Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.
Nothing here is especially mystical.
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on,
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.
“These vulnerabilities were found
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which manages shadow page
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene.
The affected products include Amazon
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Huntress, which tracks the toolkit as khunt,
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.
The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek.
Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.
The post Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison appeared first on SecurityWeek.
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.
The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.
Recent Comments