Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.
PortSwigger researcher Gareth
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was
Military device manufacturer discloses cyber incident to SEC
New Mexico judge orders Meta to pay $567 million in kids online safety case
US cyber ambassador nominee Cassady confirmed in Senate
Water utilities group partners with DEF CON offshoot for Water Watch Center
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.
AI-Generated Patches Fail Half the Time
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
“These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,” OpenSourceMalware researcher Paul
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
Tracked as CVE-2026-64638 (CVSS score: 8.9), the
Recent Comments