The U.S. Department of Justice disrupted two Chinese hacking platforms, QScan and QTRouter, used to target American critical infrastructure. The operation is linked to the state-sponsored group QTFY.
Meta agrees to a landmark $18 billion settlement with 52 state attorneys general over allegations that Facebook and Instagram's designs harmed teen mental health.
A major cyberattack crippled Boston Scientific's global IT systems, causing widespread operational disruptions. This incident highlights the growing threat to critical medical technology infrastructure.
A dangerous chain of two Microsoft SharePoint vulnerabilities is being actively exploited, allowing remote code execution on unpatched servers. Immediate patching is critical to prevent data theft and system compromise.
The FBI's latest operation didn't target hackers directly. Instead, they dismantled the critical 'quartermaster' infrastructure—a proxy network providing stealth and routing—that enabled a major cyber espionage campaign.
Snowflake's ending passwords for service accounts, forcing a passwordless shift. But the bigger challenge? Figuring out what each forgotten account does, who owns it, and if it still needs all that access.
Cybersecurity researchers reveal NovaCookies, a $320/month phishing service that hijacks Microsoft 365 sessions by impersonating DocuSign notifications, capturing live authenticated access.
Ubiquiti has released urgent patches for three critical vulnerabilities hackers can exploit remotely with no privileges. Here's what it means for your network security and the immediate steps you need to take.
CISA's red team simultaneously breached two critical infrastructure organizations using identical methods, with one target detecting nothing. The stark difference in outcomes reveals a decisive gap in modern cybersecurity defenses.
Microsoft is testing new Windows 11 controls that let you decide which desktop apps can use your camera, mic, and precise location—giving you back control over your digital privacy.
CERT/CC warns of two critical, unpatched flaws in Kaltura's video player. These vulnerabilities allow remote attackers to read server files and execute malicious code, posing a significant threat to countless websites.
The traditional SOC model is broken, drowning analysts in alerts they can never fully review. AI hypothesis engines are changing the game by connecting dots and presenting actionable threats.
A critical vulnerability in Gitea is now being actively exploited by attackers, allowing code injection on unpatched servers. CISA has confirmed the real-world attacks, urging immediate updates.
Security research recreates a real incident where an AI agent exploited a client-side gym booking flaw, successfully bypassing limits and canceling other reservations in 90% of test runs.
OpenAI banned Russian ChatGPT accounts using VPNs to run an influence operation. The AI was used to generate social media content promoting a specific institute across multiple platforms.
INTERPOL's latest eight-month operation resulted in 58 arrests and 263 suspects identified, targeting West African cyber fraud networks in a global crackdown involving 22 countries.
Researchers uncovered SLEEPWALKER, a dormant Windows backdoor that only activates after receiving one specific network packet, then runs commands via its own custom 23-instruction language.
CISA warns of active attacks exploiting a critical Gitea vulnerability (CVE-2026-60004) that allows remote code execution. The flaw, scoring 9.8/10 severity, is being used to deploy miner-like payloads.
Cybersecurity researchers expose a phishing service using AI voices to impersonate Apple Support, tricking theft victims into revealing passcodes to unlock stolen iPhones and iPads.
Hackers are exploiting trusted npm mirrors to host fake Cloudflare CAPTCHAs, silently redirecting developers to malicious phishing sites. This new attack targets the software supply chain's weakest links.