Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
Adversaries Don’t Need a Zero-Day — They Read Your Rulebook
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.
The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek.
PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek.
New GitHub, PyPI Policies Boost Supply Chain Security
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.
The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek.
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
Recent Comments