Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
How Global Law Enforcement Dismantled the Sality P2P Botnet
The US Department of Justice has announced the completion of a multinational operation to dismantle the Sality botnet — one ...
CVE-2026-82329 in JFrog Artifactory: Unauthenticated Admin Access
A critical vulnerability CVE-2026-82329 with a CVSS score of 9.8 has been discovered in JFrog Artifactory. It allows an unauthenticated ...
Malicious Packagist Themes Drop iOS Spyware and Steal Crypto
Researchers from Socket discovered 13 malicious Composer packages on Packagist disguised as themes for the Vietnamese CMS platforms OphimCMS and ...
Remote Code Execution in Langflow and Rails Active Storage: CVE Analysis
Two critical vulnerabilities — CVE-2026-0768 in the AI application development platform Langflow and CVE-2026-66066 (KindaRails2Shell) in the Active Storage component ...
Microsoft analyzes TerminalFix attacks with DLL sideloading and AD recon
Microsoft has published a detailed analysis of the new TerminalFix campaign, a variant of the ClickFix technique targeting organizations across ...
Critical Vulnerabilities in Popular WordPress Plugins and Themes
Researchers from Wordfence and Patchstack have disclosed five critical vulnerabilities (CVSS 9.8–10.0) in widely used WordPress plugins and themes — ...
How Android 17 Hardens Network Security with ECH and 2G Controls
Android 17 (API level 37) introduces four major network security improvements: platform support for Encrypted Client Hello (ECH) to hide ...
Superior campaign: wallet-draining malware in browser extensions
Researchers at Socket identified a cluster of 19 malicious extensions — 18 for Google Chrome and one for Microsoft Edge ...
Chinese-Speaking Operator Uses ownCloud Flaw to Hack Philippine Nuclear Center
CISA has added the critical vulnerability CVE-2023-49105 (CVSS 9.8) in the ownCloud platform to the Known Exploited Vulnerabilities (KEV) catalog ...
Root-level remote code execution chains in Unitree G1 EDU robots
Security researcher Olivier Laflamme published details on August 27, 2026 of two independent remote code execution chains with root privileges ...