cyber security

EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Tax and Financial Data

Ernst & Young (EY) has warned that a data breach exposed personal and financial information belonging to clients of Goldman…

1 day ago

Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands

Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI…

1 day ago

Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure

CyberXero, a Russian-speaking initial access broker combining conventional exploitation tools with AI agents to pursue global website compromises and targeted…

1 day ago

FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials

The FBI and U.S. Secret Service issued a joint cybersecurity advisory warning that operators of "FortiBleed" continue to target internet-facing…

1 day ago

Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches

Attackers breached two of South Korea’s largest churches through distinct intrusion chains, combining an ERP web shell, privileged database access,…

1 day ago

OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack

OpenSSH released version 10.6 on October 6, 2026, to address security vulnerabilities that affect encrypted sessions, file transfers, authentication, and…

1 day ago

LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension

A campaign that uses more than 100 compromised websites to distribute LUNEXSTEALER, a Windows infostealer that installs a browser extension…

1 day ago

Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception

Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a high-severity Kibana authorization…

1 day ago

Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code

Veeam released security updates to address a critical vulnerability that lets low-privileged users execute remote code on Veeam Backup Servers.…

1 day ago

Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks

A prolonged Partisan Zmiy intrusion into a medical organization, exposing an updated malware toolkit that combined Telegram command channels, DNS…

1 day ago