Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
‘Turf War’ Between Claude Agents Leads to Self-Replicating Malware
Video Call Exploit Chains Two Flaws in Unisoc Modems
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias “
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
The issue was present in .github/workflows/jira_issue.yml, which ran when a
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.
Released on
Irregular Details How a Naming Error Let AI Models Attack a Real Company
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models.
The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek.
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation.
“SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code
Recent Comments