Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.
The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.
MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.
“The flaw lives in the Forms module’s File
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities.
The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek.
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta’s Argo product is now being used to prove the resilience of Viasat’s satellite communications network.
The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek.
Recent Comments