI compromise.
Miasma v3 delivered via trojanized AsyncAPI packages creates persistent backdoors on developer machines and build servers.
CISA publishes after-action lessons following contractor exposure of AWS GovCloud credentials and IaC repos on public GitHub.
Forg365 provides AI-driven phishing, session theft and mailbox access to attack Microsoft 365 users via a subscription model.
Critical Dell BIOS weakness (CVE-2026-40639) allows instant admin-password recovery from SPI flash, risking device takeover and firmware abuse.
Threat group O UNC 066 uses phone-based phishing to trick employees into registering attacker-controlled Entra passkeys to hijack accounts.
Roundcube 1.7 patches zero-click stored XSS via crafted MIME attachments enabling remote compromise without user interaction.
Get these articles delivered to your inbox.
Subscribe free