A recent attempt at a destructive cyberattack on Poland’s power grid has prompted the Cybersecurity and Infrastructure Security Agency to publish a warning for U.S. critical infrastructure owners and operators. Tuesday’s alert follows a Jan. 30 report from Poland’s Computer Emergency Response Team concluded the December attack overlapped significantly with infrastructure used by a Russian…
Category: Research
Cybercrime, Cybersecurity and Infrastructure Security Agency (CISA), Exploits, Global Security News, Research, Technology, Threats
Ivanti’s EPMM is under active attack, thanks to two critical zero-days
Attackers are again focusing on a familiar target in the network edge space, actively exploiting two critical zero-day vulnerabilities in Ivanti software that allows administrators to set mobile device and application controls. The vulnerabilities — CVE-2026-1281 and CVE-2026-1340 — each carry a CVSS rating of 9.8 and allow unauthenticated users to execute code remotely in…
APT, Asia Pacific, Authentication, Cybercrime, Global Security News, Research, Threats
China-based espionage group compromised Notepad++ for six months
A China-based threat group operating for almost two decades broke into the internal systems of Notepad++, an extremely popular open source-code editor, to spy on a select group of targeted users, researchers at Rapid7 said Monday. Don Ho, the author and maintainer of the open-source tool, said independent security researchers confirmed a China state-sponsored group…
APT, Asia Pacific, Authentication, Cybercrime, Global Security News, Research, Threats
China-based espionage group compromised Notepad++ for six months
A China-based threat group operating for almost two decades broke into the internal systems of Notepad++, an extremely popular open source-code editor, to spy on a select group of targeted users, researchers at Rapid7 said Monday. Don Ho, the author and maintainer of the open-source tool, said independent security researchers confirmed a China state-sponsored group…
crowdstrike, Cybersecurity, Europe, Global Security News, Research, Threats
Long-running North Korea threat group splits into 3 distinct operations
A North Korea-backed threat group operating since 2009 has splintered into three distinct groups with specialized malware and objectives, CrowdStrike said in a report released Thursday. Labeled “Labyrinth Chollima” by the company, the group follows a divergence pattern CrowdStrike observed previously. Labyrinth Chollima has spawned two additional groups: Golden Chollima and Pressure Chollima. The spin-offs,…
china, Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Threats
Cybercriminals and nation-state groups are exploiting a six-month old WinRAR defect
Google Threat Intelligence Group warned that a diverse and growing collection of attackers, including nation-state groups and financially motivated cybercriminals, are exploiting a path-traversal vulnerability affecting WinRAR that was disclosed and patched six months ago. The high-severity vulnerability — CVE-2025-8088 — was exploited in the wild almost two weeks before RARLAB, the vendor behind the…
AI, Artificial Intelligence (AI), Cybersecurity, Exploits, Global Security News, Research
Some ChatGPT browser extensions are stealing your data
ChatGPT users beware: your browser extensions could be used to steal your accounts and identity. LayerX Research has identified at least 16 Chrome browser extensions for ChatGPT floating around the internet that promise to enhance work productivity. All show signs of being built by the same threat actor and designed for the same purpose: to…
CISO, Global Security News, Press Release, report, Research
New Research Exposes Critical Gap: 64% of Third-Party Applications Access Sensitive Data Without Authorization
Boston, MA, USA, 21st January 2026, CyberNewsWire
AI, Asia Pacific, Cybersecurity, Global Security News, Policy, Research, Uncategorized
HackerOne rolls out industry framework to support ‘good faith’ AI research
Four years ago, the Department of Justice announced it would no longer seek criminal charges against independent and third-party security researchers for “good faith” security research under the Computer Fraud and Abuse Act. Now, a prominent bug bounty platform is attempting to build a framework for industry to offer similar protections to researchers who study…
CISO, Global Security News, MSP, North America, Press Release, Research
Airlock Digital Announces Independent TEI Study Quantifying Measurable ROI & Security Impact
Atlanta, GA, United States, 20th January 2026, CyberNewsWire
CVE, Cybersecurity and Infrastructure Security Agency (CISA), Exploits, Global Security News, Government, Research
CISA’s secure-software buying tool had a simple XSS vulnerability of its own
A Cybersecurity and Infrastructure Security Agency tool dedicated to helping government agencies buy secure software turned out to have a cybersecurity vulnerability of its own. Jeff Williams, the former leader of the Open Worldwide Application Security Project (OWASP), told CyberScoop that he discovered a cross-site scripting vulnerability in CISA’s “Software Acquisition Guide: Supplier Response Web…
Exploits, Global Security News, Intellexa, Jamf, privacy, Research, Technology
Predator spyware demonstrates troubleshooting, researcher-dodging capabilities
Predator spyware operators have the ability to recognize why an infection failed, and the tech has more sophisticated capabilities for averting detection than previously known, according to research published Wednesday. Jamf Threat Labs found from an analysis of a Predator sample that it has an error code system that can alert operators to why an…
Australia, Cybercrime, Cybersecurity, Global Security News, North America, Research
Microsoft seizes RedVDS infrastructure, disrupts fast-growing cybercrime marketplace
Microsoft announced Wednesday that it worked with international law enforcement to seize infrastructure used to run cybercrime subscription service RedVDS and organized civil actions in the United States and United Kingdom to disrupt its further use. RedVDS has enabled at least $40 million in fraud losses in the U.S. since March 2025, according to Microsoft.…
Exploits, Global Security News, Microsoft, Patch Tuesday, Research, Threats
Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day
Microsoft’s first security update of 2026 addressed 112 vulnerabilities affecting its products and underlying systems, including one actively exploited zero-day in Desktop Window Manager. The company’s latest Patch Tuesday update marks the second consecutive month with no critical vulnerabilities disclosed. The batch of patches also contains more than 110 CVEs for the second January in…
AI, Cybersecurity, Exploits, Global Security News, prompt injection, Research, Threats
ServiceNow patches critical AI platform flaw that could allow user impersonation
ServiceNow has addressed a critical security vulnerability in its AI platform that could have allowed unauthenticated users to impersonate legitimate users and perform unauthorized actions, the company disclosed Monday. The flaw, designated CVE-2025-12420 and carrying a severity score of 9.3 out of 10, was discovered by SaaS security firm AppOmni in October. ServiceNow deployed fixes…
AI, Cybersecurity, Exploits, Global Security News, n8n, Research, Threats
Researchers rush to warn defenders of max-severity defect in n8n
Researchers warn that a critical vulnerability in n8n, an automation platform that allows organizations to integrate AI agents, workflows and hundreds of other enterprise services, could be exploited by attackers to achieve full control of targeted networks. The maximum-severity vulnerability — CVE-2026-21858 — affects about 100,000 servers globally, according to Cyera, which initially discovered and…
AI, Artificial Intelligence (AI), Cybersecurity, Emerging Tech, Global Security News, Research
OpenAI says prompt injection may never be ‘solved’ for browser agents like Atlas
OpenAI is warning that prompt injection, a technique that hides malicious instructions inside ordinary online content, is becoming a central security risk for AI agents designed to operate inside a web browser and carry out tasks for users. The company said it recently shipped a security update for ChatGPT Atlas after internal automated red-teaming uncovered…
CISA, Cybersecurity, Exploits, Global Security News, Research, Threats
MongoBleed defect swirls, stamping out hope of year-end respite
Cybersecurity professionals are closing out 2025 confronting yet another information-disclosure vulnerability, drawing widespread concern as threat hunters and researchers race to avoid impacts comparable to previous defects dubbed with a “bleed” suffix. MongoBleed — CVE-2025-14847 — is a high-severity vulnerability affecting many versions of MongoDB with default configurations that allows unauthenticated attackers to leak server…
APT, china, Cybersecurity, Exploits, Global Security News, Research, Threats
Cisco customers hit by fresh wave of zero-day attacks from China-linked APT
Cisco customers are confronting a fresh wave of attacks from a Chinese threat group that has actively exploited a critical zero-day vulnerability affecting the vendor’s software for email and web security since at least late November, the company said in an advisory Wednesday. Cisco said it became aware of the attacks Dec. 10. The defect…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
React2Shell fallout spreads to sensitive targets as public exploits hit all-time high
Fallout from React2Shell — a stubborn vulnerability that impacts wide swaths of the internet’s scaffolding — continues to spread as public exploits and stealth backdoors proliferate and worrying details emerge about the targets attackers are pursuing. Threat researchers and incident responders are reacting to swift-moving developments on React2Shell with mounting concern. Cybercriminals, ransomware gangs and…
Cybersecurity, Exploits, Geopolitics, Global Security News, Research, Threats
Amazon warns that Russia’s Sandworm has shifted its tactics
Attackers associated with Russia’s Main Intelligence Directorate (GRU) have targeted Western-based critical infrastructure with a special focus on the energy sector as part of an ongoing campaign dating back to 2021, Amazon Threat Intelligence said in a report Monday. The threat group simplified operations earlier this year by shifting away from vulnerability exploitation to focus…
Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Threats
Attacks pinned to critical React2Shell defect surge, surpass 50 confirmed victims
Security experts have observed a steady increase in malicious activity from a widening pool of attackers seeking to exploit React2Shell, a critical vulnerability disclosed last week in React Server Components. Authorities are also responding to heightened concern about the defect, with the Cybersecurity and Infrastructure Security Agency shortening the deadline for agencies to patch the…
AI, Artificial Intelligence (AI), Cybersecurity, Global Security News, Government, Research
UK cyber agency warns LLMs will always be vulnerable to prompt injection
The UK’s top cyber agency issued a warning to the public Monday: large language model AI tools may always contain a persistent flaw that allows malicious actors to hijack models and potentially weaponize them against users. When ChatGPT launched in 2022, security researchers began testing the tool and other LLMs for functionality, security and privacy.…
Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Threats
Attackers hit React defect as researchers quibble over proof
Attackers of different origins and motivations swiftly exploited a critical vulnerability dubbed React2Shell, affecting React Server Components shortly after Meta and the React team publicly disclosed the flaw with a patch Wednesday. Multiple security firms are actively responding to active exploitation in the wild as a scrum of reports conclude the malicious activity is limited…
Asia Pacific, Cybersecurity, Global Security News, Government, Research, Threats
Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware
Cybersecurity authorities and threat analysts unveiled alarming details Thursday about a suspected China state-sponsored espionage and data theft campaign that Google previously warned about in September. The outlook based on their limited visibility into China’s sustained ability to burrow into critical infrastructure and government agency networks undetected, dating back to at least 2022, is grim.…
Global Security News, Press Release, Research
SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware
Austin, TX, USA, 4th December 2025, CyberNewsWire
Cybercrime, Cybersecurity, Exploits, Global Security News, Meta, Research, Threats
Developers scramble as critical React flaw threatens major apps
Security researchers and code developers are scrambling to patch and investigate a critical vulnerability affecting React Server Components, an open-source library used widely across the internet and embedded into many essential software frameworks. The rapid response underscores the potential consequences of exploitation. Although no attacks have been observed or reported, researchers expect them soon and…
Global Security News, Press Release, report, Research
BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year
New York, New York, 1st December 2025, CyberNewsWire
Global Security News, Press Release, report, Research
BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year
New York, New York, 1st December 2025, CyberNewsWire
AI, Artificial Intelligence (AI), Cybersecurity, Exploits, Global Security News, Research, Technology
Underground AI models promise to be hackers ‘cyber pentesting waifu’
As legitimate businesses purchase AI tools from some of the largest companies in the world, cybercriminals are accessing an increasingly sophisticated underground market for custom LLMs designed to assist with lower-level hacking tasks. In a report published Tuesday, Palo Alto Networks’ Unit 42 looked at how underground hacking forums advertise and sell custom, jailbroken, and…
Cybersecurity, Exploits, GitHub, Global Security News, Research, Threats
Shai-Hulud worm returns stronger and more automated than ever before
Security researchers and authorities are warning about a fresh wave of supply-chain attacks linked to a self-replicating worm that attackers have injected into almost 500 npm (node.js package manager) software packages, exposing more than 26,000 open-source repositories on GitHub. The trojanized npm packages, which were first discovered late Sunday by Charlie Eriksen, security researcher at…
AI, ai safety, Cybersecurity, Global Security News, Research, Technology
New research finds that Claude breaks bad if you teach it to cheat
According to Anthropic, its large language model Claude is designed to be a “harmless” and helpful assistant. But new research released by the company Nov. 21 shows that when Claude is taught to cheat in one area, it becomes broadly malicious and untrustworthy in other areas. The research, conducted by 21 people — including contributors…
Amazon, Cybersecurity, Global Security News, Research, Threats
Amazon warns of global rise in specialized cyber-enabled kinetic targeting
Amazon said the lines between cyberattacks and physical, real-world attacks are blurring quickly — prompting the tech giant to call for a new category of warfare: cyber-enabled kinetic targeting. Nation-states have combined and understood how logical systems and the physical world interact for a long time, but more non-traditional attackers are showcasing expertise in using…
AI, Artificial Intelligence (AI), Cybersecurity, Exploits, Global Security News, Research
Hackers turn open-source AI framework into global cryptojacking operation
Malicious hackers have been attacking the development environment of an open-source AI framework, twisting its functions into a global cryptojacking bot for profit, according to researchers at cybersecurity firm Oligo. The flaw exists in an Application Programming Interface for Ray, an open-source framework for automating, scaling and optimizing compute resources that Oligo researchers called “Kubernetes…
CISA, Cybersecurity, Cybersecurity and Infrastructure Security Agency (CISA), Exploits, Global Security News, Research, Threats
Fortinet’s delayed alert on actively exploited defect put defenders at a disadvantage
Federal authorities and researchers alerted organizations Friday to a massively exploited vulnerability in Fortinet’s web application firewall. While the actively exploited critical defect poses significant risk to Fortinet’s customers, researchers are particularly agitated about the vendor’s delayed communications and, ultimately, post-exploitation warnings about the vulnerability. Fortinet addressed CVE-2025-64446 in a software update pushed Oct. 28,…
AI, Asia Pacific, Cybersecurity, Geopolitics, Global Security News, Research, Technology
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work
Anthropic made headlines Thursday when it released research claiming that a previously unknown Chinese state-sponsored hacking group used the company’s Claude AI generative AI product to breach at least 30 different organizations. According to Anthropic’s report, the threat actor was able to bypass Claude’s security guardrails using two methods: breaking up the work into discrete…
Asia Pacific, china, Financial, Global Security News, Research, Threats
Google, researchers see signs that Lighthouse text scammers disrupted after lawsuit
The phishing kit Lighthouse, which has aided text scams like those soliciting victims to pay unpaid road tolls, appears to have been hampered shortly after Google filed a lawsuit aimed at its creators. Google said on Thursday that Lighthouse had been shut down. Two other organizations that have tracked the suspected Chinese operators of Lighthouse…
Amazon, Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Threats
Amazon pins Cisco, Citrix zero-day attacks to APT group
Amazon’s threat intelligence team said it observed an advanced persistent threat group exploiting zero-day vulnerabilities affecting Cisco Identity Service Engine and Citrix NetScaler products before the vendors disclosed and patched the defects last summer. Amazon’s MadPot honeypot service detected active exploitation of the critical defects — CVE-2025-5777 in Citrix and CVE-2025-20337 in Cisco — and…
AI, AI Security, Amazon, Cybersecurity, Exploits, Global Security News, Research
Amazon rolls out AI bug bounty program
Amazon became the latest company to open its large language models to outside security researchers, announcing the creation of a new bug bounty program for the tech giant’s AI tools. The program will allow select third-party researchers and academic teams to prod NOVA, Amazon’s suite of foundational AI models and receive compensation for their findings.…
Cybersecurity, Exploits, Global Security News, Research, Technology, Threats
What’s left to worry (and not worry) about in the F5 breach aftermath
Researchers aren’t very concerned about the dozens of undisclosed F5 vulnerabilities a nation-state attacker stole during a prolonged attack on F5’s internal systems. Yet, the heist of sensitive intelligence from a widely used vendor’s internal network resembles previous espionage-driven attacks that could pose long-term consequences downstream. F5, which became aware of the attack Aug. 9…
Exploits, Geopolitics, Global Security News, privacy, Research, Threats
New Landfall spyware apparently targeting Samsung phones in Middle East
A new commercial-grade spyware has apparently been targeting Samsung Galaxy phones in the Middle East, but it’s not clear who’s behind it, researchers said in a blog post Friday. Whoever’s responsible, they seized upon a previously unknown, unpatched vulnerability known as a zero-day — a flaw Samsung has since closed, the researchers from Palo Alto…
Apple, Cybersecurity, Exploits, Global Security News, Research, Technology, Threats
Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads
Apple disclosed an exceptionally high number of vulnerabilities in core services and components used across its most popular devices, as the tech giant addressed 105 vulnerabilities in MacOS 26.1 and 56 vulnerabilities with the release of iOS 26.1 and iPadOS 26.1. The company’s latest security update includes some flaws that affect software spanning iPhones, Macs…
CISO, Global Security News, Press Release, report, Research
2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks
Baltimore, USA, 4th November 2025, CyberNewsWire
AI, AI Security, Cybersecurity, Exploits, Global Security News, Research, Technology
OpenAI releases ‘Aardvark’ security and patching model
A new security-focused AI model released Thursday by OpenAI aims to automate bug hunting, patching and remediation. The model, powered by ChatGPT-5 and given the name Aardvark, has been used internally at OpenAI and among external partners. Currently offered in an invite-only Beta, it’s designed to continuously scan source code repositories to find known vulnerabilities…
Exploits, Geopolitics, Global Security News, privacy, Research
Hacking Team successor linked to malware campaign, new ‘Dante’ commercial spyware
Kaspersky researchers said Monday that they’ve unearthed a malware campaign they’re linking to the successor company of the infamous Italy-based surveillance tech firm Hacking Team, and at the same time discovered new commercial malware tied to the same firm. The malware campaign that Kaspersky dubbed Operation ForumTroll targeted government organizations, media outlets, financial institutions, universities,…
Cybersecurity, Exclusive, Global Security News, Research, Threats
Researchers track surge in high-level Smishing Triad activity
Researchers have uncovered a long-running phishing campaign that uses text messages to trick victims, and it’s both bigger and more complex than previously thought. The operation, dubbed Smishing Triad, is managed in Chinese and involves thousands of malicious actors, including dozens of active, high-level participants, Palo Alto Networks’ research unit told CyberScoop. Unit 42 has…
Cybersecurity, Exploits, Global Security News, Research, Technology
Researchers uncover remote code execution flaw in abandoned Rust code library
Security specialists at Edera discovered and disclosed a high-severity vulnerability in an early and since-abandoned code for an open-source async tar archive library for the Rust programming language. Researchers warned that potential exploitation, which allows for remote code execution, could bear major impacts due to widespread forking and a lack of visibility into the code’s…
CVE, Cybersecurity, Global Security News, Government, Research
Behind the struggle for control of the CVE program
On April 16, less than a month after nonprofit R&D organization MITRE celebrated the 25th anniversary of the Common Vulnerability and Exposures (CVE) effort, the program narrowly escaped a sudden demise when a last-minute, 11-month contract extension averted a shutdown. That near-miss put vulnerability experts and cybersecurity defenders on edge, most of whom still fear…
Cisco Talos, Cybersecurity, Global Security News, Ransomware, Research, Threats
North Korean operatives spotted using evasive techniques to steal data and cryptocurrency
North Korean operatives that dupe job seekers into installing malicious code on their devices have been spotted using new malware strains and techniques, resulting in the theft of credentials or cryptocurrency and ransomware deployment, according to researchers from Cisco Talos and Google Threat Intelligence Group. Cisco Talos said it observed an attack linked to Famous…
APT, china, Cybersecurity, Exploits, Global Security News, Government, Research
Flax Typhoon can turn your own software against you
By Derek B. Johnson For more than a year, hackers from a Chinese state-backed espionage group maintained backdoor access to a popular software mapping tool by turning one of its own features into a webshell, according to new research from ReliaQuest. In a report published Tuesday, researchers said that Flax Typhoon — a group that…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Fortra cops to exploitation of GoAnywhere file-transfer service defect
Fortra, in its most forceful admission yet, confirmed a maximum-severity defect it disclosed in GoAnywhere MFT has been actively exploited in attacks, yet researchers are still pressing the vendor to be more forthcoming about how attackers obtained a private key required to achieve exploitation. The vendor published a summary of its investigation into CVE-2025-10035 Thursday,…
Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Technology, Threats
SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal
A brute-force attack exposed firewall configuration files of every SonicWall customer who used the company’s cloud backup service, the besieged vendor said Wednesday. An investigation aided by Mandiant confirmed the totality of compromise that occurred when unidentified attackers hit a customer-facing system of SonicWall controls. The company previously said less than 5% of its firewall…
Clop, Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Dozens of Oracle customers impacted by Clop data theft for extortion campaign
Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday. “We’re still assessing the scope of this incident,…
Clop, Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Dozens of Oracle customers impacted by Clop data theft for extortion campaign
Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday. “We’re still assessing the scope of this incident,…
Clop, Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Dozens of Oracle customers impacted by Clop data theft for extortion campaign
Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday. “We’re still assessing the scope of this incident,…
Clop, Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Dozens of Oracle customers impacted by Clop data theft for extortion campaign
Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday. “We’re still assessing the scope of this incident,…
Clop, Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Dozens of Oracle customers impacted by Clop data theft for extortion campaign
Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday. “We’re still assessing the scope of this incident,…
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Breach, CISO, Global Security News, Press Release, Research
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution
Palo Alto, California, 9th October 2025, CyberNewsWire
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175
Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday. Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175
Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday. Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175
Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday. Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175
Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday. Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research
Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175
Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday. Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Oracle zero-day defect amplifies panic over Clop’s data theft attack spree
Federal cyber authorities and threat hunters are on edge following Oracle’s Saturday disclosure of an actively exploited zero-day vulnerability the Clop ransomware group used to initiate a widespread data theft and extortion campaign researchers initially warned about last week. Oracle addressed the critical vulnerability — CVE-2025-61882 affecting Oracle E-Business Suite — in a security advisory…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Oracle zero-day defect amplifies panic over Clop’s data theft attack spree
Federal cyber authorities and threat hunters are on edge following Oracle’s Saturday disclosure of an actively exploited zero-day vulnerability the Clop ransomware group used to initiate a widespread data theft and extortion campaign researchers initially warned about last week. Oracle addressed the critical vulnerability — CVE-2025-61882 affecting Oracle E-Business Suite — in a security advisory…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Oracle zero-day defect amplifies panic over Clop’s data theft attack spree
Federal cyber authorities and threat hunters are on edge following Oracle’s Saturday disclosure of an actively exploited zero-day vulnerability the Clop ransomware group used to initiate a widespread data theft and extortion campaign researchers initially warned about last week. Oracle addressed the critical vulnerability — CVE-2025-61882 affecting Oracle E-Business Suite — in a security advisory…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Oracle zero-day defect amplifies panic over Clop’s data theft attack spree
Federal cyber authorities and threat hunters are on edge following Oracle’s Saturday disclosure of an actively exploited zero-day vulnerability the Clop ransomware group used to initiate a widespread data theft and extortion campaign researchers initially warned about last week. Oracle addressed the critical vulnerability — CVE-2025-61882 affecting Oracle E-Business Suite — in a security advisory…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Oracle zero-day defect amplifies panic over Clop’s data theft attack spree
Federal cyber authorities and threat hunters are on edge following Oracle’s Saturday disclosure of an actively exploited zero-day vulnerability the Clop ransomware group used to initiate a widespread data theft and extortion campaign researchers initially warned about last week. Oracle addressed the critical vulnerability — CVE-2025-61882 affecting Oracle E-Business Suite — in a security advisory…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks
When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways. Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks
When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways. Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks
When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways. Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks
When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways. Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks
When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways. Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
SonicWall firewalls targeted by fresh Akira ransomware surge
Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. Researchers have since observed another wave of ransomware attacks linked to active exploits of the defect,…
Cybercrime, Cybersecurity, Financial, Global Security News, Money, Research
The npm incident frightened everyone, but ended up being nothing to fret about
Security professionals and observers across the industry got swept into a pit of fear Monday when an attacker took over and injected malicious code into a series of widely used open-source packages in the node.js package manager, or npm. Despite all that worry, the disaster that many presumed a foregone conclusion was averted and the…
Cybersecurity, Exploits, Global Security News, Microsoft, Research, Threats
Microsoft Patch Tuesday addresses 81 vulnerabilities, none actively exploited
Microsoft addressed 81 vulnerabilities affecting its enterprise products and underlying Windows systems, but none have been actively exploited, the company said in its latest security update. The company’s monthly bundle of patches includes one high-severity vulnerability and eight critical defects, including three designated as more likely to be exploited. The most severe defect disclosed this…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Salesloft Drift security incident started with undetected GitHub access
Salesloft pinned the root cause of the Drift supply-chain attacks to a threat group gaining access to its GitHub account as far back as March, the company said in an update Saturday. During a 10-day period in mid-August, the threat group compromised and stole data from hundreds of organizations. The threat group, which Google tracks…
AI, Artificial Intelligence (AI), Cybersecurity, Global Security News, malware, Research
NYU team behind AI-powered malware dubbed ‘PromptLock’
Researchers at New York University have taken credit for creating a piece of malware found by third-party researchers that uses prompt injection to manipulate a large language model into assisting with a ransomware attack. Last month, researchers at ESET claimed to have discovered the first piece of “AI-powered ransomware” in the wild, flagging code found…
Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Threats
Sitecore zero-day vulnerability springs up from exposed machine key
An attacker exploited a zero-day vulnerability in Sitecore stemming from a misconfiguration of public ASP.NET machine keys that customers implemented based on the vendor’s documentation, according to researchers. The critical zero-day defect — CVE-2025-53690 — was exploited by the attacker using exposed keys to achieve remote code execution, Mandiant Threat Defense said in a report…
Cybercrime, Cybersecurity, Global Security News, Research, Technology, Threats
Salesloft Drift compromised en masse, impacting all third-party integrations
Salesloft Drift customers are compromised in a much more expansive downstream attack spree than previously thought, potentially ensnaring any user that integrated the AI chat agent platform to another service. “We’re telling organizations to treat any Drift integration into any platform as potentially compromised, so that increases the scope of victims,” Mandiant Consulting CTO Charles…
Cybercrime, Cybersecurity, Exploits, Global Security News, Ransomware, Research, Threats
Microsoft details Storm-0501’s focus on ransomware in the cloud
A financially motivated threat group operating since 2021 has refined its technical tradecraft, honing its focus on cloud-based systems that allow it to expand ransomware operations beyond the scope of on-premises infrastructure, Microsoft Threat Intelligence said in a report released Wednesday. By leveraging cloud-native capabilities, Storm-0501 has exfiltrated large volumes of data with speed, destroying…
AI, Cybercrime, Cybersecurity, Global Security News, Research, Threats
Hundreds of Salesforce customers impacted by attack spree linked to third-party AI agent
Google Threat Intelligence Group warned about a “widespread data theft campaign” that compromised hundreds of Salesforce customers over a 10-day span earlier this month. According to a report published Tuesday, researchers say a threat group Google tracks as UNC6395 stole large volumes of data from Salesforce customer instances by using stolen OAuth tokens from Salesloft…
AI, Cybercrime, Cybersecurity, Global Security News, Research, Threats
Hundreds of Salesforce customers impacted by attack spree linked to third-party AI agent
Google Threat Intelligence Group warned about a “widespread data theft campaign” that compromised hundreds of Salesforce customers over a 10-day span earlier this month. According to a report published Tuesday, researchers say a threat group Google tracks as UNC6395 stole large volumes of data from Salesforce customer instances by using stolen OAuth tokens from Salesloft…
AI, Cybersecurity, Global Security News, Research, vibe coding, vulnerabilities
Cursor’s AI coding agent morphed ‘into local shell’ with one-line prompt attack
Threat researchers at AimLabs on Friday disclosed a data-poisoning attack affecting the AI-powered code editing software Cursor that would have given an attacker remote code execution privileges over user devices. According to AimLabs, the flaw was reported to Cursor on July 7 and a patch was included in an update one day later for version…
Cybercrime, Cybersecurity, Geopolitics, Global Security News, Ransomware, Research
Social engineering attacks surged this past year, Palo Alto Networks report finds
Social engineering — an expanding variety of methods that attackers use to trick professionals to gain access to their organizations’ core data and systems — is now the top intrusion point globally, attracting an array of financially motivated and nation-state backed threat groups. More than one-third (36%) of the incident response cases Palo Alto Networks’…
APT, Asia Pacific, Cybersecurity, Geopolitics, Global Security News, Research, Threats
Russia-affiliated Secret Blizzard conducting ongoing espionage against embassies in Moscow
A Russian nation-state threat group has been spying on foreign diplomats, managing continuous access to their communications and data in Moscow since at least 2024, according to Microsoft Threat Intelligence. Secret Blizzard is gaining “adversary-in-the-middle” positions on Russian internet service providers and telecom networks by likely leveraging surveillance tools and deploying malware on targeted devices,…
Cybercrime, Cybersecurity, Exploits, Global Security News, Google, Research, Technology
Project Zero disclosure policy change puts vendors on early notice
Google this week changed how it publicly discloses vulnerabilities in a bid to give defenders early details about new software defects it discovers, shortening the early window of time between a vendor releasing a patch and customers installing the security update. Project Zero, Google’s squad of security researchers who find and study zero-day vulnerabilities, will…
Cybercrime, Cybersecurity, Data Breaches, Global Security News, Research, Threats
Research shows data breach costs have reached an all-time high
The average cost of a data breach for U.S. companies jumped 9% to an all-time high of $10.22 million in 2025, as the global average cost fell 9% to $4.44 million, IBM said in its 20th annual Cost of a Data Breach Report Wednesday. While shorter investigations are pushing down costs globally, reflecting the first…
AI, Gemini Advisory, Global Security News, Google, Research
Researchers flag flaw in Google’s AI coding assistant that allowed for ‘silent’ code exfiltration
Researchers have disclosed a vulnerability in Gemini Command Line Interface (CLI), Google’s latest piece of “agentic” AI software for code development. The flaw, which was reported to Google and patched prior to disclosure, would have allowed an attacker to silently execute arbitrary code on a user’s machine. In one video demonstration, a researcher interacts with…
Cybercrime, Cybersecurity, Exploits, Global Security News, Government, Ransomware, Research
Microsoft SharePoint attacks ensnare 400 victims, including federal agencies
The fallout from an attack spree targeting defects in on-premises Microsoft SharePoint servers continues to spread nearly a week after zero-day exploits were discovered, setting off alarms across the globe. More than 400 organizations have been actively compromised across four waves of attacks, according to Eye Security. Multiple government agencies, including the Departments of Energy,…
Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Technology, Threats
Cisco network access security platform vulnerabilities under active exploitation
A pair of maximum-severity vulnerabilities affecting Cisco’s network access security platform are under active exploitation, the enterprise networking and IT vendor warned in a security advisory Monday. The software defects in Cisco Identity Services Engine and Cisco ISE Passive Identity Connector — CVE-2025-20281 and CVE-2025-20337 — were disclosed and addressed by Cisco on June 25,…
china, Cybercrime, Cybersecurity, Exploits, Global Security News, Research, Threats
Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups
Microsoft said two China nation-state threat groups and a separate attacker based in China are exploiting the zero-day vulnerabilities that first caused havoc to SharePoint servers over the weekend. Linen Typhoon and Violet Typhoon — the Chinese government-affiliated threat groups — and an attacker Microsoft tracks as Storm-2603 are exploiting the pair of zero-day vulnerabilities…
CISO, Global Security News, North America, Press Release, report, Research
New Report Reveals Just 10% of Employees Drive 73% of Cyber Risk
Austin, United States / TX, 22nd July 2025, CyberNewsWire
Cybersecurity, Cybersecurity and Infrastructure Security Agency (CISA), Exploits, Global Security News, Research, Technology, Threats
Mass attack spree hits Microsoft SharePoint zero-day defect
Attackers are actively exploiting a critical zero-day vulnerability affecting on-premises Microsoft SharePoint servers, prompting industry heavyweights to sound the alarm over the weekend. Researchers discovered the active, ongoing attack spree Friday afternoon and warnings were issued en masse by Saturday evening. Microsoft released urgent guidance Saturday, advising on-premises SharePoint customers to turn on and properly…
