Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
CVE-2026-3888 in Ubuntu 24.04: snapd Vulnerability Enables Local Privilege Escalation
A new high-severity vulnerability, CVE-2026-3888, has been identified in Ubuntu Desktop 24.04 and newer, allowing a local, unprivileged attacker to ...
Stryker Cyberattack: How Hackers Used Microsoft Intune to Wipe 80,000 Devices
A significant cybersecurity incident in the medical technology sector has hit global medtech manufacturer Stryker, where attackers remotely erased data ...
Perseus Android Banking Trojan Targets Note‑Taking Apps to Steal Passwords and Seed Phrases
A new Android banking trojan dubbed Perseus is setting a concerning precedent in mobile malware. According to research by ThreatFabric, ...
DarkSword iOS Exploit Kit: Safari-Based Spyware Threat Puts Millions of iPhones at Risk
Security researchers from Lookout, iVerify and Google’s Threat Intelligence Group (GTIG) have uncovered a new advanced iOS exploit kit dubbed ...
Magecart Attack via Favicon EXIF Metadata: Limits of Static Code Analysis and the Need for Client-Side Monitoring
A recently observed Magecart web skimming campaign demonstrates how modern attackers can steal payment card data without ever modifying the ...
Custom Font Prompt Injection Attack Exposes Blind Spot in Browser-Based AI Assistants
Researchers from LayerX have presented a new prompt injection technique that targets browser-integrated AI assistants by abusing custom fonts. The ...
Apple Quietly Fixes Critical WebKit Vulnerability with Background Security Improvements
Apple has silently closed a critical browser engine vulnerability using its new Background Security Improvements (BSI) mechanism, delivering the patch ...
IP KVM Vulnerabilities Turn Low‑Cost Remote Management Into High‑Impact Attack Vector
Recent research by Eclypsium has revealed a cluster of nine security vulnerabilities in popular low‑cost IP KVM devices, priced roughly ...
CrackArmor: Nine Linux AppArmor Vulnerabilities Threaten Enterprise and Cloud Security
The Qualys Threat Research Unit (TRU) has disclosed nine vulnerabilities in the Linux kernel’s AppArmor security module, collectively dubbed CrackArmor. ...
Japan Authorizes Offensive Cyber Operations from 2025: Shift to Proactive Cyber Defense
Japan has approved a landmark change to its national cybersecurity policy: from 1 October 2025, the Self-Defense Forces (SDF) and ...