URL has been copied successfully!
URL has been copied successfully!
Collecting Cyber-News from over 60 sources
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Cyber-Security-News

access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure injection intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day

  • KI-Agenten absichern: Warum Identity zum Erfolgsfaktor wird KI braucht Identity Governance

    KI-Agenten versprechen Unternehmen mehr Tempo und Automatisierung, schaffen aber zugleich neue Sicherheitsrisiken. Entscheidend ist deshalb, nicht nur ihre Funktionen, sondern vor allem ihre Identitäten, Berechtigungen und Zugriffe konsequent zu steuern. Wer Identity Governance früh verankert, kann Innovation ermöglichen, ohne Kontrolle und Compliance aus der Hand zu geben. First seen on ap-verlag.de Jump to article: ap-verlag.de/ki-agenten-absichern-warum-identity-zum-erfolgsfaktor-wird-ki-braucht-identity-governance/107027/…

  • Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

    Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,…

  • SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

    The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” First seen on cyberscoop.com Jump to article: cyberscoop.com/supreme-court-ruling-usps-mail-in-ballots/ also interesting: Kein Klick erforderlich: Outlook-Lücke verschafft Angreifern Zugriff per E-Mail [News] Yahoo Mail Cross-Site Scripting Attack…

  • US sanctions Iranian cyber actors as UK discloses power plant attack

    The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom. First seen on therecord.media Jump to article: therecord.media/iran-cyberattacks-us-uk also interesting: Threat Casting a Nation State Attack on Critical Infrastructure Scenario at CognectCon2025 Successful Military Attacks are…

  • Exploited Zimbra Flaw Highlights Shrinking Window to Patch

    CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user’s communications. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/zimbra-flaw-exploitation-shrinking-window-patch also interesting: Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI Warns, as MITRE Updates List of Top Hardware Weaknesses Attackers exploit critical…

  • How ‘Subtractive’ Security Erases Attack Paths

    Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…

  • Russian Backdoor Found in Slovak Traffic Cameras

    SMS Messages Could Enable Remote Access to Live Traffic Feeds. Slovakian cyber authorities have suspended the rollout of high-speed traffic cameras after a security investigation uncovered backdoors and multiple software weaknesses. The devices were reportedly rebranded versions of Russian-made cameras sold through a Cyprus-based company. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645 also interesting:…

  • Alibaba’s AliExpress Uses Hidden Audio to Fingerprint Devices

    Researcher Says Bluetooth Routing Error Exposed a Probe Designed to Run Invisibly. AliExpress used silent WebAudio signals to help fingerprint devices for security and anti-abuse purposes, but an implementation error exposed the normally invisible tracking when Bluetooth headsets detected an active PC audio stream. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/alibabas-aliexpress-uses-hidden-audio-to-fingerprint-devices-a-32646 also interesting: New…

  • Claude Mythos 5 Can Find the Vulnerabilities. But Which Ones Actually Matter?

    <div cla   First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/claude-mythos-5-can-find-the-vulnerabilities-but-which-ones-actually-matter/ also interesting: Peter Schaar Industrie 4.0 unter Beschuss – Warum OT-Segmentierung für die Produktion unverzichtbar wird Von Mobilfunk bis Solaranlagen: Warum die EU jetzt gegen chinesische Technik vorgeht Die meisten Datenverluste passieren ohne böse Absicht – Riskantes Verhalten im Arbeitsalltag lässt sich nicht verbieten

  • What Are the Key Components of HIPAA? A Detailed Breakdown for 2026

    Key Takeaways HIPAA compliance continues to evolve in 2026, but organizations need to distinguish between current requirements and proposed changes. HHS has proposed a substantial update to the HIPAA Security Rule. Until that proposal is finalized, however, covered entities and business associates must continue complying with the Security Rule currently in effect. Understanding the Core……

  • Foul Language: WordlistLoader Disguises Malware as Ordinary Text

    ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer. First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text also interesting: Technical Analysis of RiseLoader Black Hat 2025 Recap: A look at new offerings announced at the show Recognizing and responding to cyber threats: What differentiates NDR, EDR…

  • Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors Hackers Exploit…

  • Anthropic Expands Mythos 5 Access for AI-Assisted Security Audits

    Anthropic expands Mythos 5 access for enterprise security teams, offering AI-assisted vulnerability scanning with safeguards and required human review. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-anthropic-mythos-5-ai-security-audits/ also interesting: Privacy Roundup: Week 3 of Year 2025 7 top cybersecurity projects for 2025 13 cybersecurity myths organizations need to stop believing Key questions CISOs must ask…

  • Google Pixel August Update Fixes High-Severity Security Flaw

    Google’s August 2026 Pixel security update fixes a high-severity privilege escalation flaw. Here’s what Pixel owners need to know. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-google-pixel-august-2026-security-update-flaw/ also interesting: Who’s Afraid of a Toxic Cloud Trilogy? Chrome High-severity Flaws Expose Sensitive Data, Trigger System Crashes Google June 2026 Android Update Patches 124 Flaws, One Actively…

  • TikTok Reaches $400M Settlement With US Over COPPA Violations

    TikTok and ByteDance have agreed to a $400 million settlement with the DOJ to resolve allegations that TikTok violated federal children’s privacy protections. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/tiktok-reaches-400m-settlement-with-us-over-coppa-violations/ also interesting: RSAC 2025 Innovation Sandbox – Knostic: Reshaping the Access Control Paradigm for Enterprise AI Security Todd Snyder subjected to $345K fine over…

  • Instinct’s powerful AI assistant is raising privacy and security concerns

    Early testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/24/instincts-powerful-ai-assistant-is-raising-privacy-and-security-concerns/ also interesting: What is Security Posture Management and Why is it Important? What is Security Posture Management…

  • New Zealand to pursue social media ban for children under 16

    The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification. First seen on therecord.media Jump to article: therecord.media/new-zealand-to-pursue-social-media-ban-for-children also interesting: Solving…

  • The Most Effective Cybersecurity Awareness Programs for Companies (2026)

    <div cla The most effective cybersecurity awareness programs pair phishing simulation testing with role-based training, then tie both to live email threat detection. IRONSCALES, KnowBe4, Proofpoint, Cofense, and Mimecast lead this market. IRONSCALES is the only one that builds awareness training directly into an AI-powered email security platform, so the same system that trains your…

  • Alabama launches investigation into OpenAI’s hack of Hugging Face

    Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/ also interesting: Someone Created First AI-Powered Ransomware Using OpenAI’s gpt-oss:20b Model Someone Created the First AI-Powered Ransomware Using…

  • Inaudible sounds used to fingerprint browsers catch AliExpress red-handed

    Is the technique outdated? Yes. Is it still creepy? Also yes. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/ also interesting: Famous YouTube Channels Hacked to Distribute Infostealers NinjaOne und SentinelOne – Effiziente IT-Sicherheit durch smarte Integration Mozilla investing in Everything.me: Mozilla has announced it is investing in Everything.me, a company that makes… Oettinger allegedly…

  • Hackers target WordPress sites in miniOrange auth bypass attacks

    Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/ also interesting: Password managers under increasing threat as infostealers triple and adapt Cybersecurity…

  • UK power plant shutdown highlights CNI cyber challenges

    An alleged Iranian attack on a small reserve ‘peaker’ power plant went largely unnoticed despite causing four days of downtime. Cyber experts say the incident raises serious questions about CNI resilience. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649386/UK-power-plant-shutdown-highlights-CNI-cyber-challenges also interesting: Iran and China-linked actors used ChatGPT for preparing attacks Fake Job Offers Used to…

  • Thousands of Leaked AWS Access Keys Are Still Active

    Truffle Security found 9,308 leaked AWS keys still active, including 768 corporate credentials with full administrative control of cloud accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-leaked-aws-access-keys-still-active/ also interesting: Top 12 ways hackers broke into your systems in 2024 Business continuity and cybersecurity: Two sides of the same coin Hardening browser security with zero-trust…

  • CISA Orders Civilian Agencies to Patch Exploited TrueConf Server Flaws

    CISA ordered civilian agencies to patch two exploited TrueConf Server flaws used to compromise systems and distribute trojanized client installers. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-cisa-trueconf-server-flaws-patch-order/ also interesting: CISA Flags Critical Palo Alto Network Flaws Actively Exploited in the Wild U.S. CISA adds a flaw in Microsoft Windows to its Known Exploited Vulnerabilities…

  • After Mythos: When the Attacker Doesn’t Need to Log In

    AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…

  • After Mythos: When the Attacker Doesn’t Need to Log In

    AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…

  • AnMed Confirms Data Theft, Warns Patients of Criminal Scams

    Ransomware Gang Gentlemen Says It Stole 6TB of Sensitive Patient Info. Nonprofit health system AnMed has confirmed cybercriminals stole information in a July cyberattack that disrupted its IT environment and patient services for several weeks. The organization is also warning patients not to fall for potential fraud, payment and other scams by criminals. First seen…

  • German Cyber Agency Warns Fingerprints Can Be Spoofed

    BSI Says AI, High-Resolution Photos and 3D Printing Increase Biometric Risks. Germany’s cybersecurity agency is warning against relying solely on fingerprint authentication, saying criminals can use high-resolution photos, AI and 3D printing to create synthetic fingerprints capable of spoofing some biometric systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/german-cyber-agency-warns-fingerprints-be-spoofed-a-32643 also interesting: Cybersecurity Snapshot: AI…

  • Bipartisan Senate bill aims to prepare energy sector for Q-Day

    Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector.  First seen on cyberscoop.com Jump to article: cyberscoop.com/quantum-guard-act-electric-grid-cybersecurity/ also interesting: The most notorious and damaging ransomware of all time Cybersecurity Snapshot: Tenable Highlights Risks of AI Use in the Cloud, as UK’s NCSC…

  • Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’

    It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/ also interesting: Iran-Backed Hackers Blast Out Threatening Texts to Israelis Top 12 ways hackers broke into your systems in 2024 Iran’s MuddyWater Hackers Target US Firms with New…

  • Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

    A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers. First seen on therecord.media Jump to article: therecord.media/cyber-scam-indian-arrested also interesting: Microsoft India’s X account hijacked in Roaring Kitty crypto scam Indian authorities seize loot from collapsed BitConnect crypto scam Google…

  • AliExpress caught fingerprinting visitors after sending inaudible sounds to browsers

    Is the technique outdated? Yes. Is it still creepy? Also yes. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/ also interesting: Der Nachfolger für SHA-2 Forschungsprojekt: Spionage-App fotografiert Büro-Panoramen… Webinar: How to build relationships with developers Interne Kommunikation: Wer die US-Wahlkampfteams gehackt hat

  • BSidesCharm 2026 You Can’t Migrate What You Can’t See: Discovering Real Post-Quantum Crypto

    Presenters: Joseph N Wilson, Anurag Swarnim Yadav Our thanks to BSidesCharm for publishing their Creators, Authors and Presenter’s outstanding BSidesCharm 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidescharm-2026-you-cant-migrate-what-you-cant-see-discovering-real-post-quantum-crypto/ also interesting: SEC reports drop in enforcement actions for 2024 FY >>Aggressive Inventory Zombies<<: Unmasking a Massive Phishing and…

  • Cybercriminals Turn GTA VI Leaks Into Malware Bait

    A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to >>take one for the…

  • TikTok reaches $400M settlement with US over COPPA violations

    The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/legal/tiktok-reaches-400m-settlement-with-us-over-coppa-violations/ also interesting: South Korea Keeps DeepSeek AI Chatbot Off App Stores Tenable Cloud Vulnerability Management: Reducing Vulnerability Risk in…

  • Fake GTA 6 Extended Look and demo sites deliver an infostealer

    Bogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer/ also interesting: Top 7 zero-day exploitation trends of 2024 Privacy Roundup: Week 9 of Year 2025 Privacy Roundup: Week 12 of Year 2025 6 rising malware trends…

  • Randall Munroe’s XKCD ‘Airport Meeting’

    via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/randall-munroes-xkcd-airport-meeting/ also interesting: 11 hottest IT security certs for higher pay today CISA releases Thorium, an open-source, scalable platform for malware analysis Introducing MAESTRO: A framework for securing generative and agentic AI Top 10…

  • New Passkey Attacks Explained: What Security Researchers Found This August

    <div cla Every August, Black Hat and DEF CON turn Las Vegas into what security people only half jokingly call hacker summer camp. This year the nickname earned itself twice over. This week a Delta flight out of Las Vegas landed under investigation for an unauthorized Wi-Fi network onboard, reportedly the work of DEF CON…

  • The Vulnerability Gap: Why Discovery Is Outrunning Repair

    AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair also interesting: The highest-paying jobs in cybersecurity today Old threats, new consequences: 90% of cyber claims stem from email and remote access HackerOne Adds AI Agent…

  • ChatGPT for Teens Adds New Safeguards, but Safety Gaps Remain

    ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards, but Safety Gaps Remain appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chatgpt-teens-safety-gaps/ also interesting: Black Hat SEO Poisoning Search…

  • Microsoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviews

    Microsoft has yet to set a firm Exchange Server SE CU1 release date as engineers work through AI-assisted security findings and ongoing patch releases. The post Microsoft Exchange Server SE CU1 Delayed Amid AI-Assisted Security Reviews appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-exchange-server-se-cu1-delay/ also interesting: Privacy Roundup: Week 3 of…

  • Top 10 Cybersecurity Companies in 2026

    Compare the top cybersecurity companies in 2026, including Cisco, CrowdStrike, Bitdefender, Semperis, and more, to find the right security vendor. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/top-cybersecurity-companies/ also interesting: 7 key trends defining the cybersecurity market today 6 hot cybersecurity trends Wie CISOs vom ERP-Leid profitieren A new approach for GenAI risk protection

  • What a Cloud DDoS Simulation Actually Validates

    A DDoS cloud simulation is a controlled, authorized exercise, not an attempt to overwhelm the cloud provider’s global infrastructure. If you run AWS Shield Advanced or Azure DDoS Network Protection, the practical question is whether that protection performs as expected inside your architecture, against the attack vectors that could realistically reach it. This article covers……

  • How to Run a Recurring DDoS Testing Program

    A practical guide to setting the cadence, onboarding the SOC, closing findings, and working with your testing vendor between engagements Running DDoS testing as a recurring program means linking every planned simulation to remediation, retesting, SOC training, and the next material change in the environment. Unlike a one-off project, it does not end when the……

  • How to Run an Authorized DDoS Test in AWS and Azure

    An authorized DDoS test in AWS or Azure begins by confirming that you own the target, that the relevant DDoS protection service covers it, and that an approved partner will conduct the simulation within the provider’s policy. Under those conditions, separate prior approval is generally not required from AWS or Microsoft. AWS does require an……

  • DDoS Testing Tools: How to Choose a Test That Proves Your Defenses Work

    A practical guide for security teams comparing free tools, self-service platforms, and expert-led testing DDoS testing tools range from free traffic generators to self-service platforms and expert-led simulations. The right choice is not the tool that can simulate DDoS attack traffic at the highest volume, but the one that produces credible evidence about the risks……

  • 3-Legged OAuth (3LO) Explained: How the OAuth Flow Works

    11 min readOAuth, and more specifically OAuth 2.0, is the de facto standard for application authorization. With this framework, you can define a flow to grant access to protected resources. More recently, OAuth 2.1 consolidated the standard by defining security best practices such as Proof Key for Code Exchange (PKCE) and exact URI matching. This…

  • Why Your Engineering Team Secretly Hates Your AI Initiative (And How to Fix It)

    Engineering teams resist AI initiatives over career anxiety and loss of control, not technical doubts. What actually worked leading teams through this at LoginRadius and GrackerAI. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-your-engineering-team-secretly-hates-your-ai-initiative-and-how-to-fix-it/ also interesting: Can AI be Meaningfully Regulated, or is Regulation a Deceitful Fudge? Windows 11 to Deprecate NTLM, Add AI-Powered App…

  • New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

    TCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/guidance-verify-quantum-safe/ also interesting: Zyxel won’t patch endlife routers against zero-day attacks Phishing-Resistant MFA: Why FIDO is Essential The age of infostealers is here. Is your financial service secure? Quantum Breakthroughs Compress…