Attack & News

Attack & News

Latest cybersecurity news, threat reports, and attack campaigns

NEWSCVE-2025-57777.5 HIGHThe Hacker News25 days ago

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

NEWScriticalThe Register25 days ago

Smooth AI criminal drives 'first' end-to-end agentic ransomware attack

NEWSHackread25 days ago

FortiBleed Credential Theft Connected to INC and Lynx Ransomware

NEWSThe Register25 days ago

Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together

NEWSCyberScoop25 days ago

Alleged longstanding member of Scattered Spider extradited to US

NEWSThe Hacker News25 days ago

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

NEWSBleeping Computer25 days ago

Google loses final appeal to overturn €4.1 billion EU fine

NEWShighSecurityWeek25 days ago

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

NEWShighThe Register25 days ago

Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list

NEWSBleeping Computer25 days ago

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

NEWSSecurityWeek25 days ago

How to Conduct a Successful Audit of AI-Driven Software Development

NEWShighThe Hacker News25 days ago

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

NEWSThe Register25 days ago

Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data

NEWScriticalInfosecurity Magazine25 days ago

Researcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day Exploits

NEWScriticalSecurityWeek25 days ago

FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks

NEWSBleeping Computer25 days ago

Microsoft fixes bug that removed Copilot buttons in Outlook

NEWShighInfosecurity Magazine25 days ago

Cybercriminals Pose as Interpol in Phishing Emails to Infect Victims With Ransomware

NEWSThe Register25 days ago

India gives WhatsApp three days to defend username rollout amid security fears

NEWShighBleeping Computer25 days ago

Cisco finally confirms attackers exploiting Unified CM flaw

NEWSThe Hacker News25 days ago

Identity Lifecycle Management Wasn't Built for AI Agents

NEWSSecurityWeek25 days ago

Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm

NEWScriticalBleeping Computer25 days ago

CISA: Microsoft SharePoint RCE flaw now actively exploited

NEWShighSecurityWeek25 days ago

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

NEWSBleeping Computer25 days ago

Opera rolls out Paste Protect feature to fight ClickFix attacks

NEWSSecurityWeek25 days ago

‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

NEWScriticalThe Register25 days ago

Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released

NEWScriticalCVE-2026-456598.8 HIGHSecurityWeek25 days ago

CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability

NEWSHackread25 days ago

Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation

NEWSInfosecurity Magazine25 days ago

NCSC Shares Tips on How to Make a Pen Tester’s Job Harder

NEWScriticalThe Hacker News25 days ago

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack