Latest News
Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
AI agents can misuse legitimate access. Learn why action-level security, trusted policy enforcement and verified approvals are critical to…
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor
Meet ClingSTUN, a new Linux backdoor that exploits IoT vulnerabilities, gives attackers remote command access and turns infected devices into…
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique
Russian group Star Blizzard expands phishing campaigns with a new malware delivery RedFlick technique, using scheduled tasks to deliver the…
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
ShinyHunters hacker “Rey” was detained in Jordan and is reportedly cooperating with the FBI after the group claimed major FBI and corporate…
Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days
Dutch Institute for Vulnerability Disclosure was breached through two Zammad 0-days in an AI-powered attack that led to remote code execution…
367,000-Ship Study Finds Global GPS Spoofing, Red Sea Activity Before Grounding
A study of 367,000 ships finds global GPS spoofing, including Red Sea activity detected months before the MSC Antonia grounding in May 2025.…
KillSec Ransomware Group Dismantled, 16-Year-Old Suspected Admin Arrested
An international police operation has disrupted the KillSec ransomware group, with three suspects arrested, five servers seized and at least…
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
Why Mobile Device Management Needs Its Own Threat Model
Allowing employees to use their own phones for work sounds simple. Deciding how much control IT should have over those devices is where it…
Japanese Car-Sharing Site Times Car Data Breach Affects 6.6M Accounts
Times Mobility says a data breach exposed data linked to 6.6 million accounts, including 1.6 million identity records with driver's license…
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Washignton, DC, USA, 30th September 2026, CyberNewswire
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data, and target Windows…