Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Inside the WebDAV Malware Delivery Lab Behind the Mexico CURP Scam
Researchers at Rapid7 discovered an unsecured malware delivery server containing 1,048 files — ranging from phishing lure templates and filename ...
How HollowGraph Uses Microsoft 365 Calendars for Covert C2
Researchers from Group-IB have discovered a spyware implant called HollowGraph that uses the calendar of a compromised Microsoft 365 account ...
Long-Lived Daxin Rootkit and Stupig Backdoor in Taiwanese Tech Network
Teams from Symantec and the Carbon Black Threat Hunter Team have discovered an active instance of the Daxin rootkit on ...
How xAI’s Grok Build Tool Sent Full Git Repositories to Its Cloud
The Grok Build CLI tool from xAI, designed to help with writing code, was, according to a researcher, uploading to ...
ESET finds vulnerable legacy UEFI shims undermining Secure Boot
Researchers at ESET identified 11 legacy UEFI bootloaders (so-called shims) signed by Microsoft that are still considered trusted on most ...
What CVE-2026-58644 in Microsoft SharePoint Means for Security
On July 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-58644 vulnerability in Microsoft SharePoint Server ...
How ClickLock Stealer Forces macOS Users to Give Up Passwords
Researchers at Group-IB have discovered a new macOS infostealer, ClickLock Stealer, which uses a fundamentally different approach to obtaining the ...
How CVE-2026-59208 exposes n8n Enterprise token exchange
A vulnerability CVE-2026-59208 has been discovered in the n8n workflow automation platform that allows an attacker to authenticate as another ...
Three Critical SAP Vulnerabilities Patched in July 2026 Release
SAP has released the July 2026 security update bundle, which fixes three critical vulnerabilities: memory corruption in SAP NetWeaver Application ...
Emergency Zoom Updates Fix Critical Windows Account Takeover Bug
Zoom has released emergency security updates addressing critical vulnerability CVE-2026-53412 with a CVSS score of 9.8 in the Zoom Workplace ...