Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Critical Model Context Protocol (MCP) Flaw Enables Remote Code Execution in LLM Tooling Ecosystem
Security researchers have identified a critical architectural flaw in the Model Context Protocol (MCP), a standard used to connect large ...
Stolen Credentials and the DAIR Model: Rethinking Incident Response in the Age of AI
Stolen and abused credentials remain one of the most reliable and widely used initial access vectors in cyber attacks, despite ...
CISA Expands KEV Catalog with Eight Exploited Vulnerabilities Targeting SD-WAN, CI/CD and Remote Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added eight new entries to its Known Exploited Vulnerabilities (KEV) catalog, ...
Operation PowerOFF: Global Crackdown on DDoS‑for‑Hire Booter Services
International law enforcement agencies have carried out a large‑scale crackdown on commercial DDoS‑for‑hire platforms, also known as booter or stresser ...
NIST Overhauls NVD: Risk‑Based Processing of CVE Vulnerabilities
The U.S. National Institute of Standards and Technology (NIST) has announced a radical change to how the National Vulnerability Database ...
PowMix Botnet Targets Czech Job Market with PowerShell-Based In-Memory Malware
A new botnet dubbed PowMix has been observed targeting employees and job seekers in the Czech Republic, according to Cisco ...
Vercel Security Breach Tied to Context.ai Compromise Highlights OAuth and Environment Variable Risks
Vercel, one of the leading providers of web infrastructure and hosting for modern front‑end frameworks, has disclosed a security incident ...
Grinex Crypto Exchange Hack Exposes Sanctions Evasion Network
The Kyrgyz cryptocurrency exchange Grinex, already under UK and US sanctions, has suspended operations following a large‑scale cyberattack. According to ...
CVE-2026-33032 (MCPwn): Critical nginx-ui Authentication Bypass Under Active Exploitation
A critical vulnerability in nginx-ui, a popular open-source web interface for managing Nginx, is being actively exploited and allows attackers ...