Skip to content
Live intelligence · last 7 days only

Recent cyber attacks, breaches and security alerts worldwide.

Current reporting from established cyber-security publications and official agencies. The default view shows the last 72 hours; switch to 24 hours or the full 7-day window when you need it.

Automated feedLast refresh 3 minutes ago60 headlines · 19 curated sources · max age 7 days
Freshness
60 matching headlines Only items published within the last 7 days are retained. CZITAPP links to the original publisher.
Dark ReadingGlobal
Cyber security

[Virtual Event] Cybersecurity Outlook 2027

Read original ↗
Unit 42Global
Vulnerability

3 Consulting Myths Debunked by Unit 42 Experts

Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths…

KrebsOnSecurityUS
Ransomware

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100…

Read original ↗
CyberScoopUS
Cyber security

Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty. The post Army soldier sentenced for spree…

Read original ↗
Security AffairsGlobal
Vulnerability

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…

Read original ↗
The RecordGlobal
Cyber security

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat…

The RecordGlobal
Cyber attack / incident

Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings

Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive…

Read original ↗
Dark ReadingGlobal
AI security

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.

Security AffairsGlobal
Cyber attack / incident

Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected…

Dark ReadingGlobal
Cyber attack / incident

What We Missed: Google Gemini Joins the AI Escape Party

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking…

CyberScoopUS
Cloud

Supreme Court permits states to use SAVE database for citizenship checks

Three justices wrote in a dissent that longstanding privacy laws protecting sensitive personal data held by the government should prevent the use of the…

Microsoft Security BlogGlobal
Vulnerability

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance…

Read original ↗
The RecordGlobal
Cyber security

Crypto CEO accuses North Korea of stealing $387 million from Bitget platform

The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the…

SecurityWeekGlobal
Data breach

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.…

The RecordGlobal
Vulnerability

Cyberattack hits Welsh police force, may have affected staff data

Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.

Read original ↗
Dark ReadingGlobal
Vulnerability

Stopping IT Worker Scams Requires Revamped HR Process

Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even…

Read original ↗
The Hacker NewsGlobal
Cyber attack / incident

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during…

SecurityWeekGlobal
Cyber security

North Korea Suspected in $351 Million Bitget Crypto Heist

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North…

Security AffairsGlobal
Cyber attack / incident

ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being…

Read original ↗
The Hacker NewsGlobal
Malware

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.…

Read original ↗
SANS Internet Storm CenterGlobal
Malware

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Introduction

Read original ↗
SecurityWeekGlobal
Vulnerability

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.  The post CISA Election Security Plan Flags Patching Barriers, Voter Database…

SecurityWeekGlobal
Cyber security

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace…

Read original ↗
The RecordGlobal
Cyber attack / incident

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s…

Read original ↗
The Hacker NewsGlobal
Cyber attack / incident

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has…

Read original ↗
SecurityWeekGlobal
Data breach

Windows, Linux, Android File Notification Systems Leak User Activity

Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems…

Read original ↗
The Hacker NewsGlobal
Cyber attack / incident

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  "At 18:31 UTC on September…

Read original ↗
The Hacker NewsGlobal
Vulnerability

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in…

Read original ↗
Security AffairsGlobal
Vulnerability

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based…

Read original ↗
SecurityWeekGlobal
Vulnerability

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce…

Read original ↗
Security AffairsGlobal
Vulnerability

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency…

Read original ↗
Dark ReadingGlobal
Cyber security

Russia's Hybrid Cyber-Physical War in Europe Heats Up

A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to…

Read original ↗
SecurityWeekGlobal
Vulnerability

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs…

Read original ↗
The Hacker NewsGlobal
Cyber security

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and…

Read original ↗
The Hacker NewsGlobal
Vulnerability

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its…

Read original ↗
SANS Internet Storm CenterGlobal
Cyber security

ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read original ↗
CyberScoopUS
Critical infrastructure

House and Senate members propose legislation for CISA to step up cyber defenses for biotech

Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. The post…

Dark ReadingGlobal
Vulnerability

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.

Security AffairsGlobal
Cyber security

Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison

Ryuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution. Karen…

SecurityWeekGlobal
AI security

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high…

Dark ReadingGlobal
Malware

SectopRAT Returns, Hiding Inside a Legitimate Application

The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts…

The RecordGlobal
Critical infrastructure

Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges

Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the…

Read original ↗
The RecordGlobal
Data breach

Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks

U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was…

Read original ↗
The RecordGlobal
Cyber security

Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation

Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox…

Read original ↗
Security AffairsGlobal
Vulnerability

AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS

MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out…

The Hacker NewsGlobal
Vulnerability

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions.…

CyberScoopUS
Cyber attack / incident

New bill would create federal investigative body for AI-driven hacks 

A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried…

Cisco TalosGlobal
Vulnerability

Trust and the enticing consultancy offer

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem.…

The Hacker NewsGlobal
Vulnerability

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link…

CyberScoopUS
Cyber security

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud. The post Phone-hacking company that…

Microsoft Security BlogGlobal
Ransomware

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance…

Microsoft Security BlogGlobal
AI security

​​​​​​​​What’s new in Microsoft Security: September 2026​​

This month's updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. The post ​​​​​​​​What’s…

SecurityWeekGlobal
Vulnerability

Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security Emerges…

The Hacker NewsGlobal
Cyber security

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy…

Dark ReadingGlobal
Ransomware

3 Cyber Threats That Defined the Summer of 2026

This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors…

SecurityWeekGlobal
Vulnerability

OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public…

The Hacker NewsGlobal
Cyber attack / incident

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a…

Dark ReadingGlobal
Cyber security

How to Build a SASE Framework for Modern Cybersecurity

Securing edge computing requires organizations to fundamentally rethink security governance. This step-by-step guide to building a SASE framework provides the path forward. (Third in…

CyberScoopUS
Vulnerability

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary…

Dark ReadingGlobal
Cyber security

Ghost Service Accounts Enable M365 Data Theft in Chile

Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.

X