Cybersecurity and other IT news aggregator

LATEST FEEDS

  • U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches 2026-08-26 at 04:02 By The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers. “We are launching an economic onslaught against Iran’s financial connections around the…


  • World Liberty Financial launches USD1 natively on Canton Network

    World Liberty Financial launches USD1 natively on Canton Network 2026-08-25 at 23:35 By Cointelegraph by Nate Kostar USD1 is the sixth-largest stablecoin, with a market capitalization of more than $4 billion, according to industry data. This article is an excerpt from Cointelegraph.com News View Original Source


  • WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

    WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android 2026-08-25 at 22:03 By Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant…


  • Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

    Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode 2026-08-25 at 22:03 By Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck’s CVE Numbering Authority (CNA) record. The…


  • Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

    Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation 2026-08-25 at 19:23 By Eduard Kovacs TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek. This article is…


  • Man Falsely Impersonates Officer, Threatens Security Guard

    Man Falsely Impersonates Officer, Threatens Security Guard 2026-08-25 at 19:00 By A Florida man was arrested after allegedly impersonating an officer and threatening a security worker for a gated community.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

    Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat 2026-08-25 at 18:27 By Nikita Kazymirskyi A cyber incident affecting a small UK electricity generator in July 2026 resulted in several days of operational unavailability and triggered a government and NCSC response. UK authorities confirmed that the event posed no threat to the…


  • When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

    When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape 2026-08-25 at 18:00 By Organizations need more than perimeter defenses — they need a comprehensive data resilience strategy that combines access controls with immutable backups and recovery capabilities. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails

    Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails 2026-08-25 at 17:11 By SecurityWeek News The company, previously known as ActiveFence, has raised a total of $280 million from investors. The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek. This article is an excerpt from…


  • A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

    A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw 2026-08-25 at 17:07 By Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared…


  • INTERPOL crackdown on West African crime rings uncovers troubling new trend

    INTERPOL crackdown on West African crime rings uncovers troubling new trend 2026-08-25 at 17:01 By Sinisa Markovic Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran…


  • The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy

    The Double Edge of AI in Healthcare: Guarding Data, Growing Empathy 2026-08-25 at 17:00 By Bindu Sundaresan Healthcare has always run on two currencies: information and trust. Patients hand over their most sensitive data, diagnoses, genetic profiles, mental health histories, on the assumption that it will be protected and that the people (or systems) handling it…


  • WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

    WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 2026-08-25 at 16:33 By Eduard Kovacs CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO 

    From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO  2026-08-25 at 16:25 By Ashish Khaitan For years, cybersecurity teams have communicated risk through labels such as “High,” “Medium,” and “Low.” Those ratings can help security teams prioritize vulnerabilities, but they often leave CFOs with a more important question unanswered: What does the risk…


  • Citrix UniconOS dual boot turns Windows endpoints into their own recovery device

    Citrix UniconOS dual boot turns Windows endpoints into their own recovery device 2026-08-25 at 16:19 By Industry News Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix…


  • Fideo Lens reveals connections across identities, accounts and devices

    Fideo Lens reveals connections across identities, accounts and devices 2026-08-25 at 16:13 By Industry News Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships among identities, accounts, devices and behaviors. Starting with a single identity signal, investigators can use Fideo Lens to visualize and connect…


  • Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference

    Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference 2026-08-25 at 15:57 By Mike Lennon Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • Fake OpenAI Codex download tricks macOS users into installing malware

    Fake OpenAI Codex download tricks macOS users into installing malware 2026-08-25 at 15:40 By Sinisa Markovic A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular…


  • Over a third of webpages created after ChatGPT’s debut show signs of AI writing, study finds

    Over a third of webpages created after ChatGPT’s debut show signs of AI writing, study finds 2026-08-25 at 15:00 By Zoe Hussain More than one-third — 35% — of webpages created after the launch of ChatGPT in 2022 show signs of AI authorship, a Pew Research Center anaylsis found. This article is an excerpt from…


  • Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

    Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows 2026-08-25 at 14:56 By Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted…


  • 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

    24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages 2026-08-25 at 14:52 By Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the…


  • E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

    E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands 2026-08-25 at 14:33 By Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to…


  • First Malware Built Specifically for Car Head Units Fuels Botnet

    First Malware Built Specifically for Car Head Units Fuels Botnet 2026-08-25 at 14:18 By Eduard Kovacs Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Frontier AI: Vulnerability Management’s Systemic Revolution

    Frontier AI: Vulnerability Management’s Systemic Revolution 2026-08-25 at 14:14 By Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful…


  • Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

    Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over…


  • Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff

    Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff 2026-08-25 at 13:01 By Associated Press AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China. The post Taiwan Charges 9 Over Illegal AI Server Exports to China,…


  • Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

    Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access 2026-08-25 at 13:01 By Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as…


  • Silent Patches Don’t Stop Attackers—They Blind Defenders

    Silent Patches Don’t Stop Attackers—They Blind Defenders 2026-08-25 at 13:00 By Tod Beardsley Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Standard Chartered becomes first bank distributor of HKD stablecoin

    Standard Chartered becomes first bank distributor of HKD stablecoin 2026-08-25 at 12:52 By Cointelegraph by Ezra Reguerra The bank plans tokenized money market fund settlements in the fourth quarter as HKDAP expands its phased rollout into conventional banking. This article is an excerpt from Cointelegraph.com News View Original Source


  • ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

    ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 2026-08-25 at 12:24 By Sinisa Markovic Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group…


  • Galaxy puts Coldcard hack losses at 1,789 BTC, with 87% unmoved

    Galaxy puts Coldcard hack losses at 1,789 BTC, with 87% unmoved 2026-08-25 at 11:46 By Cointelegraph by Helen Partz Galaxy Research’s latest tally shows that more than half of 221 Coldcard hack victim reports involved individual losses exceeding 1 Bitcoin. This article is an excerpt from Cointelegraph.com News View Original Source


  • Business owner faces up to 280 years over $24M crypto Ponzi scheme

    Business owner faces up to 280 years over $24M crypto Ponzi scheme 2026-08-25 at 10:58 By Cointelegraph by Ezra Reguerra A federal jury convicted Brent Kovar of wire fraud, mail fraud and money laundering after he took $24 million from at least 400 investors. This article is an excerpt from Cointelegraph.com News View Original Source


  • CISA Warns of Exploited Oracle WebLogic Vulnerability

    CISA Warns of Exploited Oracle WebLogic Vulnerability 2026-08-25 at 10:46 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Bitcoin ETFs add $338M as six-day inflow streak hits $2.26B

    Bitcoin ETFs add $338M as six-day inflow streak hits $2.26B 2026-08-25 at 10:38 By Cointelegraph by Helen Partz Bitcoin ETFs have drawn $2.26 billion over six trading days, while year-to-date net outflows have narrowed to about $2.57 billion. This article is an excerpt from Cointelegraph.com News View Original Source


  • Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data 2026-08-25 at 09:12 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962…


  • AI supply chain risk is showing up in developer workflows first

    AI supply chain risk is showing up in developer workflows first 2026-08-25 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and…


  • TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

    TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials 2026-08-25 at 08:33 By Sinisa Markovic Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise…


  • HOL Guard: Open-source antivirus for AI agents

    HOL Guard: Open-source antivirus for AI agents 2026-08-25 at 08:30 By Anamarija Pogorelec HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your…


  • The cybercrime supply chain has five stages, each with a price

    The cybercrime supply chain has five stages, each with a price 2026-08-25 at 08:00 By Help Net Security In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five…


  • New TCG guidance gives buyers a way to test PQC-ready TPM claims

    New TCG guidance gives buyers a way to test PQC-ready TPM claims 2026-08-25 at 07:30 By Help Net Security The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements…


  • Cybersecurity jobs available right now: August 25, 2026

    Cybersecurity jobs available right now: August 25, 2026 2026-08-25 at 07:00 By Sinisa Markovic Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and…


  • BNB Chain activates Pasteur hard fork to strengthen bridge security

    BNB Chain activates Pasteur hard fork to strengthen bridge security 2026-08-25 at 06:56 By Cointelegraph by Ezra Reguerra BNB Chain activates the Pasteur hard fork on BSC, closing bridge and validator security gaps while targeting greater transaction capacity. This article is an excerpt from Cointelegraph.com News View Original Source


  • Korean bank taps Ripple for payments, Pakistan opens crypto licensing: Asia Express

    Korean bank taps Ripple for payments, Pakistan opens crypto licensing: Asia Express 2026-08-25 at 05:03 By Cointelegraph by Andrew Fenton Asia’s biggest crypto hubs are locked in a tax-cut arms race, while Ripple will help Korea’s Jeonbuk Bank move money across borders. This article is an excerpt from Cointelegraph.com News View Original Source


  • Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

    Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt 2026-08-25 at 03:21 By If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce…


  • Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

    Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning 2026-08-25 at 03:21 By Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that…


  • Card skimming scam is stealing food benefits nationwide

    Card skimming scam is stealing food benefits nationwide 2026-08-25 at 02:16 By Fox News The Secret Service says a single skimmer can generate as much as $1 million in stolen funds. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • CFTC, US soldier accused of illegal Polymarket bet spar over interpretation of prediction markets

    CFTC, US soldier accused of illegal Polymarket bet spar over interpretation of prediction markets 2026-08-25 at 00:33 By Cointelegraph by Turner Wright A judge stayed the CFTC’s civil case against a soldier who allegedly used nonpublic information for a Polymarket bet, but the regulator is trying to weigh in on the criminal case. This article…


  • Gemini plans to distribute crypto prediction markets through Apex brokerages

    Gemini plans to distribute crypto prediction markets through Apex brokerages 2026-08-24 at 23:46 By Cointelegraph by Nate Kostar The proposed deal would make Gemini the exclusive venue for crypto event contracts offered through Apex’s FCM, expanding its prediction-market reach to brokerage clients. This article is an excerpt from Cointelegraph.com News View Original Source


  • Lady Gaga’s tech bro fiancée launches weird new startup with a skin-crawling touch

    Lady Gaga’s tech bro fiancée launches weird new startup with a skin-crawling touch 2026-08-24 at 23:08 By Annie Gaus Lady Gaga’s techie fiancée Michael Polansky has quietly launched a buzzy startup that harvests human skin left over from plastic surgery to help develop super-advanced cosmetic products. Polansky, the 42-year old entrepreneur and Harvard grad who…


Browse older archives

Scroll to Top