cybersecurity news

Adform is telling people to clear their browser cache because the altered file may remain cached after the fix, and to check any wallet address before sending funds. Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. “We are proactively expanding protections in https://corporatenex.com/top-10-supply-chain-risk-management-strategies.html response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant. While the intruders were still active inside the network, and customers lost neither heat nor electricity.

More alerts are making your team slower, and an outcome-based SOC fixes that July 20, 2026 Google’s $10,000 refund test shows why AI agents need zero trust August 18, 2026 Microsoft’s August 2026 Patch Tuesday fixes roughly 400 flaws, including three Zero-days, with one actively exploited and two publicly disclosed. NIST seeks input on modernizing the National Vulnerability Database as AI reshapes vulnerability management, risk assessment and remediation. As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question… The program could allow vetted private US companies to access targeted systems without the owner’s authorization and, in more disruptive operations, damage or destroy systems or infrastructure.

  • The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.
  • The trust framework underlying Belgium’s electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
  • The August 2026 Android security update has arrived, but Google hasn’t listed the vulnerabilities it fixes.
  • Google’s $10,000 refund test shows why AI agents need zero trust August 18, 2026
  • Data-theft campaign targets misconfigured Salesforce and ServiceNow instances.

As cyber attacks grow more sophisticated, organisations operating on modern multi-cloud platforms require the right tools and safety protocols to survive… Mandy Lamb, Head of Value-Added Services at Visa Europe, contends that Visa’s new platform will help financial institutions identify cyber risks earlier… GCU’s Dana Gonderzik provides insights on leading a people-first security strategy and staying ahead of AI-driven threats in a rapidly evolving sector…

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. This abuse has caused people to believe that fake images and videos are genuine and dismiss real content as misinformation.

Microsoft Adds Customizable Context Menu to Windows 11 File Explorer

  • The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.
  • Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer’s entire package…
  • Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised.
  • Protect your business against the most common cyber threats with Cyber Essentials.
  • SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.

They also discuss OpenAI’s Trusted Access for Cyber program and what it takes to give security practitioners access to powerful AI capabilities while managing the risks of misuse. Breaking cybersecurity news, news analysis, commentary, and other content from around the world. Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America. The trust framework underlying Belgium’s electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.

cybersecurity news

But ASSET Research Group’s tests show agents can still combine instructions across them in the same working context, so no single fragment has to contain the whole mal… The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools. As of this month, the group has claimed 96 victims , with most of them located in Italy, Spain, Poland, Türkiye, and the U.S. DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026.

GitHub Outage Disrupts Developers Worldwide Amid Ongoing Investigation

cybersecurity news

The real problem may be who owns the fixes, not the security team tracking them. The tactic disabled endpoint defenses as intended, but also accidentally broke the ransomware’s encryption process. Given the urgency, analysts and consultants want to hear more about what to do when agents https://medhaavi.in/why-tiktok-and-other-58-apps-banned-in-india/ go rogue, as well as how to better control all agent actions. TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure.

Sogang University data breach exposes information of 180,000 people

  • As part of Dark Reading’s 20th anniversary celebration, we trace the industry’s evolution through a technology lens.
  • A new “Pass-the-Passkey” family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security even when cryptographic private keys remain securely stored inside hardware tokens or trusted enclaves.
  • The artificial intelligence (AI) company said it’s making GPT 5.6 Cyber available through Daybreak Red, a new tier that provides access to its purpose-trained cybersecurity models to other firms for authorized vulnerability research, exploit validation, and security testing.
  • Hackers used compromised credentials to access enterprise and personal tax-related data.
  • GBHackers on Security is a top cybersecurity news platform, delivering up-to-date coverage on breaches, emerging threats, malware, vulnerabilities, and global cyber incidents.
  • It also worked with Salesforce to roll out new detection and governance tooling aimed at addressing the activity authentication logs miss.

As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. In at least one compromised instance, the attacks led to the deployment of a backdoor and. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the toolkit’s communication capabilities. Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads.

Google Chrome’s Security Update Decision—New Browser Danger Confirmed

cybersecurity news

In collaboration with our nation’s most critical and innovative private sector companies, the Trump Administration continues to carry out the directives of EO to keep American innovation flourishing and our systems and communities secure. “Through this strategic partnership, we will expand existing security measures to safeguard software and networks in the 21st century and continue to promote advancements in artificial intelligence. “Together with unprecedented coordination and an abundance of tools at the ready, the Trump Administration is defending our nation’s cyber and critical infrastructures through GOLD EAGLE,” said Department of Homeland Security Secretary Markwayne Mullin. GOLD EAGLE is a force multiplier, enabling government and industry to collectively identify risks, prioritize action, and strengthen the resilience of the systems that power our economy, national security, and daily life.

Leave a Reply

Your email address will not be published. Required fields are marked *