Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Qilin Ransomware Campaign Exploits PAN-OS CVE-2026-0257 Auth Bypass
The authentication bypass vulnerability CVE-2026-0257 (CVSS 7.8) in the portal and gateway components of Palo Alto Networks PAN-OS is, according ...
Researchers Show Invisible Screen Prompts Can Lead to RCE on Mobile AI Agents
A team of researchers from Simon Fraser University, the Chinese University of Hong Kong, Shandong University and the Xingtu (QAX) ...
Remote Code Execution in AWS Kiro IDE Through MCP Configuration Abuse
Researchers from Intezer together with Kodem Security discovered in the agentic IDE AWS Kiro an attack chain that allowed an ...
Inside the WebDAV Malware Delivery Lab Behind the Mexico CURP Scam
Researchers at Rapid7 discovered an unsecured malware delivery server containing 1,048 files — ranging from phishing lure templates and filename ...
How HollowGraph Uses Microsoft 365 Calendars for Covert C2
Researchers from Group-IB have discovered a spyware implant called HollowGraph that uses the calendar of a compromised Microsoft 365 account ...
Long-Lived Daxin Rootkit and Stupig Backdoor in Taiwanese Tech Network
Teams from Symantec and the Carbon Black Threat Hunter Team have discovered an active instance of the Daxin rootkit on ...
How xAI’s Grok Build Tool Sent Full Git Repositories to Its Cloud
The Grok Build CLI tool from xAI, designed to help with writing code, was, according to a researcher, uploading to ...
ESET finds vulnerable legacy UEFI shims undermining Secure Boot
Researchers at ESET identified 11 legacy UEFI bootloaders (so-called shims) signed by Microsoft that are still considered trusted on most ...
What CVE-2026-58644 in Microsoft SharePoint Means for Security
On July 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-58644 vulnerability in Microsoft SharePoint Server ...
How ClickLock Stealer Forces macOS Users to Give Up Passwords
Researchers at Group-IB have discovered a new macOS infostealer, ClickLock Stealer, which uses a fundamentally different approach to obtaining the ...