Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
Microsoft Rolls Out 22 Fresh Security Patches
Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities.
The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base.
The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek.
Rust Supply Chain Attack Linked to North Korean Hackers
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant’s cloud-based identity and access management service. It was previously called Azure Active Directory
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –
Senators press TikTok over withholding of safety features for some users
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.
The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.
Recent Comments