Attackers recently broke through Microsoft 365’s multi-factor authentication (MFA) protections without malware, hijacking a finance employee’s account to reroute vendor payments. A single phishing email […]
Category: Cybersecurity News
Stay informed about the ever-evolving world of digital threats and defenses with our Cyber Security News category. Here, you’ll find the latest breaking news, in-depth analysis, and expert insights on everything related to cybersecurity. From data breaches and ransomware attacks to emerging threats and innovative security solutions, we cover the critical issues impacting individuals, businesses, and governments worldwide. Keep up-to-date on the latest vulnerabilities, best practices, and trends shaping the future of online security.
Zyxel Fixes High-Severity Command Injection Bug in 18 Access Points
Zyxel has released critical firmware updates addressing a severe command injection vulnerability (CVE-2026-6837) that affects 18 models of its wireless access points. The flaw, residing […]
Regulator Warns Roblox Still Poses Risk of Adult Contact with Children
An independent regulator has determined that despite recent updates, Roblox continues to expose children to risks from predatory adults. The Australian eSafety Commissioner’s review identifies […]
Zombie Card Attack Lets Expired Visa Cards Still Pay via Contactless NFC
Researchers at UMass Amherst have revealed a novel vulnerability dubbed the “Zombie Card” attack, which enables expired Visa contactless cards to be fraudulently used for […]
Critical SSRF in Red Hat’s Kubernetes Multicluster Engine Leaves Internal Services Exposed
Red Hat has revealed a major vulnerability, tagged CVE-2026-66794, in its Multicluster Engine for Kubernetes. The issue impacts the cluster-proxy-addon component and enables unauthenticated attackers […]
OpenAI Hits Pause on Training Over Zero-Day Risk in New Model
OpenAI has temporarily halted major AI training operations out of concern that its next-generation model, Astra, might develop the ability to independently discover zero-day vulnerabilities. […]
Critical XXE Flaw in Cisco BroadWorks Lets Attackers Expose Configuration Files
Cisco has issued a security alert for a serious XML External Entity (XXE) injection vulnerability in several components of its BroadWorks platform that lets unauthenticated […]
OpenClaw AI Agents Hijacked in ClawHavoc Attack Targeting Crypto Wallets
Cybercriminals are exploiting OpenClaw, an open-source platform that allows AI agents to interact with files, messaging apps, and execute terminal commands. A campaign called ClawHavoc […]
“Manic” Android Malware Uses Nearby Infected Devices to Steal Data Offline
A newly discovered Android malware strain called “Manic” is actively targeting banks, government and identity services, messaging apps, crypto platforms, and military communication channels across […]
“CDN Tsunami” HTTP/3 Attack Lets Low Bandwidth Do Massive DoS
Security researchers have uncovered a new family of denial-of-service (DoS) attacks that manipulate how major content delivery networks (CDNs) translate client-facing HTTP/3 traffic into HTTP/1.1 […]