Cyber vulnerability sweep picks up Royal Navy drones sending data to China
No, no nasties to see here, guv...
The Register
*** GMail and Validation-Mails *** There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
No, no nasties to see here, guv...
The Register
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]
BleepingComputer
Global malware activity climbed sharply over the past week, with remote access trojans (RATs), information stealers, and loaders all posting significant week-over-week gains, according to threat sample uploads tracked b…
CyberSecurityNews
CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an …
CyberSecurityNews
Malicious extensions are turning a routine developer task into a route for theft. A package named Solidity Pro, promoted as a useful tool for Solidity work in Visual Studio Code, has been used to steal cryptocurrency wa…
CyberSecurityNews
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
BleepingComputer
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.
SecurityWeek
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft. The group has turned memory analysis software into a way to pull password hashes and account data from compromised compu…
CyberSecurityNews
Repairable hardware is little comfort when personal details escape
The Register
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
SecurityWeek
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment pr…
Bruce Schneier
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose accounts can open doors to contracts, payments, customer records, an…
CyberSecurityNews
Phishers are finding OnlyFans subscription upsells profitable enough to fuel massive bot campaigns.
Cybernews
Walk away and hope the classifier catches anything irreversible or destructive
The Register
Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows how old delivery methods can gain new credibility when the bait l…
CyberSecurityNews
*Additional conditions may apply.
Cybernews
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
SecurityWeek
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
BleepingComputer
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.
SecurityWeek
The hack is the first known Australian case of the emerging risk from a new generation of AI agents capable of such autonomous shenanigans.
Cybernews
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards and Maestro payment cards. The now-patched issues…
CyberSecurityNews
Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authenticatio…
CyberSecurityNews
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
SecurityWeek
AI giveth, work taketh.
Cybernews
A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic Script, or VBS, and PowerShell, two tools present on business compute…
CyberSecurityNews
Exposed details may include highly sensitive export-controlled technical info.
Cybernews
RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian add…
CyberSecurityNews
A few years ago, staying connected while travelling usually meant choosing between your home carrier's roaming service and buying a...
Cybernews
Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A new Elastic investigation found a session that opened reverse tunn…
CyberSecurityNews
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The name…
The Hacker News
Europe is supercharging IRIS² with 66 more satellites for secure connectivity.
Cybernews
De Bijenkorf, bol, and Ajax have fallen victim to a breach at a logistics partner. ING and Ace & Tate now join the list of victims.
Cybernews
Ajax is the latest victim of the data breach at CEVA Logistics.
Cybernews
A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident o…
CyberSecurityNews
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding…
The Hacker News
Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results provided in its system card. The model reduced an attacker’s chance o…
CyberSecurityNews
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on S…
SecurityWeek
Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than 1.2GB of RAM just to display a simple forecast and map. The findin…
CyberSecurityNews
PLUS: Hiveminds are emerging to hack the planet, and open-weight models are the new new red scare.
The Register
An Australian man’s AI assistant has become the center of what is being described as the country’s first known autonomous AI cyberattack, after it exploited a security flaw in a gym’s booking system to secure him a clas…
CyberSecurityNews
SANS ISC
This week’s roundup covers active exploitation of Apache Tomcat and SonicWall SMA, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able N-Central, Veeam ONE, Jenkins, and Cisco IOS XE, plus a wave of AI-se…
CyberSecurityNews
Metabase, the widely used open-source business intelligence and data visualization platform, has confirmed that a critical zero-day vulnerability tracked as GHSA-vwf4-m7j8-wcjf was actively exploited in the wild, allowi…
CyberSecurityNews
Microsoft is preparing to roll out a new Security Detection Report inside the Teams admin center, giving administrators a long-awaited, unified way to monitor messaging-based threats across their organization. The featu…
CyberSecurityNews