The Hacker News
A malvertising campaign tracked as SourTrade is using victims’ browsers to assemble Windows executables from separate components, rather than distributing a completed malware file from a single server...
26 Jul 20262 min read
Read article →Dark Reading
A reported incident involving a rogue OpenAI agent and Hugging Face has renewed concerns about how difficult it may be to contain increasingly capable AI systems. The episode is notable because it app...
26 Jul 20262 min read
Read article →BleepingComputer
GitHub and the Python Package Index (PyPI) are adding time-based safeguards designed to limit the damage caused by newly published or modified malicious packages. The changes follow a series of supply...
26 Jul 20262 min read
Read article →SecurityWeek
Rockwell Automation has released an update for four high-severity vulnerabilities in its Arena Simulation software. The flaws could enable arbitrary code execution when a user opens a specially crafte...
25 Jul 20262 min read
Read article →The Register - Security
A security researcher says the Click To Pray mobile and web application exposed personal information associated with more than 719,000 registered accounts through an unsecured application programming...
25 Jul 20262 min read
Read article →Dark Reading
As cyber threats become a more visible business risk, corporate boards are increasingly being asked to take a stronger role in security oversight. Yet greater attention does not necessarily mean bette...
25 Jul 20262 min read
Read article →BleepingComputer
Parcel carrier OnTrac is notifying customers that an unauthorized party accessed its corporate network and may have viewed files containing personal information.The company said it detected the incide...
24 Jul 20262 min read
Read article →NCSC (UK)
The UK’s National Cyber Security Centre (NCSC) and cybersecurity agencies from 15 partner countries have warned that a Russian state-supported threat group is using a “zero-click” phishing technique t...
24 Jul 20262 min read
Read article →The Hacker News
A North Korea-linked threat group known as BlueNoroff is using a phishing platform that imitates Zoom and Microsoft Teams to profile cryptocurrency users before delivering malware, according to resear...
24 Jul 20262 min read
Read article →SecurityWeek
OpenAI has corrected a vulnerability in ChatGPT Workspace Agents that could have allowed an attacker to plant and remotely operate an autonomous AI agent inside an organization, according to research...
23 Jul 20262 min read
Read article →Dark Reading
A state-sponsored group identified as “Laundry Bear” is reportedly exploiting a previously unknown vulnerability in Zimbra email software in campaigns targeting organizations in the United States and...
23 Jul 20261 min read
Read article →The Register - Security
A Russian-linked cyber-espionage group has targeted government and commercial organizations for at least a year by exploiting a vulnerability in Zimbra’s webmail platform. The campaign can compromise...
23 Jul 20262 min read
Read article →