SecurityWeek Mar 19, 2026, 01:30 PM (UTC)
Read
Harris is a hacker with a rebellious spirit and a willingness to break rules in the pursuit of his purpose – but without causing harm or damage. The post Hacker Conversations: Ben Harris, from Unintentional Young Hacker to Intentional Adult CEO appeared first…
SecurityWeek Mar 19, 2026, 01:24 PM (UTC)
Read
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser. The post Russian APT Exploits Zimbra Vulnerability Against Ukraine appeared first on SecurityWeek.
BleepingComputer Mar 19, 2026, 01:00 PM (UTC)
Read
Ubiquiti has patched two vulnerabilities in the UniFi Network Application, including a maximum-severity flaw that may allow attackers to take over user accounts. [...]
Cybersecurity Ventures Mar 19, 2026, 12:57 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 19, 2026 – Read the full story in Financial Express Corporate Wi-Fi networks, once considered a routine part of office infrastructure, are emerging as a growing cyberse…
The Hacker News Mar 19, 2026, 12:43 PM (UTC)
Read
Cybersecurity researchers have disclosed a new Android malware family called Perseus that's being actively distributed in the wild with an aim to conduct device takeover (DTO) and financial fraud. Perseus is built upon the foundations of Cerberus and Phoenix,…
BleepingComputer Mar 19, 2026, 11:02 AM (UTC)
Read
CISA warned U.S. organizations to follow Microsoft guidance to strengthen the Intune endpoint management tool after a cyberattack exploited it to wipe medical technology giant Stryker's systems. [...]
The Hacker News Mar 19, 2026, 10:58 AM (UTC)
Read
Security teams have spent years building identity and access controls for human users and service accounts. But a new category of actor has quietly entered most enterprise environments, and it operates entirely outside those controls. Claude Code, Anthropic's…
SecurityWeek Mar 19, 2026, 10:31 AM (UTC)
Read
Raven’s platform observes applications at runtime to detect anomalous behavior and prevent cyberattacks. The post Raven Emerges From Stealth With $20 Million in Funding appeared first on SecurityWeek.
Infosecurity Magazine Mar 19, 2026, 10:30 AM (UTC)
Read
The UK’s financial regulator has issued new rules to make incident and third-party reporting clearer
BleepingComputer Mar 19, 2026, 10:13 AM (UTC)
Read
A new Android malware called Perseus is checking user-curated notes to steal sensitive information, like passwords, recovery phrases, or financial data. [...]
BleepingComputer Mar 19, 2026, 10:06 AM (UTC)
Read
A critical Microsoft SharePoint vulnerability patched in January is now being exploited in attacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned. [...]
Infosecurity Magazine Mar 19, 2026, 09:50 AM (UTC)
Read
Notorious ransomware group Interlock has been exploiting a Cisco zero-day bug since January, AWS says
SecurityWeek Mar 19, 2026, 09:42 AM (UTC)
Read
The SharePoint remote code execution vulnerability CVE-2026-20963, which Microsoft patched in January, has been exploited in the wild. The post CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability appeared first on SecurityWeek.
The Hacker News Mar 19, 2026, 09:14 AM (UTC)
Read
A new exploit kit for Apple iOS devices designed to steal sensitive data from is being wielded by multiple threat actors since at least November 2025, according to reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout. According to GTIG, m…
Infosecurity Magazine Mar 19, 2026, 09:00 AM (UTC)
Read
35% of security leaders working in the UK’s critical infrastructure said regulatory requirements are the primary influence on their security programs
SecurityWeek Mar 19, 2026, 08:57 AM (UTC)
Read
Amazon found evidence that the FMC software vulnerability has been exploited since late January, and found links to Russia. The post Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks appeared first on SecurityWeek.
The Hacker News Mar 19, 2026, 06:05 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, stating they have been actively exploited…
BleepingComputer Mar 18, 2026, 10:56 PM (UTC)
Read
Identity protection company Aura has confirmed that an unauthorized party gained access to nearly 900,000 customer records containing names and email addresses. [...]
BleepingComputer Mar 18, 2026, 07:57 PM (UTC)
Read
CISA has ordered U.S. government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS). [...]
SecurityWeek Mar 18, 2026, 07:37 PM (UTC)
Read
With exploitation of vulnerabilities taking just days, preemptive security must be the new model for defenders. The post The Collapse of Predictive Security in the Age of Machine-Speed Attacks appeared first on SecurityWeek.
BleepingComputer Mar 18, 2026, 06:10 PM (UTC)
Read
ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation. [...]
SecurityWeek Mar 18, 2026, 06:01 PM (UTC)
Read
The company has developed an AI-powered platform that autonomously discovers and validates software vulnerabilities. The post Autonomous Offensive Security Firm XBOW Raises $120M at $1B+ Valuation appeared first on SecurityWeek.
The Hacker News Mar 18, 2026, 05:26 PM (UTC)
Read
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has sanctioned six individuals and two entities for their involvement in the Democratic People's Republic of Korea (DPRK) information technology (IT) worker scheme with an aim to def…
BleepingComputer Mar 18, 2026, 04:53 PM (UTC)
Read
The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since late January. [...]
The Hacker News Mar 18, 2026, 04:00 PM (UTC)
Read
Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that's exploiting a recently disclosed critical security flaw in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability in question is CVE-2026-20131 (CVSS scor…
SecurityWeek Mar 18, 2026, 03:59 PM (UTC)
Read
Phil Venables, former CISO of Google Cloud and now a venture partner at Ballistic Ventures, has joined Native’s board of directors. The post Cloud Security Startup Native Exits Stealth With $42 Million in Funding appeared first on SecurityWeek.
Infosecurity Magazine Mar 18, 2026, 03:45 PM (UTC)
Read
CVE-2026-3888 Ubuntu snap flaw lets local users escalate to root via timing-based exploit
BleepingComputer Mar 18, 2026, 03:32 PM (UTC)
Read
Marquis, a Texas-based financial services provider, revealed this week that a ransomware gang stole the data of over 670,000 individuals in an August 2025 cyberattack that also disrupted operations at 74 banks across the United States. [...]
SecurityWeek Mar 18, 2026, 03:30 PM (UTC)
Read
Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance. The post ‘DarkSword’ iOS Exploit Kit Used by State-Sponsored Hackers, Spyware Vendors appeared first on SecurityWeek.
SecurityWeek Mar 18, 2026, 02:57 PM (UTC)
Read
Cyber risk doesn’t stop at your perimeter. Today’s most dangerous threats could be hiding in your software supply chain. The post Virtual Summit Today: Supply Chain & Third-Party Risk Summit appeared first on SecurityWeek.
Infosecurity Magazine Mar 18, 2026, 02:15 PM (UTC)
Read
ShieldGuard Chrome extension posed as a crypto security tool but stole wallets and drained user data
BleepingComputer Mar 18, 2026, 02:05 PM (UTC)
Read
Refund fraud is now a business, with methods and tutorials sold to exploit return policies for profit. Flare shows how fraudsters turn refunds and chargebacks into a repeatable profit model. [...]
BleepingComputer Mar 18, 2026, 02:02 PM (UTC)
Read
A new exploit kit for iOS devices and delivery framework dubbed "Darksword" has been used to steal a wide range of personal information, including data from cryptocurrency wallet app. [...]
BleepingComputer Mar 18, 2026, 01:55 PM (UTC)
Read
Customers of upscale department store chain Nordstrom received fraudulent messages from a legitimate company email address that promoted cryptocurrency scams disguised as a St. Patrick's Day promotion. [...]
Infosecurity Magazine Mar 18, 2026, 01:00 PM (UTC)
Read
Rapid7 says median time from publication to CISA KEV inclusion dropped to five days
The Hacker News Mar 18, 2026, 12:30 PM (UTC)
Read
Cybersecurity researchers have disclosed a critical security flaw impacting the GNU InetUtils telnet daemon (telnetd) that could be exploited by an unauthenticated remote attacker to execute arbitrary code with elevated privileges. The vulnerability, tracked a…
The Hacker News Mar 18, 2026, 11:58 AM (UTC)
Read
When a Magecart payload hides inside the EXIF data of a dynamically loaded third-party favicon, no repository scanner will catch it – because the malicious code never actually touches your repo. As teams adopt Claude Code Security for static analysis, this is…
The Hacker News Mar 18, 2026, 11:42 AM (UTC)
Read
Cybersecurity researchers have warned about the risks posed by low-cost IP KVM (Keyboard, Video, Mouse over Internet Protocol) devices, which can grant attackers extensive control over compromised hosts. The nine vulnerabilities, discovered by Eclypsium, span…
Infosecurity Magazine Mar 18, 2026, 11:15 AM (UTC)
Read
The Vidar 2.0 infostealers is deployed through fake free game cheats on GitHub and Reddit
The Hacker News Mar 18, 2026, 10:30 AM (UTC)
Read
Security teams today are not short on tools or data. They are overwhelmed by both. Yet within the terabytes of alerts, exposures, and misconfigurations – security teams still struggle to understand context: Q: Which exposures, misconfigurations, and vulnerabil…
Infosecurity Magazine Mar 18, 2026, 09:40 AM (UTC)
Read
Gartner has urged security teams to get involved in AI projects from the start to avoid costly incident response
The Hacker News Mar 18, 2026, 08:08 AM (UTC)
Read
A high-severity security flaw affecting default installations of Ubuntu Desktop versions 24.04 and later could be exploited to escalate privileges to the root level. Tracked as CVE-2026-3888 (CVSS score: 7.8), the issue could allow an attacker to seize control…
The Hacker News Mar 18, 2026, 06:31 AM (UTC)
Read
Apple on Tuesday released its first round of Background Security Improvements to address a security flaw in WebKit that affects iOS, iPadOS, and macOS. The vulnerability, tracked as CVE-2026-20643 (CVSS score: N/A), has been described as a cross-origin issue i…
BleepingComputer Mar 18, 2026, 01:06 AM (UTC)
Read
Apple has released its first Background Security Improvements update to fix a WebKit flaw tracked as CVE-2026-20643 on iPhones, iPads, and Macs without requiring a full operating system upgrade. [...]
BleepingComputer Mar 17, 2026, 09:42 PM (UTC)
Read
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions. [...]
BleepingComputer Mar 17, 2026, 06:41 PM (UTC)
Read
The European Union Council has announced sanctions against three entities and two individuals for their involvement in cyberattacks targeting critical infrastructure in the region. [...]
Cybersecurity Ventures Mar 17, 2026, 06:04 PM (UTC)
Read
Security chiefs watch short videos produced by Cybercrime Magazine – Steve Morgan, Founder of Cybersecurity Ventures Sausalito, Calif. – Mar. 18, 2026 Around a year ago, Cybersecurity Ventures asked AI “Why use YouTube for marketing?” and it replied “YouTube i…
The Hacker News Mar 17, 2026, 04:39 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a new method for exfiltrating sensitive data from artificial intelligence (AI) code execution environments using domain name system (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazo…
Infosecurity Magazine Mar 17, 2026, 04:30 PM (UTC)
Read
Android’s LSPosed-based attack hijacks payment apps via runtime manipulation and SIM-binding bypass
Infosecurity Magazine Mar 17, 2026, 03:00 PM (UTC)
Read
CursorJack shows how malicious MCP deeplinks in Cursor IDE can trigger user-approved code execution
The Hacker News Mar 17, 2026, 02:34 PM (UTC)
Read
The ransomware operation known as LeakNet has adopted the ClickFix social engineering tactic delivered through compromised websites as an initial access method. The use of ClickFix, where users are tricked into manually running malicious commands to address no…
Cybersecurity Ventures Mar 17, 2026, 01:06 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 17, 2026 – Read the full story in Eureka Street Mark Gaetani, National President of the St Vincent de Paul Society in Australia, recently read in Cybercrime Magazine th…
Infosecurity Magazine Mar 17, 2026, 12:00 PM (UTC)
Read
Armis reveals that “mutually assured disruption” is no longer preventing state-backed attacks
The Hacker News Mar 17, 2026, 11:30 AM (UTC)
Read
A majority of security leaders are struggling to defend AI systems with tools and skills that are not fit for the challenge, according to the AI and Adversarial Testing Benchmark Report 2026 from Pentera. The report, based on a survey of 300 US CISOs and senio…
Infosecurity Magazine Mar 17, 2026, 10:30 AM (UTC)
Read
Akamai says 87% of organizations suffered an API-related security incident last year
Infosecurity Magazine Mar 17, 2026, 10:15 AM (UTC)
Read
The US Cyber Monitoring Center should be operational in 2027, said the UK CMC leadership
The Hacker News Mar 17, 2026, 09:53 AM (UTC)
Read
North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim's KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat int…
The Hacker News Mar 17, 2026, 05:23 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Wing FTP to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2025-47813…
The Hacker News Mar 16, 2026, 07:37 PM (UTC)
Read
The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories. "The attack targets Python projects — including Django apps, ML research code, Streamlit dash…
Infosecurity Magazine Mar 16, 2026, 02:45 PM (UTC)
Read
Some of these campaigns are linked to Darcula, a Chinese-language phishing-as-a-service platform
The Hacker News Mar 16, 2026, 02:17 PM (UTC)
Read
Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few b…
Infosecurity Magazine Mar 16, 2026, 02:00 PM (UTC)
Read
CrackArmor AppArmor flaws let local Linux users gain root, break containers and enable DoS attacks
Infosecurity Magazine Mar 16, 2026, 01:00 PM (UTC)
Read
DNS-based attack in AWS Bedrock AgentCore lets AI sandboxes exfiltrate cloud data
Cybersecurity Ventures Mar 16, 2026, 12:54 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 16, 2026 – Read the full Forbes story The cloud is home to a dizzying amount of data. According to Cybersecurity Ventures, nearly half of the world’s data exists in ext…
The Hacker News Mar 16, 2026, 11:58 AM (UTC)
Read
If you run security at any reasonably complex organization, your validation stack probably looks something like this: a BAS tool in one corner. A pentest engagement, or maybe an automated pentesting product, in another. A vulnerability scanner feeding an attac…
The Hacker News Mar 16, 2026, 11:41 AM (UTC)
Read
Three different ClickFix campaigns have been found to act as a delivery vector for the deployment of a macOS information stealer called MacSync. "Unlike traditional exploit-based attacks, this method relies entirely on user interaction – usually in the form of…
Infosecurity Magazine Mar 16, 2026, 11:15 AM (UTC)
Read
The FBI wants to hear from gamers who have downloaded Steam titles containing malware
Infosecurity Magazine Mar 16, 2026, 10:30 AM (UTC)
Read
An issue with the Companies House website has put the personal and corporate information of millions at risk
The Hacker News Mar 16, 2026, 09:07 AM (UTC)
Read
Ukrainian entities have emerged as the target of a new campaign likely orchestrated by threat actors linked to Russia, according to a report from S2 Grupo's LAB52 threat intelligence team. The campaign, observed in February 2026, has been assessed to share ove…
The Hacker News Mar 16, 2026, 05:43 AM (UTC)
Read
Google is testing a new security feature as part of Android Advanced Protection Mode (AAPM) that prevents certain kinds of apps from using the accessibility services API. The change, incorporated in Android 17 Beta 2, was first reported by Android Authority la…
The Hacker News Mar 14, 2026, 04:17 PM (UTC)
Read
China's National Computer Network Emergency Response Technical Team (CNCERT) has issued a warning about the security stemming from the use of OpenClaw (formerly Clawdbot and Moltbot), an open-source and self-hosted autonomous artificial intelligence (AI) agent…
The Hacker News Mar 14, 2026, 12:55 PM (UTC)
Read
Cybersecurity researchers have flagged a new iteration of the GlassWorm campaign that they say represents a "significant escalation" in how it propagates through the Open VSX registry. "Instead of requiring every malicious listing to embed the loader directly,…
The Hacker News Mar 13, 2026, 05:33 PM (UTC)
Read
A suspected China-based cyber espionage operation has targeted Southeast Asian military organizations as part of a state-sponsored campaign that dates back to at least 2020. Palo Alto Networks Unit 42 is tracking the threat activity under the moniker CL-STA-10…
The Hacker News Mar 13, 2026, 05:09 PM (UTC)
Read
Meta has announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. "If you have chats that are impacted by this change, you will see instructions on how you can download any media or messages you may want…
Infosecurity Magazine Mar 13, 2026, 04:15 PM (UTC)
Read
A new law enforcement operation against phishing and ransomware operators led to the takedown of 45,000 malicious IP addresses
The Hacker News Mar 13, 2026, 03:20 PM (UTC)
Read
INTERPOL on Friday announced the takedown of 45,000 malicious IP addresses and servers used in connection with phishing, malware, and ransomware campaigns, as part of the agency's ongoing efforts to dismantle criminal networks, disrupt emerging threats, and sa…
The Hacker News Mar 13, 2026, 01:38 PM (UTC)
Read
Microsoft has disclosed details of a credential theft campaign that employs fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. "The campaign redirects users searching for legitimate enterprise…
The Hacker News Mar 13, 2026, 01:28 PM (UTC)
Read
Disclaimer: This report has been prepared by the Threat Research Center to enhance cybersecurity awareness and support the strengthening of defense capabilities. It is based on independent research and observations of the current threat landscape available at…
Cybersecurity Ventures Mar 13, 2026, 01:09 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 13, 2026 – Read the full story in Forbes Cloud security has become the backbone of enterprise resilience, but the threat landscape has evolved faster than traditional s…
Infosecurity Magazine Mar 13, 2026, 10:00 AM (UTC)
Read
Operation Lightning sees international law enforcement partners shut down ‘SocksEscort,’ a major malicious proxy service used by cybercriminals worldwide
The Hacker News Mar 13, 2026, 09:17 AM (UTC)
Read
Google on Thursday released security updates for its Chrome web browser to address two high-severity vulnerabilities that it said have been exploited in the wild. The list of vulnerabilities is as follows - CVE-2026-3909 (CVSS score: 8.8) - An out-of-bounds wr…
The Hacker News Mar 13, 2026, 08:18 AM (UTC)
Read
Cybersecurity researchers have disclosed multiple security vulnerabilities within the Linux kernel's AppArmor module that could be exploited by unprivileged users to circumvent kernel protections, escalate to root, and undermine container isolation guarantees.…
The Hacker News Mar 13, 2026, 05:26 AM (UTC)
Read
A court-authorized international law enforcement operation has dismantled a criminal proxy service named SocksEscort that enslaved thousands of residential routers worldwide into a botnet for committing large-scale fraud. "SocksEscort infected home and small b…
The Hacker News Mar 13, 2026, 04:15 AM (UTC)
Read
Veeam has released security updates to address multiple critical vulnerabilities in its Backup & Replication software that, if successfully exploited, could result in remote code execution. The vulnerabilities are as follows - CVE-2026-21666 (CVSS score: 9.9)…
The Hacker News Mar 12, 2026, 05:31 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a new banking malware targeting Brazilian users that's written in Rust, marking a significant departure from other known Delphi-based malware families associated with the Latin American cybercrime ecosystem.…
The Hacker News Mar 12, 2026, 05:02 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a suspected artificial intelligence (AI)-generated malware codenamed Slopoly put to use by a financially motivated threat actor named Hive0163. "Although still relatively unspectacular, AI-generated malware s…
Infosecurity Magazine Mar 12, 2026, 04:00 PM (UTC)
Read
PixRevolution Android trojan hijacks Brazil’s PIX payments in real time using accessibility abuse
Infosecurity Magazine Mar 12, 2026, 03:28 PM (UTC)
Read
The critical vulnerability affecting both cloud and self-hosted n8n instances requires no authentication or even n8n account to be exploited
The Hacker News Mar 12, 2026, 01:30 PM (UTC)
Read
Phishing has quietly turned into one of the hardest enterprise threats to expose early. Instead of crude lures and obvious payloads, modern campaigns rely on trusted infrastructure, legitimate-looking authentication flows, and encrypted traffic that conceals m…
The Hacker News Mar 12, 2026, 01:14 PM (UTC)
Read
Another Thursday, another pile of weird security stuff that somehow happened in just seven days. Some of it is clever. Some of it is lazy. A few bits fall into that uncomfortable category of “yeah… this is probably going to show up in real incidents sooner tha…
Cybersecurity Ventures Mar 12, 2026, 12:58 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 12, 2026 – Listen to the podcast Stacy Horn, 66, is an author and the founder of East Coast Hang Out, or ECHO, which is widely regarded as the first social The post Bac…
Infosecurity Magazine Mar 12, 2026, 12:45 PM (UTC)
Read
CISA issued urgent directive as attackers exploit Cisco SD-WAN flaw granting admin access to networks
The Hacker News Mar 12, 2026, 11:30 AM (UTC)
Read
The most dangerous phishing campaigns aren’t just designed to fool employees. Many are designed to exhaust the analysts investigating them. When a phishing investigation takes 12 hours instead of five minutes, the outcome can shift from a contained incident to…
Infosecurity Magazine Mar 12, 2026, 10:30 AM (UTC)
Read
The ICO has fined Police Scotland after it shared the entire contents of a victim’s phone with her alleged attacker
The Hacker News Mar 12, 2026, 09:58 AM (UTC)
Read
Apple on Wednesday backported fixes for a security flaw in iOS, iPadOS, and macOS Sonoma to older versions after it was found to be used as part of the Coruna exploit kit. The vulnerability, tracked as CVE-2023-43010, relates to an unspecified vulnerability in…
Infosecurity Magazine Mar 12, 2026, 09:30 AM (UTC)
Read
The pro-Iran Handala group claims to have wiped 200,000 systems in destructive wiper malware attack on US firm Stryker
The Hacker News Mar 12, 2026, 07:56 AM (UTC)
Read
Cybersecurity researchers have discovered half-a-dozen new Android malware families that come with capabilities to steal data from compromised devices and conduct financial fraud. The Android malware range from traditional banking trojans like PixRevolution, T…
The Hacker News Mar 12, 2026, 05:18 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting n8n to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, tracked as CVE-2025-68…
Infosecurity Magazine Mar 11, 2026, 04:50 PM (UTC)
Read
French small and medium businesses remained the organizations most targeted by ransomware in 2025
The Hacker News Mar 11, 2026, 04:38 PM (UTC)
Read
Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user could be trained and tricked into falling prey to phishing and scam traps. The attack, at its core, takes…
Krebs on Security Mar 11, 2026, 04:20 PM (UTC)
Read
A hacktivist group with links to Iran's intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker's largest hub outside of the United S…
Infosecurity Magazine Mar 11, 2026, 04:20 PM (UTC)
Read
Infosecurity Europe 2026 reveals its keynote line-up, featuring Jason Fox, Shlomo Kramer, Cynthia Kaiser and more, with sessions on AI, cloud security and post quantum threats
Infosecurity Magazine Mar 11, 2026, 04:00 PM (UTC)
Read
LeakyLooker flaws in Google Looker Studio let attackers run cross-tenant SQL attacks on cloud data
The Hacker News Mar 11, 2026, 02:51 PM (UTC)
Read
Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. The vulnerabilities are listed below - CVE-2026-27577 (CVS…
Infosecurity Magazine Mar 11, 2026, 02:45 PM (UTC)
Read
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
Infosecurity Magazine Mar 11, 2026, 02:30 PM (UTC)
Read
BlackSanta malware targets HR staff with fake resumes, kills EDR and steals system data
Infosecurity Magazine Mar 11, 2026, 01:35 PM (UTC)
Read
Palo Alto Networks’ Unit 42 has developed a successful attack to bypass safety guardrails in popular generative AI tools
The Hacker News Mar 11, 2026, 01:15 PM (UTC)
Read
Meta on Wednesday said it disabled over 150,000 accounts associated with scam centers in Southeast Asia as part of a coordinated effort in partnership with authorities from Thailand, the U.S., the U.K., Canada, Korea, Japan, Singapore, the Philippines, Austral…
Cybersecurity Ventures Mar 11, 2026, 12:57 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 11, 2026 – Listen to the podcast Fergus Hay is the CEO & co-founder of The Hacking Games, a recruitment tech platform that uses AI to identify gamers whose skills can T…
The Hacker News Mar 11, 2026, 12:26 PM (UTC)
Read
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnera…
The Hacker News Mar 11, 2026, 11:30 AM (UTC)
Read
“You knew, and you could have acted. Why didn’t you?” This is the question you do not want to be asked. And increasingly, it’s the question leaders are forced to answer after an incident. For years, many executive teams and boards have treated a large vulnerab…
Infosecurity Magazine Mar 11, 2026, 10:30 AM (UTC)
Read
Check Point data shows attack volumes are growing much faster in the UK than worldwide
Infosecurity Magazine Mar 11, 2026, 09:20 AM (UTC)
Read
March Patch Tuesday sees Microsoft release updates for 79 flaws
The Hacker News Mar 11, 2026, 09:15 AM (UTC)
Read
Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two that have been listed as publicly known. Of these, eight are rated Critical, and 76 are rated Important in severity. Forty-s…
The Hacker News Mar 11, 2026, 07:31 AM (UTC)
Read
A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim's cloud environment within a span of 72 hours. The attack started with the theft of a developer's GitHub t…
The Hacker News Mar 11, 2026, 05:12 AM (UTC)
Read
Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors. The Rust packages, published to crates.io, are listed below - chrono_anchor dnp3times time_calibrato…
Krebs on Security Mar 11, 2026, 12:32 AM (UTC)
Read
Microsoft Corp. today pushed security updates to fix at least 77 vulnerabilities in its Windows operating systems and other software. There are no pressing "zero-day" flaws this month (compared to February's five zero-day treat), but as usual some patches may…
Infosecurity Magazine Mar 10, 2026, 05:15 PM (UTC)
Read
OpenAI’s latest acquisition addresses a security need Jamieson O’Reilly, security advisor at OpenClaw, raised during an exclusive interview with Infosecurity
Infosecurity Magazine Mar 10, 2026, 04:00 PM (UTC)
Read
Only 24% of organizations test identity disaster recovery plans every 6 months, Quest Software said
Infosecurity Magazine Mar 10, 2026, 03:30 PM (UTC)
Read
Google Cloud report details a sharp rise in attackers exploiting software vulnerabilities, including React2Shell
Infosecurity Magazine Mar 10, 2026, 03:00 PM (UTC)
Read
Ericsson data breach affects 15k employees/customers after third-party service provider compromise
Cybersecurity Ventures Mar 10, 2026, 12:19 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 10, 2026 – Read the full story in EC-Council The late 1990s dot-com boom saw internet adoption explode, venture capital pour in, new roles appear overnight, and salarie…
Infosecurity Magazine Mar 10, 2026, 10:45 AM (UTC)
Read
Dutch intelligence reveals Russian state hackers are trying to hijack the Signal and WhatsApp accounts of key targets
Infosecurity Magazine Mar 10, 2026, 10:00 AM (UTC)
Read
Prolific ShinyHunters group claims to have stolen data from nearly 400 websites in Experience Cloud attacks
Infosecurity Magazine Mar 9, 2026, 03:45 PM (UTC)
Read
Huntress researchers uncover campaign exploiting vulnerabilities to steal data using Elastic Cloud as a data hub
Infosecurity Magazine Mar 9, 2026, 03:00 PM (UTC)
Read
US national cyber strategy focuses on stronger defenses, countering threats, fostering innovation
Infosecurity Magazine Mar 9, 2026, 02:00 PM (UTC)
Read
New UK Online Crime Centre will combine expertise from a range of sources to takedown online channels cyber-scammers rely on
Infosecurity Magazine Mar 9, 2026, 01:25 PM (UTC)
Read
Over one in five winners of IT-Harvest’s 2026 Cyber 150 are AI security companies
Cybersecurity Ventures Mar 9, 2026, 01:02 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 9, 2026 – Read the full story in Forbes If Defense Tech is the loud winner during the Iran conflict, Cybersecurity is the quiet one, and the opportunity is just as larg…
Infosecurity Magazine Mar 9, 2026, 10:45 AM (UTC)
Read
Billing services provider TriZetto Provider Solutions has begun notifying millions of patients about a data breach
Infosecurity Magazine Mar 9, 2026, 10:00 AM (UTC)
Read
Derrick Van Yeboah admitted he stole over $10m in romance scams as part of crime gang
Krebs on Security Mar 8, 2026, 11:35 PM (UTC)
Read
AI-based assistants or "agents" -- autonomous programs that have access to the user's computer, files, online services and can automate virtually any task -- are growing in popularity with developers and IT workers. But as so many eyebrow-raising headlines ove…
Infosecurity Magazine Mar 6, 2026, 03:15 PM (UTC)
Read
A bank, an airport, a non-profit and the Israeli branch of a US software company were among the targets of this new MuddyWater campaign
Infosecurity Magazine Mar 6, 2026, 12:29 PM (UTC)
Read
Almost a quarter of the zero days detected by Google in 2025 targeted security and networking appliances
Infosecurity Magazine Mar 5, 2026, 04:00 PM (UTC)
Read
Malicious insiders are using misusing AI for nefarious gain, while employees cutting corners also creates risk, warns Mimecast
Infosecurity Magazine Mar 5, 2026, 02:00 PM (UTC)
Read
Critical flaw "ContextCrush" in Context7 MCP Server could allow malicious instructions into AI tools
Cybersecurity Ventures Mar 5, 2026, 01:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 5, 2026 – Listen to the podcast In the latest episode of “CISO Confidential“, a series on the popular Cybercrime Magazine Podcast sponsored by Doppel, host Charlie Osbo…