Attack & News
Attack & News
Latest cybersecurity news, threat reports, and attack campaigns

NEWSCVE-2025-57777.5 HIGHThe Hacker News25 days ago
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
NEWScriticalThe Register25 days ago
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack

NEWSHackread25 days ago
FortiBleed Credential Theft Connected to INC and Lynx Ransomware
NEWSThe Register25 days ago
Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together

NEWSCyberScoop25 days ago
Alleged longstanding member of Scattered Spider extradited to US

NEWSThe Hacker News25 days ago
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

NEWSBleeping Computer25 days ago
Google loses final appeal to overturn €4.1 billion EU fine

NEWShighSecurityWeek25 days ago
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
NEWShighThe Register25 days ago
Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list

NEWSBleeping Computer25 days ago
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

NEWSSecurityWeek25 days ago
How to Conduct a Successful Audit of AI-Driven Software Development

NEWShighThe Hacker News25 days ago
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
NEWSThe Register25 days ago
Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data

NEWScriticalInfosecurity Magazine25 days ago
Researcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day Exploits

NEWScriticalSecurityWeek25 days ago
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks

NEWSBleeping Computer25 days ago
Microsoft fixes bug that removed Copilot buttons in Outlook

NEWShighInfosecurity Magazine25 days ago
Cybercriminals Pose as Interpol in Phishing Emails to Infect Victims With Ransomware
NEWSThe Register25 days ago
India gives WhatsApp three days to defend username rollout amid security fears

NEWShighBleeping Computer25 days ago
Cisco finally confirms attackers exploiting Unified CM flaw

NEWSThe Hacker News25 days ago
Identity Lifecycle Management Wasn't Built for AI Agents

NEWSSecurityWeek25 days ago
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm

NEWScriticalBleeping Computer25 days ago
CISA: Microsoft SharePoint RCE flaw now actively exploited

NEWShighSecurityWeek25 days ago
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

NEWSBleeping Computer25 days ago
Opera rolls out Paste Protect feature to fight ClickFix attacks

NEWSSecurityWeek25 days ago
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
NEWScriticalThe Register25 days ago
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released

NEWScriticalCVE-2026-456598.8 HIGHSecurityWeek25 days ago
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability

NEWSHackread25 days ago
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation

NEWSInfosecurity Magazine25 days ago
NCSC Shares Tips on How to Make a Pen Tester’s Job Harder

NEWScriticalThe Hacker News25 days ago