Cyber Security News

Our category for the newest news in cybersecurity includes new threats, data breaches, and security tools. For the protection of digital assets, we keep you up to date on hacking strategies, rules, and best practices. Knowing how cybersecurity is changing can help you keep your data and processes safer.

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant…

4 minutes ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users' session…

20 minutes ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python…

32 minutes ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports. Disguised as…

1 hour ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise iPhones and harvest cryptocurrency wallet…

2 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw that could allow a man-in-the-middle…

2 hours ago

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site…

3 hours ago

Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root

Cisco has disclosed three critical vulnerabilities in its Nexus 3000 and 9000 Series switches that could allow unauthenticated remote attackers…

3 hours ago

Financially Motivated Hacker Uses Agentic AI to Breach Multiple South Korean Finance Targets

A financially motivated campaign that used agentic AI tools to breach South Korean financial organizations and exfiltrate data. Active from…

3 hours ago

PoC Exploit Released for Critical VMware Vulnerability Enabling Guest-to-Host Attacks

A public proof-of-concept (PoC) exploit has been released for CVE-2026-59346, a critical integer overflow flaw in VMware Workstation and Fusion…

3 hours ago