The Cronos blockchain network has resumed trading after a price manipulation attack on the Tectonic cryptocurrency lending platform resulted in an attacker borrowing $74 million. The exploit is attributed to an attacker manipulating the price of the CRO token, which was then used to borrow an excessive amount of stablecoins.
Microsoft has identified a bug in Windows that incorrectly reports Microsoft Defender Antivirus as turned off, despite it functioning normally. This issue affects various Windows versions and is being addressed by Microsoft, but industry experts express concern that it could train users to ignore critical security alerts, making them more vulnerable to attacks.
The Department of Defense (DoD) has confirmed refrigeration disruptions at several military commissaries, leading to speculation that these systems may have been hacked. The affected locations include installations across California, Wyoming, Arizona, Rhode Island, and Mississippi.
Microsoft Exchange Online is experiencing a widespread service issue affecting authentication, causing email delays and failures for customers. The company is actively investigating the problem.
OpenAI has confirmed a partial outage affecting ChatGPT, preventing users on various subscription plans from initiating or continuing tasks. The outage is impacting users globally, with many reporting errors.
Chinese Fire Ant hackers are using Cisco routers as spying platforms by exploiting Generic Routing Encapsulation (GRE) tunnels. Researchers discovered an unexplained GRE tunnel interface on a Cisco IOS XR router, indicating a novel attack vector.
File servers continue to be essential in IT infrastructures, but managing their access permissions securely presents challenges due to accumulation over time. tenfold Software provides five best practices to streamline file server administration and enforce least-privilege access.
ServiceNow has released patches for three critical code injection vulnerabilities. These vulnerabilities could allow attackers to execute arbitrary code, potentially leading to unauthorized data access or modification.
This article summarizes several cybersecurity incidents, including a router with a pre-installed backdoor, a fake check used to install malware, and the exploitation of old vulnerabilities. It also touches on issues with AI agents going off-task and the security implications of exposed systems and weak defaults.
A recent incident involving Hugging Face highlights the critical need for security leaders to treat autonomous AI agents as highly privileged identities. This approach is essential for maintaining robust security postures in environments utilizing AI.
Boston Scientific is still experiencing the aftermath of a cyberattack that caused significant global network disruptions. The medical device company has engaged cybersecurity firm CrowdStrike to assist in the ongoing investigation of the incident.
A China-linked threat actor known as Fire Ant has expanded its campaign to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. The actor aims to steal credentials and blind security logs, impacting critical network infrastructure.
Microsoft has advised users to disregard false "Antivirus is turned off" notifications that have appeared after installing the latest Defender updates. This issue is causing confusion for users who believe their protection is compromised when it is not.
AI agents are introducing a new, faster, and more expansive threat to cloud security architectures. These autonomous agents can chain vulnerabilities and exploit misconfigurations at machine speed, making it challenging for organizations to maintain a strong cloud security posture.
FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG). BleepingComputer validated a sample of the stolen data, which included detailed customer, booking, and travel information.
This article announces a virtual event focused on securing enterprise cloud assets in the context of AI advancements. The event aims to inform organizations about the latest strategies and considerations for protecting their cloud environments.
Cosmos Labs has disclosed a critical vulnerability in the shared Cosmos EVM module that was exploited between August 20 and August 25, 2026, leading to the draining of funds from six blockchains. The flaw, identified as GHSA-7g4w-cg88-2cq2, has been rated Critical by Cosmos Labs, though it was released without a CVE or CVSS score.
Researchers have developed a new hardware attack called GPUThor that exploits memory bit flipping techniques to bypass error-correcting codes (ECC) on enterprise Nvidia GPUs. This attack can lead to root access on the underlying system, improving upon previous Rowhammer-style attacks.
Android 17 will introduce new network security features, including support for Encrypted Client Hello (ECH). ECH is a privacy standard designed to prevent network providers from monitoring which websites users visit. These updates aim to improve connection privacy and protect user data on home networks.
The article highlights the challenges of responding to OT cyberattacks due to a lack of data, trails, and history. It suggests that cyber deception techniques are necessary to address these gaps.
Over 8,300 internet-exposed Gitea servers remain vulnerable to critical remote code execution attacks due to unpatched security flaws. Cybersecurity watchdog Shadowserver reported the ongoing exploitation of these vulnerabilities.
An Identity Fabric integrates disparate identity systems to provide a unified view of identity behavior across various applications, APIs, and infrastructure. As enterprises adopt more cloud services and automated workloads, maintaining identity security increasingly relies on real-time visibility rather than static configurations.
Shenzhen Zhibotong Electronics (ZBT) routers have been found to contain two undocumented factory implants in their firmware. These implants, SPEAKINGSTONE and DARKLANTERN, allow unauthenticated remote attackers to gain root access and execute commands on the devices.
cPanel has released patches for a critical security vulnerability in its cPanel and WebHost Manager (WHM) software. This flaw could allow a hosting customer to gain root control of an entire server by exploiting domain parking and addon domain functionalities. The vulnerability is assigned the CVE identifier CVE-2026-65643 and affects all supported versions.
An untold number of ZBT routers sold globally as white-label products have been found to contain several implants developed by the manufacturer. This discovery raises significant security concerns for users of these devices.
A website offering AI girlfriend services had its testing and staging environments exposed to the public for three weeks. This lack of protection allowed sensitive information to be accessible, highlighting the importance of securing all environments, not just production.
The Manchester Airports Group (MAG) has reported a data breach resulting from a cyberattack. Hackers successfully accessed MAG's systems and exfiltrated customer data, specifically information collected during Wi-Fi sign-ups across Manchester, Stansted, and East Midlands airports.
This article details a method for recovering cleartext credentials within ServiceNow, a popular IT service management platform. It explains how script includes can be utilized to create a mechanism for retrieving any discovery or LDAP credential type.
Vercel has released security patches for two critical vulnerabilities in the Next.js web framework. One vulnerability allows for remote code execution through specially crafted AVIF image files, while the other involves a path traversal flaw exploitable on Windows filesystems.
This article emphasizes the critical importance of testing backups to ensure their recoverability. It highlights that a backup is only truly valuable if a successful restore can be performed, urging organizations to regularly verify their data recovery capabilities.
The White House has issued a new executive order (14420) aimed at increasing scrutiny of industrial control systems within the US power grid. This order seeks to prevent foreign actors from introducing backdoors and engaging in cyber sabotage against critical energy infrastructure.
Android 17 is introducing new network security features, including Encrypted Client Hello (ECH) support, to enhance connection privacy and protect users from tracking during web browsing. These updates also aim to address cellular vulnerabilities and safeguard home network privacy.
Microsoft has released a fix for a recurring issue causing system crashes and gaming problems on Windows 11. The update addresses bugs that have been affecting user experience and system stability.
A security vulnerability (CVE-2026-75112) has been identified in Rockwell Automation OTTO Fleet Manager versions less than or equal to V2.36.2. This flaw involves the use of insufficient computational effort in password hashing, making offline brute-force attacks against stored hashes easier for attackers. Successful exploitation could lead to the compromise of weakly hashed credentials if an attacker obtains an unencrypted system backup.
Xiiaozet LK100W devices running firmware version below 2.1.240 are vulnerable to multiple security flaws, including OS command injection and authentication bypass. Successful exploitation could allow an attacker to gain control over the affected devices. The vulnerabilities have a CVSS v3.1 base score of 9.8.
Multiple vulnerabilities have been identified in All-Line Equipment Company's Fuel-Boss systems, specifically affecting versions running PHP 7.1.5 or earlier. Successful exploitation could allow remote attackers to execute arbitrary commands or code on affected industrial control systems.
Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37 are vulnerable to XML External Entity (XXE) injection and improper certificate validation. Successful exploitation could allow attackers to read or write local files, initiate outbound network requests, or intercept and modify communications.
Ebyte NA111-M devices running Firmware 9013-2-17 are affected by multiple critical vulnerabilities. These flaws, including Missing Authentication and Cross-Site Request Forgery, could allow remote attackers to fully compromise the device, leading to disruption of availability and access to sensitive information.
Mitsubishi Electric has released an update concerning multiple FA products, specifically addressing a vulnerability (CVE-2025-3511) in their CC-Link IE TSN Remote I/O modules. Successful exploitation could lead to a denial-of-service condition, timeout errors, or communication delays.
Boston Scientific is experiencing global operational disruptions due to a cyberattack. The incident has impacted the company's ability to process and ship customer orders.
CISA has issued a directive mandating U.S. federal agencies to patch a critical remote code execution (RCE) vulnerability affecting Citrix NetScaler appliances. The vulnerability is reportedly being actively exploited in the wild, and agencies must complete the patching by Saturday.
The US has disrupted a Chinese hacking platform known as QTFY, which provided malicious hacking services to the Chinese government and other entities. This platform was implicated in attacks targeting military and critical infrastructure.
A cyberattack on a small British electricity generator, which took it offline for four days, has highlighted a significant weakness in critical infrastructure. Thousands of smaller industrial sites, including generators and water systems, have aging operational technology connected to the internet without adequate security, making them easy targets. While the initial attribution to Iran-linked hackers is unconfirmed, the incident prompted UK government engagement with energy executives to assess and strengthen protections.
Academic researchers have revealed a new Rowhammer attack, named GPUThor, that targets NVIDIA workstation GPUs with GDDR6 memory. This attack successfully bypasses Error Correction Codes (ECC), a primary defense against GPU Rowhammer, and can lead to denial-of-service and root access on the host system.
The pro-Russian hacker group Server Killers has claimed responsibility for a significant cyberattack targeting Norway's public digital services. The specifics of the attack and its impact are still being assessed.
CISA has added six exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Among these is a high-severity vulnerability affecting Citrix NetScaler ADC and Gateway, which has been actively exploited.
CISA is strongly advising government agencies to promptly address a vulnerability affecting Citrix NetScaler. This vulnerability, identified as CVE-2026-8452, has reportedly been exploited in active attacks.
The FBI has seized hacking tools attributed to China, which were allegedly used to target critical US networks including NASA, the Department of Energy, and the US Senate. This action disrupts a significant cyber espionage operation.
ownCloud has an improper authentication vulnerability (CVE-2023-49105) that allows unauthenticated attackers to access, modify, or delete files if the victim's username is known and they lack a signing key. Organizations must apply vendor-provided mitigations and comply with CISA's BOD 26-04 guidance for prioritizing security updates.
A significant vulnerability, CVE-2026-53362, has been identified in the Linux Kernel's IPv6 networking subsystem. This flaw allows for privilege escalation and affects numerous Linux distributions, including Suse and Red Hat. CISA has mandated that stakeholders apply mitigations according to vendor instructions and follow specific guidance on prioritizing security updates.