Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Critical cPanel Authentication Vulnerability: What Hosting Providers and Site Owners Must Do Now
One of the world’s most widely used hosting control panels, cPanel, has received urgent security updates to address a serious ...
Microsoft Entra ID Agent ID Administrator Vulnerability Exposed Critical Service Principal Takeover Risk
A recently disclosed vulnerability in Microsoft Entra ID (formerly Azure AD) allowed users with a new Agent ID Administrator role ...
Silk Typhoon Suspect Extradited to the US over Microsoft Exchange and COVID‑19 Espionage Campaigns
Chinese citizen Xu Zewei, whom US authorities describe as a member of the state‑linked hacking group known as Silk Typhoon, ...
Critical CVE-2026-25874 Vulnerability in Hugging Face LeRobot Exposes AI Robotics to Remote Code Execution
A critical vulnerability CVE-2026-25874 has been identified in the open-source robotics platform LeRobot by Hugging Face, enabling unauthenticated remote code ...
Apple Patches iOS Notification Bug That Left Deleted Signal Messages on iPhones (CVE-2026-28950)
Apple has released an unscheduled security update for iOS and iPadOS to fix a critical flaw in the Notification Services ...
DOJ Sentences Cybersecurity Professionals for Supporting BlackCat Ransomware Operations
The U.S. Department of Justice (DOJ) has sentenced two cybersecurity professionals to four years in prison each for assisting the ...
NASA Inspector General Exposes Sophisticated Spear‑Phishing Operation Against Aerospace and Defense Research
The NASA Office of Inspector General (OIG) has disclosed details of a sophisticated spear‑phishing and cyber‑espionage campaign in which a ...
New GopherWhisper APT Uses Go-Based Malware and Cloud C2 to Spy on Mongolian Government
A previously unknown advanced persistent threat (APT) group, dubbed GopherWhisper, has been linked to a cyber‑espionage campaign targeting government entities ...
Anthropic Project Glasswing: AI Vulnerability Discovery and the New Reality of Cyber Defense
Anthropic’s decision to delay the public release of Project Glasswing is one of the clearest signals of how rapidly artificial ...