Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Exploitation of Cisco ASA and FTD VPN vulnerability CVE-2026-20349
Cisco has confirmed active exploitation of vulnerability CVE-2026-20349 (CVSS 8.6) in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall ...
August 2026 Microsoft Patch Tuesday: Priority Guidance for CVE-2026-68820
Microsoft’s August security update addresses CVE-2026-68820 — a privilege escalation vulnerability in the Windows kernel driver afd.sys that, according to ...
How OpenAI’s GPT-5.6-Cyber Changes Cyber Defense
OpenAI has introduced the specialized model GPT-5.6-Cyber, designed for zero-day vulnerability discovery, exploit chain development, and incident response. The model ...
How CVE-2026-55040 Lets Attackers Hijack On‑Prem SharePoint
The CVE-2026-55040 vulnerability (CVSS 9.1) in the JSON Web Token validation pipeline on Microsoft SharePoint servers allows a remote unauthenticated ...
Why Mozilla Revoked Its Firefox and Thunderbird Linux Signing Key
Mozilla has revoked the cryptographic subkey (subkey) used to sign Firefox and Thunderbird downloads for Linux, after an unencrypted copy ...
Go-based macOS stealer uses ClickFix to drain crypto wallets
Researchers at Huntress have documented a campaign in which ClickFix-style attacks are used to deliver Go-based malware to macOS. The ...
How UNC6671 Uses Vishing and AitM to Breach Okta and Microsoft 365
The extortion group UNC6671 is conducting a large-scale voice phishing (vishing) campaign against financial, legal and technology organizations in North ...
Prompt-injection bugs let low-priv bots trigger privileged CI in Google ADK
Researchers at Pillar Security identified two vulnerabilities in the automation of the Google Agent Development Kit (ADK) for Python GitHub ...
Arctic Wolf exposes MFA-bypassing BEC against Microsoft 365
Researchers at Arctic Wolf Labs have recorded a large-scale phishing campaign targeting Microsoft 365 accounts. The attackers use an adversary-in-the-middle ...
Solidity Pro: malicious VS Code extension targeting Web3 developers
Researchers from Yeeth Security discovered the malicious Solidity Pro extension for Microsoft Visual Studio Code which, while masquerading as a ...